CVE-2023-31308: Out-of-bounds Read
Published Aug 31, 2026
·Updated
A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of service due to out-of-bounds memory read.
Affected Software
1 affected component
Microsoft SMU
Event History
Aug 31, 2026
CVE Published
via MITRE·06:24 PM
Data Sourced
via MITRE·06:24 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attack vector is local and requires low privileges. No user interaction is required, but the attacker must be able to operate a malicious virtual function that can invoke the affected SMU command handlers.
2
What is the expected security impact?
The reported impact is denial of service with low availability impact. The provided CVSS vector indicates no confidentiality or integrity impact.