PT-2023-1747 · Microsoft · Windows

L1Nk3D

+2

·

Published

2023-03-14

·

Updated

2024-05-29

·

CVE-2023-23394

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Windows Client Server Run-Time Subsystem (CSRSS) (affected versions not specified)
Description The vulnerability is related to a lack of protection for system data in the Windows operating system. It allows attackers to obtain sensitive information and potentially affect the system. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Information Disclosure

Untrusted Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2023-01342
CVE-2023-23394

Affected Products

Windows