#VU72209 Input validation error in Windows and Windows Server - CVE-2023-21803
Published: February 14, 2023
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to compromise the affected system
The vulnerability exists due to insufficient validation of user-supplied input within the Windows iSCSI Discovery Service. A remote attacker can send a specially crafted malicious DHCP discovery request to the iSCSI Discovery Services and execute arbitrary code on the system.
Note, only x86 or 32-bit based versions of Windows are affected by this vulnerability.