CVE-2023-21806 is a high-severity spoofing vulnerability affecting Microsoft Power BI Report Server. It allows an authenticated attacker to execute code remotely with low privileges, requiring user interaction, and has a significant impact on confidentiality, with some impact on integrity and availability. While not actively exploited in the wild and lacking public exploit code, its inclusion in a Patch Tuesday update and mentions in cybersecurity news indicate some community awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.0.1111.115CPE matchmatch criteria | cpe:2.3:a:microsoft:power_bi_report_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.