Windows MSHTML Security Feature Bypass (CVE-2023-29324)
CVE-2023-29324 Published on May 9, 2023
Windows MSHTML Platform Security Feature Bypass Vulnerability
Windows MSHTML Platform Security Feature Bypass Vulnerability
Weakness Type
External Control of File Name or Path
The software allows user input to control or influence paths or file names that are used in filesystem operations.
Products Associated with CVE-2023-29324
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Windows 10 Version 1809:- Version 10.0.17763.0 and below 10.0.17763.4377 is affected.
- Version 10.0.0 and below 10.0.17763.4377 is affected.
- Version 10.0.17763.0 and below 10.0.17763.4377 is affected.
- Version 10.0.17763.0 and below 10.0.17763.4377 is affected.
- Version 10.0.20348.0 and below 10.0.20348.1726 is affected.
- Version 10.0.0 and below 10.0.19042.2965 is affected.
- Version 10.0.0 and below 10.0.22000.1936 is affected.
- Version 10.0.19043.0 and below 10.0.19044.2965 is affected.
- Version 10.0.22621.0 and below 10.0.22621.1702 is affected.
- Version 10.0.19045.0 and below 10.0.19045.2965 is affected.
- Version 10.0.10240.0 and below 10.0.10240.19926 is affected.
- Version 10.0.14393.0 and below 10.0.14393.5921 is affected.
- Version 10.0.14393.0 and below 10.0.14393.5921 is affected.
- Version 10.0.14393.0 and below 10.0.14393.5921 is affected.
- Version 6.0.6003.0 and below 6.0.6003.22070 is affected.
- Version 6.0.6003.0 and below 6.0.6003.22070 is affected.
- Version 6.0.6003.0 and below 6.0.6003.22070 is affected.
- Version 6.1.7601.0 and below 6.1.7601.26519 is affected.
- Version 6.1.7601.0 and below 6.1.7601.26519 is affected.
- Version 6.2.9200.0 and below 6.2.9200.24266 is affected.
- Version 6.2.9200.0 and below 6.2.9200.24266 is affected.
- Version 6.3.9600.0 and below 6.3.9600.20969 is affected.
- Version 6.3.9600.0 and below 6.3.9600.20969 is affected.
Exploit Probability
EPSS
1.87%
Percentile
82.90%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.