CVE-2023-29367

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 14, 2023
Updated: May 29, 2024
CWE ID 908

Summary

CVE-2023-29367 is a remote code execution vulnerability affecting the iSCSI Target WMI Provider. An attacker can exploit this weakness by sending crafted WMI queries to a targeted system, ultimately leading to the execution of arbitrary code. Successful exploitation allows the attacker to gain control over the affected system, potentially resulting in unauthorized access or data theft. This issue poses a significant risk to organizations using iSCSI Target servers and should be addressed promptly by installing the available patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2012
  • Windows Server 2022
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2012 R2

Affected Vendors

  • Microsoft