First published: Tue Jul 11 2023(Updated: )
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server 2012 x64 | ||
Microsoft Windows Server 2012 x64 | ||
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft Windows Server 2008 Itanium | =r2-sp1 | |
Microsoft Windows Server 2012 x64 | ||
Microsoft Windows Server 2012 x64 | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35351 is a vulnerability in Windows Active Directory Certificate Services (AD CS) that allows remote code execution.
CVE-2023-35351 has a severity rating of 6.6, classified as high.
CVE-2023-35351 affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2016, Windows Server 2019, and Windows Server 2022.
To fix CVE-2023-35351, you should apply the relevant patches provided by Microsoft. Please refer to the Microsoft support links for the specific patches for your Windows Server version.
You can find more information about CVE-2023-35351 on the Microsoft Security Response Center website.