CVE-2023-38148 is a critical Remote Code Execution vulnerability affecting Microsoft Windows 10, 11, and Server 2022 via the Internet Connection Sharing (ICS) feature. With a CVSS score of 8.8 (High), it allows unauthenticated attackers on an adjacent network to execute arbitrary code with high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, its high EPSS score and significant media coverage suggest a strong potential for future exploitation. There are no public exploit modules or proof-of-concept codes available, but the vulnerability has garnered substantial community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.19044.3448CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.3448CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22000.2416CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.20348.1960CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.