Rewterz
Rewrerz Threat Alert – Agent Tesla Malware – Active IOCs
March 20, 2023
Rewterz
Rewterz Threat Alert – DarkCrystal RAT (DCRat) – Active IOCs
March 20, 2023

Rewrerz Threat Advisory – CVE-2023-24870 – Microsoft Windows PostScript Printer Driver Vulnerability

Severity

Medium

Analysis Summary

CVE-2023-24870

Microsoft Windows could allow a remote authenticated attacker to obtain sensitive information, caused by a flaw in the PostScript Printer Driver. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information from heap memory and then use this information to launch further attacks against the affected system.

Impact

  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2023-24870

Affected Vendors

Microsoft

Affected Products

  • Microsoft Windows Server version 20H2
  • Microsoft Windows 10 20H2 for x64-based Systems
  • Microsoft Windows Server (Server Core installation) 2019
  • Microsoft Windows Server (Server Core installation) 2012
  • Microsoft Windows 10 21H1 for 32-bit Systems
  • Microsoft Windows 10 21H1 for ARM64-based Systems
  • Microsoft Windows 10 21H2 for 32-bit Systems
  • Microsoft Windows 10 21H2 for ARM64-based Systems
  • Microsoft Windows 10 21H2 for x64-based Systems
  • Microsoft Windows 10 22H2 for 32-bit Systems

Remediation

Refer to GitHub Website for patch, upgrade or suggested workaround information. 

GitHub Website