CVE-2023-23416
published 2023-03-14CVE-2023-23416: Windows Cryptographic Services Remote Code Execution Vulnerability
PriorityP349high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
7.58%
93.9th percentile
Windows Cryptographic Services Remote Code Execution Vulnerability
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19805 | 10.0.10240.19805 |
| microsoft | windows_10_1607 | < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_10_1809 | < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_10_20h2 | < 10.0.19042.2728 | 10.0.19042.2728 |
| microsoft | windows_10_21h2 | < 10.0.19044.2728 | 10.0.19044.2728 |
| microsoft | windows_10_22h2 | < 10.0.19045.2728 | 10.0.19045.2728 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19805 | 10.0.10240.19805 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2728 | 10.0.19042.2728 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2728 | 10.0.19044.2728 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2728 | 10.0.19045.2728 |
| microsoft | windows_11_21h2 | < 10.0.22000.1696 | 10.0.22000.1696 |
| microsoft | windows_11_22h2 | < 10.0.22000.1413 | 10.0.22000.1413 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1696 | 10.0.22000.1696 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.1413 | 10.0.22621.1413 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24168 | 6.2.9200.24168 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20865 | 6.3.9600.20865 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1607 | 10.0.20348.1607 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fqrg-vgqq-fff3: Windows Cryptographic Services Remote Code Execution Vulnerability
ghsa_unreviewed·2023-03-14
CVE-2023-23416 [HIGH] GHSA-fqrg-vgqq-fff3: Windows Cryptographic Services Remote Code Execution Vulnerability
Windows Cryptographic Services Remote Code Execution Vulnerability
Microsoft
Windows Cryptographic Services Remote Code Execution Vulnerability
vendor_msrc·2023-03-14·CVSS 7.8
CVE-2023-23416 [HIGH] CWE-20 Windows Cryptographic Services Remote Code Execution Vulnerability
Windows Cryptographic Services Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
For successful exploitation, a malicious certificate needs to be imported on an affected system. An attacker could upload a certificate to a service that processes or imports certificates, or an attacker could convince an authenticated user to import a certificate on their system.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from th
No detection rules found.
No public exploits indexed.
Qualys
The March 2023 Patch Tuesday Security Update Review | Qualys
blogs_qualys·2023-03-15·CVSS 9.8
[CRITICAL] The March 2023 Patch Tuesday Security Update Review | Qualys
#### Table of Contents
- Microsoft Patches for March 2023
- Adobe Patches for March 2023
- Zero-day Vulnerabilities Patched in March Patch Tuesday Edition
- Other Critical Severity Vulnerabilities Patched in March Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response withPatch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
- This Month in Vulnerabilities & Patches
Microsoft has released its monthly security update for March 2023. This month’s updates addressed various vulnerabilities in different products. Let’s go through this month’s Patch Tuesday details and discuss
Qualys
The March 2023 Patch Tuesday Security Update Review
blogs_qualys·2023-03-15·CVSS 9.8
[CRITICAL] The March 2023 Patch Tuesday Security Update Review
## Table of Contents
Microsoft Patches for March 2023
Adobe Patches for March 2023
Zero-day Vulnerabilities Patched in March Patch Tuesday Edition
Other Critical Severity Vulnerabilities Patched in March Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response withPatch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
This Month in Vulnerabilities & Patches
Microsoft has released its monthly security update for March 2023. This month’s updates addressed various vulnerabilities in different products. Let’s go through this month’s Patch Tuesday details and discuss the security
Talos
Microsoft Patch Tuesday for March 2023 — Snort rules and prominent vulnerabilities
blogs_talos·2023-03-14·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday for March 2023 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for March 2023 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing 83 vulnerabilities across the company’s hardware and software line, including two issues that are actively being exploited in the wild, continuing a trend of zero-days appearing in Patch Tuesdays over the past few months.
Two of the vulnerabilities included in March’s security update have been exploited in the wild, according to Microsoft, including one critical issue.
In all, eight of the issues disclosed this month are critical, while the remainder — outside of one — is “important.”
A moderate-severity vulnerability that’s already being exploited in the wild is CVE-2023-24880 , a security feature bypass vulnerability in Windows Smart
Talos
Microsoft Patch Tuesday for March 2023 — Snort rules and prominent vulnerabilities
blogs_talos·2023-03-14·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday for March 2023 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing 83 vulnerabilities across the company’s hardware and software line, including two issues that are actively being exploited in the wild, continuing a trend of zero-days appearing in Patch Tuesdays over the past few months.
Two of the vulnerabilities included in March’s security update have been exploited in the wild, according to Microsoft, including one critical issue.
In all, eight of the issues disclosed this month are critical, while the remainder — outside of one — is “important.”
A moderate-severity vulnerability that’s already being exploited in the wild is CVE-2023-24880, a security feature bypass vulnerability in Windows SmartScreen, a cloud-based anti-phishing and anti-malware feature included in several Microso
Tenable
Microsoft’s March 2023 Patch Tuesday Addresses 76 CVEs (CVE-2023-23397)
blogs_tenable·2023-03-14·CVSS 9.8
[CRITICAL] Microsoft’s March 2023 Patch Tuesday Addresses 76 CVEs (CVE-2023-23397)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Crowdstrike
March 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] March 2023 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
2023-03-14
Published