CVE-2023-21819
📛 CVE Title
Windows Secure Channel Denial of Service Vulnerability
Description
Windows Secure Channel Denial of Service Vulnerability
Overview
- State
- PUBLISHED
- Assigner (CNA)
- microsoft
- CVSS severity
- HIGH
- CVSS score
- 7.5 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C- Effective score
- 7.5 / 10 HIGH source: CNA overview
- MSRC score
- 7.5 / 10 HIGH MS rating: Important · Denial of Service
- CWE(s)
-
CWE-125 - Reserved
- 2022-12-16
- Published
- 2023-02-14 08:00 UTC
- Last updated
- 2023-02-14 08:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/21xxx/CVE-2023-21819.json
- Linked Threat
- CVE-2023-21819 — Windows Secure Channel Denial of Service Vulnerability
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-25985 - Assigner
- microsoft
- Published
- Feb 14, 2023, 7:33:20 PM
- Updated
- Jan 1, 2025, 12:41:05 AM
- EUVD base score (CVSS 3.1)
-
7.5 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C - EUVD-reported EPSS
- 21.3800
- Vendors
- Microsoft
- Products
-
Windows 11 version 21H2 (10.0.0 <10.0.22621.1574)Windows 10 Version 22H2 (10.0.19045.0 <10.0.19045.2604)Windows 10 Version 1809 (10.0.0 <10.0.17763.4010)Windows Server 2022 (10.0.20348.0 <10.0.20348.1547)Windows Server 2019 (Server Core installation) (10.0.17763.0 <10.0.17763.4010)Windows 10 Version 21H2 (10.0.19043.0 <10.0.19044.2604)Windows 10 Version 1809 (10.0.17763.0 <10.0.17763.4010)Windows 10 Version 20H2 (10.0.0 <10.0.19042.2604)Windows Server 2019 (10.0.17763.0 <10.0.17763.4010)
- Aliases
-
GHSA-f73c-qhrh-5x2f
ENISA description: Windows Secure Channel Denial of Service Vulnerability
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-11 01:49 UTC (source: CVRF).
- MS severity
- Important
- Impact
- Denial of Service
- MS CVSS base score
- 7.5 / 10 (temporal 6.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C - Exploit assessment
- Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;DOS:N/A
- Release
- 2023-Feb
Microsoft remediations / KB articles (8)
- 5022840 — Vendor Fix / Security Update (fixed build 10.0.17763.4010)
- 5022840 — Update
- 5022842 — Vendor Fix / Security Update (fixed build 10.0.20348.1547)
- 5022842 — Update
- 5022921 — Vendor Fix / Security Hotpatch Update (fixed build 10.0.20348.1540)
- 5022834 — Vendor Fix / Security Update (fixed build 10.0.19042.2604)
- 5022834 — Update
- 5022836 — Vendor Fix / Security Update (fixed build 10.0.22621.1574)
Affected products (9)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | Windows 10 Version 1809 |
10.0.17763.0 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Windows 10 Version 1809 |
10.0.0 (affected)
|
ARM64-based Systems |
| Microsoft | Windows Server 2019 |
10.0.17763.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2019 (Server Core installation) |
10.0.17763.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2022 |
10.0.20348.0 (affected)
|
x64-based Systems |
| Microsoft | Windows 10 Version 20H2 |
10.0.0 (affected)
|
32-bit Systems, ARM64-based Systems |
| Microsoft | Windows 11 version 21H2 |
10.0.0 (affected)
|
x64-based Systems, ARM64-based Systems |
| Microsoft | Windows 10 Version 21H2 |
10.0.19043.0 (affected)
|
32-bit Systems, ARM64-based Systems, x64-based Systems |
| Microsoft | Windows 10 Version 22H2 |
10.0.19045.0 (affected)
|
x64-based Systems, ARM64-based Systems, 32-bit Systems |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Windows Secure Channel Denial of Service Vulnerability vendor-advisory
Web references (12)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- 5022834 msrc
- 5022836 msrc
- 5022840 msrc
- 5022842 msrc
- MSRC update guide: CVE-2023-21819 msrc
- https://support.microsoft.com/help/5022842 rapid7:support.microsoft.com
- http://cwe.mitre.org/data/definitions/125.html rapid7:cwe.mitre.org
- https://www.cve.org/CVERecord?id=CVE-2023-21819 rapid7:www.cve.org
- https://attackerkb.com/topics/CVE-2023-21819 rapid7:attackerkb.com
- https://support.microsoft.com/help/5022834 rapid7:support.microsoft.com
- https://support.microsoft.com/help/5022836 rapid7:support.microsoft.com
- https://support.microsoft.com/help/5022840 rapid7:support.microsoft.com
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:lubegard.com
Instant Shudder Fixx™ by Lubegard®: One-time-use additive instantly eliminates torque converter shudder, chatter & harsh shifting in automatic transmissions. Fast results, safe for all ATF types, no disassembly needed.
2026-06-04 14:45 UTC -
web:nvd.nist.gov
To defend against namespace hijacking achieved through update/ patch operations on namespaces, Capsule uses a webhook to validate update requests targeting namespaces.
2026-06-04 14:45 UTC -
web:nvd.nist.gov
An official website of the United States government NVD MENU
2026-06-04 14:45 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-04 14:45 UTC -
web:www.kernel.org
This site is operated by the Linux Kernel Organization, a 501 (c)3 nonprofit corporation, with support from the following sponsors.
