CVE-2023-36706
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2023-36706 is a newly discovered vulnerability affecting Microsoft's Windows Deployment Services. This issue allows unauthenticated attackers to obtain sensitive information by sending specially crafted requests to the affected WDS server. The vulnerability could potentially lead to the disclosure of server configuration details and other critical information, posing a significant risk to organizational security. Microsoft has released a patch to address this issue, and administrators are strongly encouraged to install it as soon as possible to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
- Windows Server 2022
- Microsoft Windows Server 2019
Affected Vendors
- Microsoft