
Severity
Medium
Analysis Summary
CVE-2023-24870
Microsoft Windows could allow a remote authenticated attacker to obtain sensitive information, caused by a flaw in the PostScript Printer Driver. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information from heap memory and then use this information to launch further attacks against the affected system.
Impact
- Information Disclosure
Indicators Of Compromise
CVE
- CVE-2023-24870
Affected Vendors
Microsoft
Affected Products
- Microsoft Windows Server version 20H2
- Microsoft Windows 10 20H2 for x64-based Systems
- Microsoft Windows Server (Server Core installation) 2019
- Microsoft Windows Server (Server Core installation) 2012
- Microsoft Windows 10 21H1 for 32-bit Systems
- Microsoft Windows 10 21H1 for ARM64-based Systems
- Microsoft Windows 10 21H2 for 32-bit Systems
- Microsoft Windows 10 21H2 for ARM64-based Systems
- Microsoft Windows 10 21H2 for x64-based Systems
- Microsoft Windows 10 22H2 for 32-bit Systems
Remediation
Refer to GitHub Website for patch, upgrade or suggested workaround information.