CVE-2023-46224: Critical severity microsoft windows operating system vulnerability
Published Dec 19, 2023
·Updated
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
Affected Software
2 affected components
All of the following
Microsoft Windows
Ivanti Avalanche<6.4.2
Event History
Dec 19, 2023
CVE Published
03:43 PM
Data Sourced
03:43 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-46224?
CVE-2023-46224 is considered to be of high severity due to its potential for causing Denial of Service or remote code execution.
2
How do I fix CVE-2023-46224?
To mitigate CVE-2023-46224, users should upgrade their Ivanti Avalanche software to the latest version that addresses this vulnerability.
3
What types of attacks can CVE-2023-46224 facilitate?
CVE-2023-46224 can facilitate memory corruption that may lead to Denial of Service (DoS) attacks or remote code execution.
4
Which versions of Ivanti Avalanche are affected by CVE-2023-46224?
CVE-2023-46224 affects Ivanti Avalanche versions prior to 6.4.2.
5
Is Microsoft Windows affected by CVE-2023-46224?
Microsoft Windows is not affected by CVE-2023-46224, as the vulnerability is specific to Ivanti Avalanche.