CVE-2023-36584: Windows Mark of the Web Security Feature Bypass Vulnerability
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
Other sources
Windows Mark of the Web Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26769Patch KB5031441 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.21620Patch KB5031407 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24523Patch KB5031427 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22317Patch KB5031411 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6351Patch KB5031362 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20232Patch KB5031377 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.3570Patch KB5031356 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.3570Patch KB5031356 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.2428Patch KB5031354 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2538Patch KB5031358 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2031Patch KB5031364 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4974Patch KB5031361
Event History
Frequently Asked Questions
What is CVE-2023-36584?
CVE-2023-36584 is a Windows Mark of the Web Security Feature Bypass Vulnerability.
What is the severity of CVE-2023-36584?
CVE-2023-36584 has a severity of high.
Which software is affected by CVE-2023-36584?
CVE-2023-36584 affects Windows 10, Windows Server 2008, Windows Server 2022, Windows Server 2008 R2, Windows Server 2019, Windows Server 2012, Windows Server 2012 R2, Windows 11.
How can I fix CVE-2023-36584?
To fix CVE-2023-36584, install the appropriate security update provided by Microsoft.
Where can I find more information about CVE-2023-36584?
You can find more information about CVE-2023-36584 on the Microsoft Security Response Center website.