CVE-2023-34367

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jun 14, 2023
Updated: Jan 6, 2025
CWE ID 287

Summary

CVE-2023-34367 is a vulnerability affecting Windows 7 systems that allows for full blind TCP/IP hijacking. This issue, which is also present in various IoT devices and other TCP/IP implementations, permits an attacker to hijack connections without the need for any knowledge of the initial connection or data being transmitted. Despite being labeled as a low severity issue by the vendor, the potential consequences of a successful attack can be significant, leading to data theft or unauthorized access. Windows 7 users are advised to apply available patches or consider upgrading to a more secure operating system to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 7

Affected Vendors

  • Microsoft