CVE-2023-23378 is a Remote Code Execution vulnerability affecting Microsoft Print 3D. With a CVSS score of 7.8 (High), it allows an unauthenticated attacker to execute arbitrary code on a vulnerable system if a user is tricked into opening a malicious file. While not listed in CISA's KEV catalog, this vulnerability was addressed in Microsoft's February 2023 Patch Tuesday, indicating its significance. There is no public exploit code available, and community discussion and media coverage are limited, though it was mentioned in a BleepingComputer article regarding the patch release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.791CPE matchmatch criteria | cpe:2.3:a:microsoft:print_3d:*:*:*:*:*:*:*:* | ||
>= 3.3.0, < 3.3.791CPE match | cpe:2.3:a:microsoft:print_3d:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.