CVE-2023-23407
published 2023-03-14CVE-2023-23407: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
PriorityP430high7.1CVSS 3.1
AVAACHPRNUIRSUCHIHAH
EPSS
0.39%
31.7th percentile
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19805 | 10.0.10240.19805 |
| microsoft | windows_10_1607 | < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_10_1809 | < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_10_20h2 | < 10.0.19042.2728 | 10.0.19042.2728 |
| microsoft | windows_10_21h2 | < 10.0.19044.2728 | 10.0.19044.2728 |
| microsoft | windows_10_22h2 | < 10.0.19045.2728 | 10.0.19045.2728 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19805 | 10.0.10240.19805 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2728 | 10.0.19042.2728 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2728 | 10.0.19044.2728 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2728 | 10.0.19045.2728 |
| microsoft | windows_11_21h2 | < 10.0.22000.1696 | 10.0.22000.1696 |
| microsoft | windows_11_22h2 | < 10.0.22000.1413 | 10.0.22000.1413 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1696 | 10.0.22000.1696 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.1413 | 10.0.22621.1413 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26415 | 6.1.7601.26415 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24168 | 6.2.9200.24168 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20865 | 6.3.9600.20865 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1607 | 10.0.20348.1607 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
vendor_msrc·2023-03-14·CVSS 7.1
CVE-2023-23407 [HIGH] CWE-591 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?
Exploiting this vulnerability requires an attacker to be on the same network segment as the target system. Traffic associated with exploitation of this vulnerability is not routable and is bound to the data link layer of the OSI model.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A user would need to dial a PP
GHSA
GHSA-89r6-vqv7-m7cq: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
ghsa_unreviewed·2023-03-14
CVE-2023-23407 [HIGH] CWE-362 GHSA-89r6-vqv7-m7cq: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-14
Published