CVE-2023-36404

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Nov 14, 2023
Updated: Jan 1, 2025
CWE ID 284

Summary

CVE-2023-36404 is a newly disclosed vulnerability affecting the Windows Kernel. This issue allows an attacker to gain unauthorized access to sensitive information by causing a memory dump, leading to potential privacy breaches. The vulnerability stems from a flaw in the Windows Kernel's handling of certain system calls, enabling an attacker to bypass security restrictions and access protected information. This vulnerability poses a serious threat, as the exposed data can reveal critical system details, potentially aiding further exploitation. Microsoft is currently working on a patch to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share