PT-2023-5940 · Microsoft · Wordpad+1

CVE-2023-36563

·

Published

2023-10-10

·

Updated

2026-02-11

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft WordPad (affected versions not specified)
Description The vulnerability in Microsoft WordPad is related to the disclosure of NTLM hashes, which can be exploited by attackers to obtain sensitive information. This issue can affect the system and potentially allow remote attackers to disclose protected information. The vulnerability has been exploited in real-world attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06637
CVE-2023-36563

Affected Products

Wordpad
Windows