CVE-2023-35367: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6085Patch KB5028169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4645Patch KB5028168 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22175Patch KB5028226 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.21063Fixed in 6.3.9600.21075Patch KB5028223 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24374Patch KB5028233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26623Patch KB5028224 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20048Patch KB5028186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1992Patch KB5028185 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.3208Patch KB5028166 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1850Patch KB5028171 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.3208Patch KB5028166 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2176Patch KB5028182
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35367?
CVE-2023-35367 is rated as a critical severity vulnerability.
How does CVE-2023-35367 affect systems?
CVE-2023-35367 allows an attacker to execute remote code on affected systems, compromising system integrity.
How do I fix CVE-2023-35367?
To fix CVE-2023-35367, apply the relevant security updates provided by Microsoft.
Which systems are affected by CVE-2023-35367?
CVE-2023-35367 affects various versions of Windows, including Windows Server 2019, Windows 10, and Windows 11.
Is there any workaround for CVE-2023-35367?
There are no effective workarounds for CVE-2023-35367; patching is the recommended approach.