2023年3月31日星期五

Microsoft Windows Snipping Tool Information Disclosure Vulnerability

Release Date: 31 Mar 2023

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

A vulnerability has been identified in Microsoft Windows Snipping Tool, a remote user can exploit this vulnerability to trigger information disclosure on the targeted system.

 

Note:
Proof of Concept exploit code is publicly available for CVE-2023-28303.


Impact

  • Information Disclosure

System / Technologies affected

  • Snip & Sketch in Windows 10 prior to 10.2008.3001.0
  • Snipping Tool in Windows 11 prior to 11.2302.20.0

Please refer to the link below for detail:

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28303


Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor.

  • Windows 10:Update to version 10.2008.3001.0 or later
  • Windows 11: Update to version 11.2302.20.0 or later

 

 


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

惡意軟件警報 - 零售商成為 Scattered Spider 黑客組織勒索軟件攻擊的目標

惡意軟件警報 - 零售商成為 Scattered Spider 黑客組織勒索軟件攻擊的目標 發佈日期: 2025年05月02日 類別: ...