CVE-2023-29367
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jun 14, 2023
Updated: May 29, 2024
CWE ID 908
Summary
CVE-2023-29367 is a remote code execution vulnerability affecting the iSCSI Target WMI Provider. An attacker can exploit this weakness by sending crafted WMI queries to a targeted system, ultimately leading to the execution of arbitrary code. Successful exploitation allows the attacker to gain control over the affected system, potentially resulting in unauthorized access or data theft. This issue poses a significant risk to organizations using iSCSI Target servers and should be addressed promptly by installing the available patch.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Microsoft Windows Server 2016
- Microsoft Windows Server 2012
- Windows Server 2022
- Microsoft Windows Server 2019
- Microsoft Windows Server 2012 R2
Affected Vendors
- Microsoft