[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Windows Search Security Feature Bypass Vulnerability - CVE-2023-36564

ID: oval:org.secpod.oval:def:93617Date: (C)2023-10-11   (M)2024-03-06
Class: VULNERABILITYFamily: windows




Windows Search Security Feature Bypass Vulnerability. The user would have to click on a specially crafted URL to be compromised by the attacker. A security feature bypass vulnerability exists when MapUrlToZone fails to correctly handle certain paths. This could allow an attacker to plant files without Mark-of-the-Web (MotW). To exploit this vulnerability, an attacker could email or otherwise provide a specially crafted link to a victim and convince them to open it.

Platform:
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Reference:
CVE-2023-36564
CVE    1
CVE-2023-36564
CPE    25
cpe:/o:microsoft:windows_server_2008:r2:sp1:x64
cpe:/o:microsoft:windows_server_2008:::x64
cpe:/o:microsoft:windows_server_2008:::x86
cpe:/o:microsoft:windows_10:1809::x64
...

© SecPod Technologies