PT-2023-5940 · Microsoft · Wordpad+1

Published

2023-10-10

·

Updated

2026-02-11

·

CVE-2023-36563

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft WordPad (affected versions not specified)
Description The vulnerability in Microsoft WordPad is related to the disclosure of NTLM hashes, which can be exploited by attackers to obtain sensitive information. This issue can affect the system and potentially allow remote attackers to disclose protected information. The vulnerability has been exploited in real-world attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-06637
CVE-2023-36563

Affected Products

Wordpad
Windows