2026-06-04 14:45 UTC -
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-06-04 14:45 UTC -
web:www.screwfix.com
Screwfix offers a wide range of trade tools and hardware at competitive prices with convenient delivery and collection options.
2026-06-04 14:45 UTC -
web:forums.ea.com
Broken and Updated Sims 4 Mods and CC: patch 1.124, May 12 and 21, 2026 About This Thread This thread tracks Sims 4 mods and CC that have been "broken" or made obsolete by game update 1.124, May 12, 2026, and the May 21 hotfix, or declared unsupported by their creators.
2026-06-04 14:45 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 05:47 UTC -
web:access.redhat.com
Learn about our open source products, services, and company. You are here
2026-05-22 05:47 UTC -
web:www.secure.com
Learn the difference between vulnerability remediation and mitigation , and how a risk-based strategy can strengthen your security posture.
2026-05-22 05:47 UTC -
web:attack.mitre.org
This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...
2026-05-22 05:47 UTC -
web:source.android.com
This Section contains the available Android Security Bulletins, which provide fixes for possible issues affecting Android devices.
2026-05-22 05:47 UTC -
web:support.microsoft.com
Summary An authenticated user (attacker) could cause an information disclosure vulnerability in Windows Kernel. This vulnerability does not require administrator or other elevated privileges. The attacker who successfully exploits this vulnerability could view heap memory from a privileged process that is running on the server. Successful exploitation of this vulnerability requires an attacker ...
2026-05-22 05:47 UTC -
web:support.servicenow.com
This document lists all the released Store applications and schema changes for Vulnerability Response and Configuration Compliance. Vulnerability Response and Configuration Compliance Compatibility Matrix
2026-05-22 05:47 UTC -
web:www.bugcrowd.com
Vulnerability mitigation is typically considered a temporary or interim solution. While mitigation measures can reduce the immediate risk associated with vulnerabilities, they may not provide a permanent fix . Organizations should aim to prioritize and plan for complete vulnerability remediation whenever feasible and allocate resources accordingly.
2026-05-22 05:47 UTC -
web:www.cisco.com
This document describes a list of software versions that have incorporated fixes for Cisco IOS® XE Software Web UI Cisco bug ID CSCwh87343.
2026-05-22 05:47 UTC -
web:www.experts-exchange.com
In today's threat landscape, it is important to address vulnerabilities as fast as possible. Within Microsoft Active Directory environments, the fastest and best way to address these is through the use of GPO. This article will show how to address the Birthday\Sweet32 vulnerability via a GPO.
2026-05-22 05:47 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-21819.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T09:51:51.176Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "Windows Secure Channel Denial of Service Vulnerability",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21819"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-21819",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-10-04T18:06:28.156056Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-10-04T18:06:39.564Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Windows 10 Version 1809",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.17763.4010",
"status": "affected",
"version": "10.0.17763.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"ARM64-based Systems"
],
"product": "Windows 10 Version 1809",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.17763.4010",
"status": "affected",
"version": "10.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2019",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.17763.4010",
"status": "affected",
"version": "10.0.17763.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2019 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.17763.4010",
"status": "affected",
"version": "10.0.17763.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2022",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.20348.1547",
"status": "affected",
"version": "10.0.20348.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"ARM64-based Systems"
],
"product": "Windows 10 Version 20H2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.19042.2604",
"status": "affected",
"version": "10.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems",
"ARM64-based Systems"
],
"product": "Windows 11 version 21H2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.22621.1574",
"status": "affected",
"version": "10.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"ARM64-based Systems",
"x64-based Systems"
],
"product": "Windows 10 Version 21H2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.19044.2604",
"status": "affected",
"version": "10.0.19043.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems",
"ARM64-based Systems",
"32-bit Systems"
],
"product": "Windows 10 Version 22H2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.19045.2604",
"status": "affected",
"version": "10.0.19045.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"versionEndExcluding": "10.0.17763.4010",
"versionStartIncluding": "10.0.17763.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:*",
"versionEndExcluding": "10.0.17763.4010",
"versionStartIncluding": "10.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.0.17763.4010",
"versionStartIncluding": "10.0.17763.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.0.17763.4010",
"versionStartIncluding": "10.0.17763.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.0.20348.1547",
"versionStartIncluding": "10.0.20348.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_20H2:*:*:*:*:*:*:x86:*",
"versionEndExcluding": "10.0.19042.2604",
"versionStartIncluding": "10.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_21H2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "10.0.22621.1574",
"versionStartIncluding": "10.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*",
"versionEndExcluding": "10.0.19044.2604",
"versionStartIncluding": "10.0.19043.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*",
"versionEndExcluding": "10.0.19045.2604",
"versionStartIncluding": "10.0.19045.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2023-02-14T08:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Windows Secure Channel Denial of Service Vulnerability"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-125",
"description": "CWE-125: Out-of-bounds Read",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-01-01T00:41:05.542Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Windows Secure Channel Denial of Service Vulnerability",
"tags": [
"vendor-advisory"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21819"
}
],
"title": "Windows Secure Channel Denial of Service Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2023-21819",
"datePublished": "2023-02-14T19:33:20.984Z",
"dateReserved": "2022-12-16T22:13:41.245Z",
"dateUpdated": "2025-01-01T00:41:05.542Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}