CVE-2023-21689: Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24116Patch KB5022895 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20821Patch KB5022894 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26366Patch KB5022874 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5717Patch KB5022838 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19747Patch KB5022858 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1265Patch KB5022845 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1574Patch KB5022836 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4010Patch KB5022840 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1547Fixed in 10.0.20348.1540Patch KB5022921
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21689?
CVE-2023-21689 has been evaluated with a high severity rating as it allows for remote code execution.
How do I fix CVE-2023-21689?
To fix CVE-2023-21689, update your affected Microsoft software to the latest security patches provided by Microsoft.
What software is affected by CVE-2023-21689?
CVE-2023-21689 affects various Microsoft products, including Windows Server 2016, Windows 10, Windows Server 2019, and Windows 11.
Can CVE-2023-21689 be exploited remotely?
Yes, CVE-2023-21689 can be exploited remotely, allowing attackers to execute arbitrary code.
Is there a workaround for CVE-2023-21689?
Currently, applying the relevant security updates is the recommended method to mitigate the risk associated with CVE-2023-21689, as there are no known effective workarounds.