CVE-2023-21740
published 2023-12-12CVE-2023-21740: Windows Media Remote Code Execution Vulnerability Windows Media Remote Code Execution Vulnerability
high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.08%
60.9th percentile
Windows Media Remote Code Execution Vulnerability
Windows Media Remote Code Execution Vulnerability
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20345 | 10.0.10240.20345 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.6529 | 10.0.14393.6529 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5206 | 10.0.17763.5206 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5206 | 10.0.17763.5206 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19041.3803 | 10.0.19041.3803 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.3803 | 10.0.19045.3803 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.2652 | 10.0.22000.2652 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.2861 | 10.0.22621.2861 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22621.2861 | 10.0.22621.2861 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.2861 | 10.0.22631.2861 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26864 | 6.1.7601.26864 |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24614 | 6.2.9200.24614 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.21715 | 6.3.9600.21715 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.6529 | 10.0.14393.6529 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.5206 | 10.0.17763.5206 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2159 | 10.0.20348.2159 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_10_version_22h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_11_version_22h2 | — | — |
| msrc | windows_11_version_23h2 | — | — |
| msrc | windows_server_2008_r2 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvelistv57.8HIGH
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Media Remote Code Execution Vulnerability
vendor_msrc·2023-12-12·CVSS 7.8
CVE-2023-21740 [HIGH] CWE-122 Windows Media Remote Code Execution Vulnerability
Windows Media Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.
For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the use
CVEList
Windows Media Remote Code Execution Vulnerability
cvelistv5·2023-12-12·CVSS 7.8
CVE-2023-21740 [HIGH] CWE-122 Windows Media Remote Code Execution Vulnerability
Windows Media Remote Code Execution Vulnerability
Windows Media Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Trendmicro
The December 2023 Security Update Review
blogs_trendmicro·2023-12-12
The December 2023 Security Update Review
# The December 2023 Security Update Review
Get the December 2023 security update and review.
By: Zero Day Initiative
2023/12/12
Read time: ( words)
Save to Folio
It’s the final patch Tuesday of 2023, and Apple, Adobe, and Microsoft have released their latest security offerings. Take a break from your holiday hustle and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
Apple Patches for December 2023
Apple kicked off the December release cycle with patches for iOS and iPadOS with eight CVEs. Two of these CVEs in Webkit are reported as being under active attack on iOS versions 16.7.1 and older. If you’re using an older iPhone or iPad, you should definitely update your device immediately. If you’re using a dev
Talos
Microsoft releases lightest Patch Tuesday in three years, no zero-days disclosed
blogs_talos·2023-12-12·CVSS 8.1
[HIGH] Microsoft releases lightest Patch Tuesday in three years, no zero-days disclosed
Microsoft’s monthly security update released Tuesday is the company’s lightest in four years, including only 33 vulnerabilities.
Perhaps more notable is that there are no zero-day vulnerabilities included in December’s Patch Tuesday, a rarity for Microsoft this year. The company’s regular set of advisories has included a vulnerability that’s been actively exploited in the wild in 10 months this year.
However, there are four critical vulnerabilities that Microsoft released patches, three of which could lead to remote code execution. The remainder of this month’s vulnerabilities are considered “important.” Thirty-three vulnerabilities are the lowest number included in a Patch Tuesday since December 2019.
Two of the critical vulnerabilities are CVE-2023-35630 and CVE-2023-35641, which exis
Bleepingcomputer
Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
blogs_bleepingcomputer·2023-12-12·CVSS 5.5
[MEDIUM] Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
## Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
## Lawrence Abrams
10 Elevation of Privilege Vulnerabilities
8 Remote Code Execution Vulnerabilities
6 Information Disclosure Vulnerabilities
5 Denial of Service Vulnerabilities
5 Spoofing Vulnerabilities
The total count of 34 flaws does not include 8 Microsoft Edge flaws fixed on December 7th.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5033375 cumulative update and Windows 10 KB5033372 cumulative update .
## One publicly disclosed zero-day fixed
This month's Patch Tuesday fixes one AMD zero-day vulnerability disclosed in August that previously remained unpatched.
The ' CVE-2023-20588 - AMD: CVE-2023-20588 AMD Speculative Leaks ' vul
Talos
Microsoft releases lightest Patch Tuesday in three years, no zero-days disclosed
blogs_talos·2023-12-12·CVSS 8.1
[HIGH] Microsoft releases lightest Patch Tuesday in three years, no zero-days disclosed
## Microsoft releases lightest Patch Tuesday in three years, no zero-days disclosed
Microsoft’s monthly security update released Tuesday is the company’s lightest in four years, including only 33 vulnerabilities.
Perhaps more notable is that there are no zero-day vulnerabilities included in December’s Patch Tuesday, a rarity for Microsoft this year. The company’s regular set of advisories has included a vulnerability that’s been actively exploited in the wild in 10 months this year.
However, there are four critical vulnerabilities that Microsoft released patches, three of which could lead to remote code execution. The remainder of this month’s vulnerabilities are considered “important.” Thirty-three vulnerabilities are the lowest number included in a Patch Tuesday since December 2019.
2023-12-12
Published