CVE-2023-28291
Published Apr 11, 2023
Last updated 6 months ago
Overview
- Description
- Raw Image Extension Remote Code Execution Vulnerability
- Source
- secure@microsoft.com
- NVD status
- Modified
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
- secure@microsoft.com
- CWE-20
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:raw_image_extension:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8D9D1918-77CE-4EC6-AFAC-6FFFAC2CC4C1", "versionEndExcluding": "2.1.60611.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows_10_20h2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6AFD13A6-A390-4400-9029-2F4058CA17E2" }, { "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2F513002-D8C1-4D3A-9F79-4B52498F67E9" }, { "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D4793BFB-2E4E-4067-87A5-4B8749025CA3" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:raw_image_extension:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C657556D-78C4-4ED5-8322-18CB038FF1D0", "versionEndExcluding": "2.0.60612.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows_11_21h2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "BB4AE761-6FAC-4000-A63D-42CE3FAB8412" } ], "operator": "OR" } ], "operator": "AND" } ]