CVE-2023-38147 is a high-severity Remote Code Execution (RCE) vulnerability affecting Windows Miracast Wireless Display, impacting various versions of Windows 10, 11, and Server. With a CVSS score of 8.8, it can be exploited by an unauthenticated attacker over an adjacent network with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not listed in CISA's KEV catalog, its mention in community discussions and media coverage, including BleepingComputer's report on Microsoft's September 2023 Patch Tuesday, indicates some awareness. Organizations should prioritize patching due to the significant potential impact despite the lack of active exploitation evidence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.10240.20162CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:* | ||
< 10.0.14393.6252CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:* | ||
< 10.0.17763.4851CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:* | ||
< 10.0.19044.3448CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.3448CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.