Lucene search

K
mscveMicrosoftMS:CVE-2023-38140
HistorySep 12, 2023 - 7:00 a.m.

Windows Kernel Information Disclosure Vulnerability

2023-09-1207:00:00
Microsoft
msrc.microsoft.com
9
windows
kernel
information
disclosure
vulnerability

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

17.7%

Affected configurations

Vulners
Node
microsoftwindows_server_2016Range<10.0.14393.6252
OR
microsoftwindows_server_2016Range<10.0.14393.6252
OR
microsoftwindows_10_1607Range<10.0.14393.6252
OR
microsoftwindows_10_1607Range<10.0.14393.6252
OR
microsoftwindows_10_22h2Range<10.0.19045.3448
OR
microsoftwindows_10_22h2Range<10.0.19045.3448
OR
microsoftwindows_10_22h2Range<10.0.19045.3448
OR
microsoftwindows_10_21h2Range<10.0.19044.3448
OR
microsoftwindows_10_21h2Range<10.0.19044.3448
OR
microsoftwindows_10_21h2Range<10.0.19044.3448
OR
microsoftwindows_11_21h2Range<10.0.22000.2416
OR
microsoftwindows_11_21h2Range<10.0.22000.2416
OR
microsoftwindows_server_2022Range<10.0.20348.1970
OR
microsoftwindows_server_2022Range<10.0.20348.1964
OR
microsoftwindows_server_2022Range<10.0.20348.1970
OR
microsoftwindows_server_2022Range<10.0.20348.1964
OR
microsoftwindows_server_2019Range<10.0.17763.4851
OR
microsoftwindows_server_2019Range<10.0.17763.4851
OR
microsoftwindows_10_1809Range<10.0.17763.4851
OR
microsoftwindows_10_1809Range<10.0.17763.4851
OR
microsoftwindows_10_1809Range<10.0.17763.4851
VendorProductVersionCPE
microsoftwindows_server_2016*cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
microsoftwindows_10_1607*cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*
microsoftwindows_10_22h2*cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*
microsoftwindows_10_21h2*cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*
microsoftwindows_11_21h2*cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*
microsoftwindows_server_2022*cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
microsoftwindows_server_2019*cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
microsoftwindows_10_1809*cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

17.7%