Record summary

CVE-2023-36563 has a selected CVSS score of 6.5 (medium). CISA lists CVE-2023-36563 in KEV.

Description

Microsoft WordPad Information Disclosure Vulnerability

Description source: GitHub Advisory

Exploitation context

Known exploitation

CISA KEV
Listed · Oct 10, 2023 · CISA
VulnCheck KEV
Listed · Oct 10, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 23, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 21
ProductSourceVersion rangeStatus
CVE List10.0.10240.0 to < 10.0.10240.20232affected
CVE List10.0.14393.0 to < 10.0.14393.6351affected
CVE List10.0.17763.0 to < 10.0.17763.4974affected
10.0.0 to < 10.0.17763.4974affected
CVE List10.0.19043.0 to < 10.0.19041.3570affected
CVE List10.0.19045.0 to < 10.0.19045.3570affected
CVE List10.0.0 to < 10.0.22000.2538affected
CVE List10.0.22621.0 to < 10.0.22621.2428affected
CVE List6.0.6003.0 to < 6.0.6003.22317affected
CVE List6.1.7601.0 to < 6.1.7601.26769affected

Windows Server 2008 R2 Service Pack 1 (Server Core installation)

Browse Microsoft / Windows Server 2008 R2 Service Pack 1 (Server Core installation)
CVE List6.1.7601.0 to < 6.1.7601.26769affected

Windows Server 2008 Service Pack 2 (Server Core installation)

Browse Microsoft / Windows Server 2008 Service Pack 2 (Server Core installation)
CVE List6.0.6003.0 to < 6.0.6003.22317affected
CVE List6.2.9200.0 to < 6.2.9200.24523affected

References

3