CVE-2023-21699: Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20821Patch KB5022894 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24116Patch KB5022895 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21915Patch KB5022893 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26366Patch KB5022874 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5717Patch KB5022838 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19747Patch KB5022858 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4010Patch KB5022840
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21699?
CVE-2023-21699 is rated as a medium-severity vulnerability that can lead to information disclosure.
How do I fix CVE-2023-21699?
To fix CVE-2023-21699, you need to apply the latest security updates provided by Microsoft for the affected Windows versions.
Which versions of Windows are affected by CVE-2023-21699?
CVE-2023-21699 affects various versions of Windows 10, Windows Server 2008 R2, Windows Server 2012, and Windows Server 2016.
What type of vulnerability is CVE-2023-21699?
CVE-2023-21699 is classified as an information disclosure vulnerability in the Windows Internet Storage Name Service (iSNS).
When was CVE-2023-21699 disclosed?
CVE-2023-21699 was disclosed in early 2023, following an assessment of the vulnerability by Microsoft.