PT-2023-1772 · Microsoft · Windows
Published
2023-03-14
·
Updated
2024-05-29
·
CVE-2023-21708
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows versions prior to the fixed version
Description
The issue exists due to insufficient input validation in the Procedure Call Runtime of Windows operating systems. This allows a remote attacker to execute arbitrary code.
Recommendations
For Windows versions prior to the fixed version, apply the necessary patch or update to resolve the issue.
As a temporary workaround, consider restricting access to the Remote Procedure Call Runtime to minimize the risk of exploitation.
Fix
RCE
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows