CVE-2023-38146
Windows Themes Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Windows Themes Remote Code Execution Vulnerability
Vulnerabilidad de Ejecución Remota de Código en Windows Themes
When an unpatched Windows 11 host loads a theme file referencing an msstyles file, Windows loads the msstyles file, and if that file's PACKME_VERSION is 999, it then attempts to load an accompanying dll file ending in _vrf.dll. Before loading that file, it verifies that the file is signed. It does this by opening the file for reading and verifying the signature before opening the file for execution. Because this action is performed in two discrete operations, it opens the procedure for a time of check to time of use vulnerability. By embedding a UNC file path to an SMB server we control, the SMB server can serve a legitimate, signed dll when queried for the read, but then serve a different file of the same name when the host intends to load/execute the dll.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-07-12 CVE Reserved
- 2023-09-12 CVE Published
- 2024-05-01 First Exploit
- 2024-08-02 CVE Updated
- 2024-11-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CAPEC
References (5)
URL | Date | SRC |
---|---|---|
https://github.com/Jnnshschl/CVE-2023-38146 | 2024-05-01 |
URL | Date | SRC |
---|---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38146 | 2024-05-29 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Windows 11 21h2 Search vendor "Microsoft" for product "Windows 11 21h2" | < 10.0.22000.2416 Search vendor "Microsoft" for product "Windows 11 21h2" and version " < 10.0.22000.2416" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 11 22h2 Search vendor "Microsoft" for product "Windows 11 22h2" | < 10.0.22621.2275 Search vendor "Microsoft" for product "Windows 11 22h2" and version " < 10.0.22621.2275" | - |
Affected
|