MS.Windows.IKE.Vendor.ID.CVE-2023-21758.DoS
Description
This indicates an attack attempt to exploit a Denial of Service Vulnerability in Microsoft Windows Server.
The vulnerability is due to improper handling of incoming packets when IPsec is enabled on the machine. A remote attacker could exploit this vulnerability by sending a crafted Vendor ID payload to a target server. Successful exploitation results in denial of service conditions on the target server.
Affected Products
Microsoft Windows 10 Version 1607
Microsoft Windows 10 Version 1809
Microsoft Windows 10 version 20H2
Microsoft Windows 10 Version 21H2
Microsoft Windows 10 Version 22H2
Microsoft Windows 11 Version 21H2
Microsoft Windows 11 Version 22H2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Impact
Denial of Service: Remote attackers can crash vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21758
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2023-06-27 | 24.590 | Default_action:pass:drop |
2023-06-05 | 23.570 | Sig Added |
2023-05-30 | 23.564 |