發布時間:2023-05-04
來源:圣博潤| CVE ID | CVE-2023-23410 | 公開日期 | 2023-03-21 |
| 危害級別 | 高危 | 攻擊復雜程度 | 低 |
| POC/EXP | 已公開 | 攻擊途徑 | 遠程網絡 |
HTTP.sys是Microsoft Windows處理HTTP請求的內核驅動(dong)程序。Windows HTTP.sys中存在整數溢出漏(lou)洞(dong),由(you)于對ServiceName的原始(shi)輸入長度(du)校驗錯(cuo)誤,可以通過構造(zao)惡意內容來觸發該漏(lou)洞(dong),導致(zhi)權(quan)限提(ti)升或拒絕服務。
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 for 32-bit Systems
Windows 10 Version 22H2 for 32-bit Systems
Windows 10 Version 22H2 for ARM64-based Systems
Windows 10 Version 22H2 for x64-based Systems
Windows 11 Version 22H2 for x64-based Systems
Windows 11 Version 22H2 for ARM64-based Systems
Windows 10 Version 21H2 for x64-based Systems
Windows 10 Version 21H2 for ARM64-based Systems
Windows 10 Version 21H2 for 32-bit Systems
Windows 11 version 21H2 for ARM64-based Systems
Windows 11 version 21H2 for x64-based Systems
Windows 10 Version 20H2 for ARM64-based Systems
Windows 10 Version 20H2 for 32-bit Systems
Windows 10 Version 20H2 for x64-based Systems
Windows Server 2022 (Server Core installation)
Windows Server 2022
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
目前微軟(ruan)已經發布了該漏洞的補(bu)丁,受影響用戶可及時安裝。
//msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23410
//msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23410
//www.numencyber.com/cve-2023-23410-analysis/
地址:北京市海(hai)淀區東冉北街(jie)9號寶藍?金園(yuan)網絡安全(quan)服務產業園(yuan) A幢(chuang)B3010室
郵箱:support@thinkpage.net
郵編:100044
技術支持熱(re)線:010-8213-8088、400-966-2332
網址://thinkpage.net/
北京圣(sheng)博潤高新(xin)技術股份有(you)限公司
京ICP備07015083號-1QQ:1423326688
座機:010-8213-8088
返回頂部