CVE-2023-32022 is a security feature bypass vulnerability affecting various versions of Microsoft Windows Server, including 2012, 2016, 2019, and 2022. With a CVSS score of 7.6 (HIGH), this vulnerability allows an authenticated attacker to bypass security features over the network with low attack complexity, potentially leading to partial confidentiality, integrity, and full availability impacts. While there is no known active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage. It is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.