U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-36596

Change History

Initial Analysis by NIST 10/13/2023 3:22:20 PM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Added CWE

								
							
							
						
NIST CWE-668
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.10240.20232
     *cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.10240.20232
     *cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.17763.4974
     *cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.17763.4974
     *cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.17763.4974
     *cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.19041.3570
     *cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.19041.3570
     *cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.19041.3570
     *cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.19041.3570
     *cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.19041.3570
     *cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.19041.3570
     *cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.22000.2538
     *cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.22000.2538
     *cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.22621.2428
     *cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.22621.2428
     *cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
     *cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
     *cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
     *cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
     *cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*
Changed Reference Type
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36596 No Types Assigned
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36596 Patch, Vendor Advisory