CVE-2023-32084 is a Denial of Service vulnerability affecting HTTP.sys in various Microsoft Windows versions, including Windows 10, 11, and Server editions. This vulnerability carries a high severity CVSS score of 7.5, indicating it can be exploited remotely with low attack complexity to cause a complete denial of service. While there is no evidence of active exploitation, public exploit code, or Metasploit modules, the vulnerability has received some community discussion and media coverage. Organizations should prioritize patching affected systems to mitigate the risk of service disruption.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.4645CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:* | ||
< 10.0.22000.2176CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.22621.1992CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.