CVE-2023-38140

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Sep 12, 2023
Updated: Jan 1, 2025
CWE ID 908

Summary

CVE-2023-38140 is a new Windows Kernel vulnerability that has been disclosed. This information disclosure issue allows attackers to access sensitive data by manipulating specific system calls. The vulnerability could potentially lead to serious consequences if exploited, including the compromise of confidential information or the ability to execute arbitrary code. Microsoft has acknowledged the issue and is working on a patch, but in the meantime, organizations are urged to take steps to mitigate risk, such as applying available workarounds or implementing network segmentation. It is recommended that users and administrators stay informed of updates and apply patches as soon as they become available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share