First published: Tue Oct 10 2023(Updated: )
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2019 | ||
Windows 11 | =22H2 | |
Windows 11 | =22H2 | |
Windows 11 | =21H2 | |
Windows 11 | =21H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows 10 | <10.0.10240.20232 | |
Microsoft Windows 10 | <10.0.14393.6351 | |
Microsoft Windows 10 | <10.0.17763.4974 | |
Microsoft Windows 10 | <10.0.19041.3570 | |
Microsoft Windows 10 | <10.0.19045.3570 | |
Windows 11 | <10.0.22000.2538 | |
Windows 11 | <10.0.22621.2428 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 | ||
Windows 10 | =1809 | |
Windows 10 | =1809 | |
Windows 10 | =1809 | |
Windows 10 | =22H2 | |
Windows 10 | =22H2 | |
Windows 10 | =22H2 | |
Windows 10 | =1607 | |
Windows 10 | =1607 | |
Windows 10 | =21H2 | |
Windows 10 | =21H2 | |
Windows 10 | =21H2 | |
Windows 10 | ||
Windows 10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Layer 2 Tunneling Protocol Remote Code Execution Vulnerability is CVE-2023-41774.
The severity of CVE-2023-41774 is critical with a CVSS score of 8.1.
The affected software products include Microsoft Windows 10 (versions 21H2 and 22H2), Windows Server 2008 (SP2 and Server Core Installation), Windows Server 2008 R2 (SP1 and Server Core Installation), Windows Server 2012 (including Server Core Installation), Windows Server 2012 R2 (including Server Core Installation), Windows Server 2016 (including Server Core Installation), Windows Server 2019 (including Server Core Installation), and Windows Server 2022 (including Server Core Installation).
To fix CVE-2023-41774, users should apply the relevant patches provided by Microsoft. Links to the patches can be found in the Microsoft support articles for each affected software product.
More information about CVE-2023-41774 can be found on the Microsoft Security Response Center website at the provided reference link.