Input validation error in Microsoft Windows and Windows Server - CVE-2023-21694
Published: February 14, 2023
Vulnerability identifier: #VU72205
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21694
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input in Windows Fax Service. A remote attacker on the local network with administrative access to the device can execute arbitrary code on the target system
Affected software
Microsoft Windows
Windows Server
Windows Server
How to mitigate CVE-2023-21694
Install updates from vendor's website.