CVE-2023-36046
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2023-36046 is a Windows Authentication Denial of Service (DoS) vulnerability. An attacker can exploit this flaw by sending maliciously crafted packets to a targeted Windows server, leading to a denial of service condition. The vulnerability lies in the way the server handles authentication requests, allowing an attacker to cause a memory leak and exhaust system resources. This can result in the server becoming unresponsive or crashing, rendering it unable to process legitimate requests. Organizations using affected Windows systems are advised to apply the available patch or implement mitigations to prevent potential DoS attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Windows 11 21H2
- Microsoft Windows 11 22h2
- Windows Server 2022
Affected Vendors
- Microsoft