CVE-2023-21690: Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20821Patch KB5022894 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24116Patch KB5022895 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19747Patch KB5022858 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26366Patch KB5022874 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5717Patch KB5022838 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1574Patch KB5022836 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1265Patch KB5022845 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1547Fixed in 10.0.20348.1540Patch KB5022921 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4010Patch KB5022840
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21690?
The severity of CVE-2023-21690 is rated as critical due to its potential for remote code execution.
How do I fix CVE-2023-21690?
To fix CVE-2023-21690, apply the latest security patches provided by Microsoft for your affected version of Windows.
Which versions of Windows are affected by CVE-2023-21690?
CVE-2023-21690 affects various versions of Windows 10, Windows 11, and Windows Server including specific builds and architectures.
What exploitation methods are possible for CVE-2023-21690?
CVE-2023-21690 can be exploited remotely without user interaction, allowing attackers to execute arbitrary code on the system.
Are there any mitigations for CVE-2023-21690?
While the primary defense against CVE-2023-21690 is applying patches, additional network-level protections can help mitigate potential exploits.