Severity

Medium

Analysis Summary

CVE-2023-36406 CVSS:5.5

Microsoft Windows Hyper-V could allow a local authenticated attacker to obtain sensitive information. By executing a specially crafted program, an attacker could exploit this vulnerability to obtain sensitive information from memory contents in kernel space and use this information to launch further attacks against the affected system.

CVE-2023-36407 CVSS:7.8

Microsoft Windows Hyper-V could allow a local authenticated attacker to gain elevated privileges on the system. By executing a specially crafted program, an authenticated attacker could exploit this vulnerability to obtain SYSTEM privileges.

CVE-2023-36408 CVSS:7.8

Microsoft Windows Hyper-V could allow a local authenticated attacker to gain elevated privileges on the system. By executing a specially crafted program, an authenticated attacker could exploit this vulnerability to obtain SYSTEM privileges.

Impact

  • Information Disclosure
  • Privileges Escalation

Indicators Of Compromise

CVE

  • CVE-2023-36406
  • CVE-2023-36407
  • CVE-2023-36408

Affected Vendors

Microsoft

Affected Products

  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2022
  • Microsoft Windows 10 1809 for x64-based Systems
  • Microsoft Windows 10 1607 for x64-based Systems
  • Microsoft Windows Server (Server Core installation) 2019
  • Microsoft Windows Server (Server Core installation) 2016
  • Microsoft Windows Server (Server Core installation) 2022
  • Microsoft Windows 10 21H2 for x64-based Systems
  • Microsoft Windows 11 22H2 for ARM64-based Systems
  • Microsoft Windows 11 22H2 for x64-based Systems
  • Microsoft Windows 10 22H2 for x64-based Systems
  • Microsoft Windows 11 21H2 for ARM64-based Systems
  • Microsoft Windows 11 21H2 for x64-based Systems
  • Microsoft Windows Server (Server Core installation) 2022 23H2
  • Microsoft Windows 11 23H2 for ARM64-based Systems
  • Microsoft Windows 11 23H2 for x64-based Systems

Remediation

Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

CVE-2023-36406

CVE-2023-36407

CVE-2023-36408