PT-2023-1772 · Microsoft · Windows

Published

2023-03-14

·

Updated

2024-05-29

·

CVE-2023-21708

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows versions prior to the fixed version
Description The issue exists due to insufficient input validation in the Procedure Call Runtime of Windows operating systems. This allows a remote attacker to execute arbitrary code.
Recommendations For Windows versions prior to the fixed version, apply the necessary patch or update to resolve the issue. As a temporary workaround, consider restricting access to the Remote Procedure Call Runtime to minimize the risk of exploitation.

Fix

RCE

Integer Underflow

Weakness Enumeration

Related Identifiers

BDU:2023-01367
CVE-2023-21708

Affected Products

Windows