cbcvebase.
CVE-2023-36397
published 2023-11-14

CVE-2023-36397: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

PriorityP272critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
17.51%
96.8th percentile
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2030810.0.10240.20308
microsoftwindows_10_1607< 10.0.14393.645210.0.14393.6452
microsoftwindows_10_1809< 10.0.17763.512210.0.17763.5122
microsoftwindows_10_21h2< 10.0.19041.369310.0.19041.3693
microsoftwindows_10_22h2< 10.0.19045.369310.0.19045.3693
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2030810.0.10240.20308
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.645210.0.14393.6452
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.512210.0.17763.5122
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.512210.0.17763.5122
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19043.369310.0.19043.3693
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.369310.0.19045.3693
microsoftwindows_11_21h2< 10.0.22000.260010.0.22000.2600
microsoftwindows_11_22h2< 10.0.22621.271510.0.22621.2715
microsoftwindows_11_23h2< 10.0.22621.271510.0.22621.2715
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.260010.0.22000.2600
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.271510.0.22621.2715
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.271510.0.22631.2715
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.271510.0.22631.2715
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.268166.1.7601.26816
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.223676.0.6003.22367
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.245696.2.9200.24569
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.216686.3.9600.21668

Detection & IOCsextracted from sources · hover to see the quote

portTCP/1801
snort
62627
snort
62628
snort
62630
snort
62631
snort
62632
snort
62633
snort
62641
snort
62642
snort
62643
snort
62644
snort
300751
snort
300752
snort
300753
snort
300757
snort
300758
  • Check for the Windows Message Queuing service running and TCP port 1801 actively listening — both conditions must be true for a host to be exploitable.
  • Exploitation requires the Windows Message Queuing (MSMQ) service to be enabled; hunt for unexpected enablement of this service on internet-facing or PGM Server hosts.
  • Trigger condition is a specially crafted file sent over the network to a PGM Server environment with MSMQ running; monitor for anomalous inbound network traffic to TCP/1801 from untrusted sources.
  • ·The Talos Snort rule set covers multiple November 2023 Patch Tuesday CVEs, not exclusively CVE-2023-36397; confirm which specific rule IDs map to this CVE before deploying.
  • ·Microsoft rates exploitation of CVE-2023-36397 as 'Less Likely' and it has not been publicly disclosed or exploited in the wild as of the advisory date.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.