CVE-2023-21687: HTTP.sys Information Disclosure Vulnerability
HTTP.sys Information Disclosure Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1574Patch KB5022836 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1265Patch KB5022845 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1547Fixed in 10.0.20348.1540Patch KB5022921
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21687?
CVE-2023-21687 is classified as a Moderate severity vulnerability.
How do I fix CVE-2023-21687?
To remediate CVE-2023-21687, install the latest security updates provided by Microsoft for affected Windows versions.
Which Microsoft products are affected by CVE-2023-21687?
CVE-2023-21687 affects Microsoft Windows 11 and Windows Server 2022 across different versions.
Can CVE-2023-21687 lead to information disclosure?
Yes, CVE-2023-21687 can potentially lead to information disclosure, exposing sensitive data.
Is there a patch available for CVE-2023-21687?
Yes, Microsoft has released patches for CVE-2023-21687 as part of their security updates.