Cloud Defense Logo

Products

Solutions

Company

Book A Live Demo

CVE-2023-36396 Explained : Impact and Mitigation

Learn about CVE-2023-36396, a high-severity vulnerability, enabling remote code execution in Windows 11 versions 22H2 and 23H2. Discover mitigation strategies here.

A detailed overview of the Windows Compressed Folder Remote Code Execution Vulnerability affecting Windows 11 versions 22H2, 23H2.

Understanding CVE-2023-36396

This article provides insights into the impact, technical details, and mitigation strategies related to CVE-2023-36396.

What is CVE-2023-36396?

The CVE-2023-36396, known as the Windows Compressed Folder Remote Code Execution Vulnerability, allows attackers to execute malicious code on affected systems remotely.

The Impact of CVE-2023-36396

The vulnerability poses a high risk (CVSS base score: 7.8) by enabling remote code execution, potentially leading to unauthorized access, data theft, and system compromise.

Technical Details of CVE-2023-36396

Learn about the vulnerability description, affected systems, and exploitation mechanisms.

Vulnerability Description

The flaw in Windows Compressed Folder allows threat actors to execute arbitrary code, jeopardizing system integrity.

Affected Systems and Versions

        Windows 11 version 22H2: Affected versions less than 10.0.22621.2715 on ARM64 and x64-based systems.
        Windows 11 version 23H2: Affected versions less than 10.0.22631.2715 on ARM64-based systems.
        Windows 11 Version 23H2: Affected versions less than 10.0.22631.2715 on x64-based systems.

Exploitation Mechanism

Attackers can exploit this vulnerability remotely, gaining unauthorized access and executing malicious activities on the compromised systems.

Mitigation and Prevention

Discover immediate steps and long-term security practices to safeguard against CVE-2023-36396.

Immediate Steps to Take

        Apply security updates and patches released by Microsoft promptly.
        Consider disabling the affected feature temporarily until a patch is applied.

Long-Term Security Practices

        Regularly update and maintain system security configurations.
        Implement network segmentation and access controls to limit exposure.

Patching and Updates

Stay informed about security advisories and updates from Microsoft to address vulnerabilities and enhance system security.

Popular CVEs

CVE Id

Published Date

Is your System Free of Underlying Vulnerabilities?
Find Out Now