CVE-2023-36435: Microsoft QUIC Denial of Service Vulnerability
Impact The MsQuic server will continue to leak memory until no more is available, resulting in a denial of service.
Patches The following patch was made:
- Fix Memory Leak from Multiple Decodes of TP - https://github.com/microsoft/msquic/commit/d364feeda0dd8b729eca6fef149c1ef98630f0cb
Workarounds Beyond upgrading to the patched versions, there is no other workaround.
Other sources
Microsoft QUIC Denial of Service Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-36435?
CVE-2023-36435 is a Microsoft QUIC Denial of Service Vulnerability.
What is the severity of CVE-2023-36435?
The severity of CVE-2023-36435 is high with a CVSS score of 7.5.
Which software products are affected by CVE-2023-36435?
Microsoft Windows 11 (versions 21H2 and 22H2), Microsoft Windows Server 2022, and Microsoft .NET 7.0 are affected by CVE-2023-36435.
How can I fix CVE-2023-36435 on Windows 11 (version 21H2)?
To fix CVE-2023-36435 on Windows 11 (version 21H2), install the patch KB5031358 from the Microsoft Catalog Update site.
How can I fix CVE-2023-36435 on Windows Server 2022?
To fix CVE-2023-36435 on Windows Server 2022, install the patch KB5031364 from the Microsoft Catalog Update site.