CVE-2023-21691: Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability
Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26366Patch KB5022874 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21915Patch KB5022893 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24116Patch KB5022895 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20821Patch KB5022894 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19747Patch KB5022858 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5717Patch KB5022838 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1265Patch KB5022845 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4010Patch KB5022840 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1574Patch KB5022836 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1547Fixed in 10.0.20348.1540Patch KB5022921 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2604Patch KB5022834
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21691?
CVE-2023-21691 has a severity rating classified as critical, indicating a significant risk of information disclosure.
How do I fix CVE-2023-21691?
To fix CVE-2023-21691, apply the relevant security patches provided by Microsoft for affected Windows Server and Windows 10 versions.
Which systems are affected by CVE-2023-21691?
CVE-2023-21691 affects several versions of Windows Server and Windows 10, including specific server core installations.
Is there a workaround for CVE-2023-21691?
While applying patches is the primary solution, disabling PEAP may serve as a temporary workaround for CVE-2023-21691.
What type of vulnerability is CVE-2023-21691?
CVE-2023-21691 is classified as an information disclosure vulnerability within the Protected Extensible Authentication Protocol.