CVE-2023-21805: Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21915Fixed in 1.1.0.0Patch KB5022835 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20821Fixed in 6.3.9600.20818Patch KB5022835 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5717Patch KB5022838 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24116Fixed in 1.1.0.0Patch KB5022835 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26366Fixed in 1.1.0.0Patch KB5022835 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19747Patch KB5022858 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1265Patch KB5022845 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1574Patch KB5022836 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2604Patch KB5022834 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1547Fixed in 10.0.20348.1540Patch KB5022921 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4010Patch KB5022840
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21805?
CVE-2023-21805 has been assigned a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2023-21805?
To fix CVE-2023-21805, apply the latest security patches provided by Microsoft for your affected Windows version.
Which systems are affected by CVE-2023-21805?
CVE-2023-21805 affects multiple Microsoft Windows operating systems including Windows Server 2008, 2012, 2016, 2019, and 2022, as well as Windows 10 and 11.
What happens if CVE-2023-21805 is exploited?
If exploited, CVE-2023-21805 could allow an attacker to execute arbitrary code on the affected system, leading to full system compromise.
Is there a workaround for CVE-2023-21805?
Currently, implementing security updates is the primary recommendation, as there are no officially documented workarounds for CVE-2023-21805.