PT-2023-6948 · Microsoft · Windows User Interface Application Core+1

Kap0K

+1

·

Published

2023-11-14

·

Updated

2024-05-29

·

CVE-2023-36393

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows User Interface Application Core (affected versions not specified)
Description The issue is related to insufficient input validation in the Windows User Interface Application Core, which can be exploited by attackers to execute arbitrary code by loading a specially crafted file. This can allow remote attackers to execute arbitrary code and affect the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Untrusted Search Path

Weakness Enumeration

Related Identifiers

BDU:2023-07967
CVE-2023-36393

Affected Products

Windows
Windows User Interface Application Core