CVE-2023-36046 is a Windows Authentication Denial of Service vulnerability affecting Windows 11 and Windows Server 2022. With a CVSS score of 7.1 (HIGH), it allows a local, low-privileged attacker to achieve a denial of service with low attack complexity, impacting system availability and integrity. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. While community discussion and media coverage are minimal, Microsoft addressed this flaw in their November 2023 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.22000.2600CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.22000.2600CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:x64:* | ||
< 10.0.22621.2715CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.22621.2715CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:* | ||
< 10.0.22621.2715CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.