cbcvebase.
CVE-2023-21689
published 2023-02-14

CVE-2023-21689: Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

PriorityP273critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
26.50%
97.8th percentile
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.1974710.0.10240.19747
microsoftwindows_10_1607< 10.0.14393.571710.0.14393.5717
microsoftwindows_10_1809< 10.0.17763.401010.0.17763.4010
microsoftwindows_10_20h2< 10.0.19042.260410.0.19042.2604
microsoftwindows_10_21h2< 10.0.19044.260410.0.19044.2604
microsoftwindows_10_22h2< 10.0.19045.260410.0.19045.2604
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1974710.0.10240.19747
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.571710.0.14393.5717
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.401010.0.17763.4010
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.401010.0.17763.4010
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.260410.0.19042.2604
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.260410.0.19044.2604
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.260410.0.19045.2604
microsoftwindows_11_21h2< 10.0.22000.157410.0.22000.1574
microsoftwindows_11_22h2< 10.0.22621.126510.0.22621.1265
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22621.157410.0.22621.1574
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.126510.0.22621.1265
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.263666.1.7601.26366
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.241166.2.9200.24116
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.208216.3.9600.20821
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.571710.0.14393.5717
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.401010.0.17763.4010
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.154710.0.20348.1547

Detection & IOCsextracted from sources · hover to see the quote

  • The attack vector is network with no privileges required and no user interaction needed; target is the server account via a malicious network call to a Windows NPS (Network Policy Server) running PEAP
  • PEAP is only negotiated when NPS is running on Windows Server with a network policy configured to allow PEAP; detection should focus on anomalous PEAP negotiation traffic toward NPS servers
  • Exploitation assessed as 'More Likely' for latest software release despite no public exploit or in-the-wild exploitation at time of advisory; prioritize patching NPS servers exposed to network
  • ·To mitigate exposure, ensure PEAP Type is not configured as an allowed EAP type in NPS network policy; removing PEAP from allowed EAP types prevents the vulnerable code path from being reached
  • ·Vulnerability only exists on Windows Server instances where NPS is actively running and has a network policy permitting PEAP negotiation; servers without NPS or without PEAP-enabled policies are not exposed

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.