VDB
CVE-2023-36900
CVE-2023-36900
PUBLISHED
In verschiedenen Version von Microsoft Windows und Microsoft Windows Server existieren mehrere Schwachstellen. Microsoft veröffentlicht keine Details dazu. Ein Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, seine Privilegien zu erweitern, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen oder Sicherheitsvorkehrungen zu umgehen. Für die Ausnutzung einiger dieser Schwachstellen ist eine Benutzerinteraktion erforderlich.
EPSS 25.15% · 96.3th percentile
Risk Scores
EPSS Score
25.15%
96.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Windows Server 2022 | |
| Microsoft | Microsoft Windows Server 2019 | |
| Microsoft | Microsoft Windows 11 Version 22H2 | |
| Microsoft | Microsoft Windows 10 | |
| Microsoft | Microsoft Windows Server 2008 SP2 | |
| Microsoft | Microsoft Windows 10 Version 1809 | |
| Microsoft | Microsoft Windows Server 2012 R2 | |
| Microsoft | Microsoft Windows Server 2008 R2 SP1 | |
| Hitachi | Hitachi Storage Virtual Storage Platform | |
| Microsoft | Microsoft Windows 11 version 21H2 | |
| Microsoft | Microsoft Windows 10 Version 21H2 | |
| Microsoft | Microsoft Windows Server 2012 | |
| Microsoft | Microsoft Windows Server 2016 | |
| Microsoft | Microsoft Windows 10 Version 1607 | |
| Microsoft | Microsoft Windows 10 Version 22H2 |
Exploit Intelligence
- Denial-of-Service PoC | Writeup | Header with CLFS structures | Imhex pattern for .blf extension (github-poc)
- Denial-of-Service PoC | Writeup | Header with CLFS structures | Imhex pattern for .blf extension (github-poc)
- Denial-of-Service PoC | Writeup | Header with CLFS structures | Imhex pattern for .blf extension (github-poc)
- Denial-of-Service PoC | Writeup | Header with CLFS structures | Imhex pattern for .blf extension (github-poc)
- Denial-of-Service PoC | Writeup | Header with CLFS structures | Imhex pattern for .blf extension (github-poc)
- Denial-of-Service PoC | Writeup | Header with CLFS structures | Imhex pattern for .blf extension (github-poc)
- https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1 (msrc)
- Windows Common Log File System Driver Elevation of Privilege Vulnerability (circl)
- CVE-2023-36900 (cve.org)
Timeline
- Aug 8, 2023 CVE Published
- Aug 9, 2023 EPSS Score
- Aug 11, 2023 CVE Updated
- Oct 15, 2023 EPSS Score
- Dec 21, 2023 EPSS Score
- Feb 27, 2024 EPSS Score
- Mar 31, 2024 EPSS Score
- May 4, 2024 EPSS Score
- Jun 3, 2024 EPSS Score
- Jul 8, 2024 EPSS Score
- Jul 20, 2024 EPSS Score
- Aug 14, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2011.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2011 advisory
- https://www.hitachi.com/products/it/storage-solutions/sec_info/2023/08.html advisory
- https://msrc.microsoft.com/update-guide advisory