CVE-2023-24876
published 2023-03-14CVE-2023-24876: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.40%
69.5th percentile
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19805 | 10.0.10240.19805 |
| microsoft | windows_10_1607 | < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_10_1809 | < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_10_20h2 | < 10.0.19042.2728 | 10.0.19042.2728 |
| microsoft | windows_10_21h2 | < 10.0.19044.2728 | 10.0.19044.2728 |
| microsoft | windows_10_22h2 | < 10.0.19045.2728 | 10.0.19045.2728 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19805 | 10.0.10240.19805 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2728 | 10.0.19042.2728 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2728 | 10.0.19044.2728 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2728 | 10.0.19045.2728 |
| microsoft | windows_11_21h2 | < 10.0.22000.1696 | 10.0.22000.1696 |
| microsoft | windows_11_22h2 | < 10.0.22000.1413 | 10.0.22000.1413 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1696 | 10.0.22000.1696 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.1413 | 10.0.22621.1413 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24168 | 6.2.9200.24168 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20865 | 6.3.9600.20865 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1607 | 10.0.20348.1607 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector involves sending a specially crafted XPS file to a shared printer; monitor for anomalous XPS file submissions to shared printers from authenticated users with normal privileges. ↗
- ·Exploitation is considered 'Less Likely' for the latest software release but 'More Likely' for older software releases; prioritize patching older Windows versions accordingly. ↗
- ·Customer action is required — apply the relevant Microsoft patches (e.g., KB5023702, KB5023705, KB5023696, KB5023706, KB5023756, KB5023752) to remediate the vulnerable Microsoft PostScript and PCL6 Class Printer Driver. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
vendor_msrc·2023-03-14·CVSS 8.8
CVE-2023-24876 [HIGH] CWE-122 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An authenticated attacker with normal privileges could send a modified XPS file to a shared printer, which can result in a remote code execution.
Microsoft PostScript Printer Driver: Microsoft PostScript Printer Driver
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023702
Reference: https://support.microsoft.com/help/5023702
Reference: https://catalog.update.microsoft.com/v7/site/Sea
GHSA
GHSA-4pgc-mf63-3x2r: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
ghsa_unreviewed·2023-03-14
CVE-2023-24876 [HIGH] GHSA-4pgc-mf63-3x2r: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Qualys
The March 2023 Patch Tuesday Security Update Review | Qualys
blogs_qualys·2023-03-15·CVSS 9.8
[CRITICAL] The March 2023 Patch Tuesday Security Update Review | Qualys
#### Table of Contents
- Microsoft Patches for March 2023
- Adobe Patches for March 2023
- Zero-day Vulnerabilities Patched in March Patch Tuesday Edition
- Other Critical Severity Vulnerabilities Patched in March Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response withPatch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
- This Month in Vulnerabilities & Patches
Microsoft has released its monthly security update for March 2023. This month’s updates addressed various vulnerabilities in different products. Let’s go through this month’s Patch Tuesday details and discuss
Qualys
The March 2023 Patch Tuesday Security Update Review
blogs_qualys·2023-03-15·CVSS 9.8
[CRITICAL] The March 2023 Patch Tuesday Security Update Review
## Table of Contents
Microsoft Patches for March 2023
Adobe Patches for March 2023
Zero-day Vulnerabilities Patched in March Patch Tuesday Edition
Other Critical Severity Vulnerabilities Patched in March Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response withPatch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
This Month in Vulnerabilities & Patches
Microsoft has released its monthly security update for March 2023. This month’s updates addressed various vulnerabilities in different products. Let’s go through this month’s Patch Tuesday details and discuss the security
2023-03-14
Published