CVE-2023-21298

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 30, 2023
Updated: Nov 6, 2023
CWE ID 203

Summary

CVE-2023-21298 is a newly identified vulnerability in Slice, a popular application for managing shortcuts on Windows. This issue involves a side channel information disclosure, allowing an attacker to potentially gain insights into the installed applications without requiring any user interaction or additional execution privileges. Consequently, an attacker could escalate their privileges locally without the need for further exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share