CVE-2023-32083 is a Microsoft Failover Cluster information disclosure vulnerability affecting Windows Server 2016, 2019, and 2022. This medium-severity flaw (CVSS 4.9) allows a highly privileged attacker to remotely obtain sensitive information with low attack complexity, though it does not impact integrity or availability. There is currently no known active exploitation, public exploit code, or Metasploit modules, and it is not listed on CISA's KEV catalog. While community discussion and media coverage are minimal, organizations should still apply available patches to mitigate potential risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.