« Volver al listado

CVE-2023-36871

Estado: ModificadaMedia (6.5)—

Azure Active Directory Security Feature Bypass Vulnerability

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (10)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-36871",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 1809",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.17763.0",
              "lessThan": "10.0.17763.4645",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "32-bit Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 1809",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.0",
              "lessThan": "10.0.17763.4645",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "ARM64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2019",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.17763.0",
              "lessThan": "10.0.17763.4645",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2019 (Server Core installation)",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.17763.0",
              "lessThan": "10.0.17763.4645",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2022",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.20348.0",
              "lessThan": "10.0.20348.1850",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 11 version 21H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.0",
              "lessThan": "10.0.22000.2176",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems",
            "ARM64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 21H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.19043.0",
              "lessThan": "10.0.19044.3208",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "32-bit Systems",
            "ARM64-based Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 11 version 22H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.22621.0",
              "lessThan": "10.0.22621.1992",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "ARM64-based Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 22H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.19045.0",
              "lessThan": "10.0.19045.3208",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems",
            "ARM64-based Systems",
            "32-bit Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 1507",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.10240.0",
              "lessThan": "10.0.10240.20048",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "32-bit Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 1607",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.14393.0",
              "lessThan": "10.0.14393.6085",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "32-bit Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2016",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.14393.0",
              "lessThan": "10.0.14393.6085",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2016 (Server Core installation)",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.14393.0",
              "lessThan": "10.0.14393.6085",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        }
      ]
    }
  ],
  "published": "2023-07-11T18:15:20.597",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36871",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36871",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Azure Active Directory Security Feature Bypass Vulnerability"
    }
  ],
  "lastModified": "2026-06-17T06:07:15.943",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA7DB0E9-3DCD-4FAE-8F9A-20D15E061ED7",
              "versionEndExcluding": "10.0.10240.20048"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8557A170-443F-49D3-9041-0D883E6CB556",
              "versionEndExcluding": "10.0.14393.6085"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7CD9EA5-EB3A-4C42-B208-75590288F6F6",
              "versionEndExcluding": "10.0.17763.4645"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22A20A25-6FDE-4715-873E-E7FBF2DFABCA",
              "versionEndExcluding": "10.0.19041.3208"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7408C04A-729A-4CFF-8AF0-97A18BB2BD9C",
              "versionEndExcluding": "10.0.19045.3208"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F10BCA0D-417F-42E3-93BF-2C227357702B",
              "versionEndExcluding": "10.0.22000.2176"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1C277B2-DE09-453D-B33E-42917E11D0E5",
              "versionEndExcluding": "10.0.22621.1992"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "041FF8BA-0B12-4A1F-B4BF-9C4F33B7C1E7"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB79EE26-FC32-417D-A49C-A1A63165A968"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "821614DD-37DD-44E2-A8A4-FE8D23A33C3C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}