Critical CVSS 9.8 EPSS 0.95454 🔬 Patch diffed 2023-04 archive

Executive Summary

None

Overview

9.8
CVSS CRITICAL
Critical
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
Category Remote Code Execution
Released Apr 11 2023
Last Updated Apr 11 2023
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.95454 — 0.99861 percentile
NVD CVSS 9.8 CRITICAL — matches MSRC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 8.5

EPSS Score

0.95454
probability of exploitation in the next 30 days
0.99861 percentile - updated 2026-07-25
View on FIRST.org

Affected Products

25 affected products
Product KB Article Severity Impact Restart Required
Windows 10 for 32-bit Systems 5025234 (Security Update) Critical Remote Code Execution Yes
Windows 10 for x64-based Systems 5025234 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1607 for 32-bit Systems 5025228 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1607 for x64-based Systems 5025228 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1809 for 32-bit Systems 5025229 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1809 for ARM64-based Systems 5025229 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1809 for x64-based Systems 5025229 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 20H2 for 32-bit Systems 5025221 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 20H2 for ARM64-based Systems 5025221 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 21H2 for 32-bit Systems 5025221 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 21H2 for ARM64-based Systems 5025221 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 21H2 for x64-based Systems 5025221 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 22H2 for 32-bit Systems 5025221 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 22H2 for ARM64-based Systems 5025221 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 22H2 for x64-based Systems 5025221 (Security Update) Critical Remote Code Execution Yes
Windows 11 version 21H2 for ARM64-based Systems 5025224 (Security Update) Critical Remote Code Execution Yes
Windows 11 version 21H2 for x64-based Systems 5025224 (Security Update) Critical Remote Code Execution Yes
Windows 11 Version 22H2 for ARM64-based Systems 5025239 (Security Update) Critical Remote Code Execution Yes
Windows 11 Version 22H2 for x64-based Systems 5025239 (Security Update) Critical Remote Code Execution Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 5025271 (Monthly Rollup) 5025273 (Security Only) Critical Remote Code Execution 5023755 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22015 Yes 5025271 5025273 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5025271 (Monthly Rollup) 5025273 (Security Only) Critical Remote Code Execution 5023755 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22015 Yes 5025271 5025273 Windows Server 2008 for x64-based Systems Service Pack 2 5025271 (Monthly Rollup) 5025273 (Security Only) Critical Remote Code Execution 5023755 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22015 Yes 5025271 5025273 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5025271 (Monthly Rollup) 5025273 (Security Only) Critical Remote Code Execution 5023755 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22015 Yes 5025271 5025273 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5025279 (Monthly Rollup) 5025277 (Security Only) Critical Remote Code Execution 5023769 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26466 Yes 5025279 5025277 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5025279 (Monthly Rollup) 5025277 (Security Only) Critical Remote Code Execution 5023769 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26466 Yes 5025279 5025277 Windows Server 2012 5025287 (Monthly Rollup) 5025272 (Security Only) Critical Remote Code Execution 5023769 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.24216 Yes None Windows Server 2012 (Server Core installation) 5025287 (Monthly Rollup) 5025272 (Security Only) Critical Remote Code Execution 5023769 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.24216 Yes None Windows Server 2012 R2 5025285 (Monthly Rollup) 5025288 (Security Only) Critical Remote Code Execution 5023765 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20919 Yes None Windows Server 2012 R2 (Server Core installation) 5025285 (Monthly Rollup) 5025288 (Security Only) Critical Remote Code Execution 5023765 Base: 9.8 Temporal: 8.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20919 Yes None Windows Server 2016 5025228 (Security Update) Critical Remote Code Execution Yes
Windows Server 2016 (Server Core installation) 5025228 (Security Update) Critical Remote Code Execution Yes
Windows Server 2019 5025229 (Security Update) Critical Remote Code Execution Yes
Windows Server 2019 (Server Core installation) 5025229 (Security Update) Critical Remote Code Execution Yes
Windows Server 2022 5025230 (Security Update) Critical Remote Code Execution Yes
Windows Server 2022 (Server Core installation) 5025230 (Security Update) Critical Remote Code Execution Yes

Patches

7 patches
Article Type Restart
5025234 Security Update Yes
5025228 Security Update Yes
5025229 Security Update Yes
5025221 Security Update Yes
5025224 Security Update Yes
5025239 Security Update Yes
5025230 Security Update Yes

Patch Diff

ghidriff · mqqm.dll (KB5025239)

Patch diff 10.0.22621.963 -> 10.0.22621.1555 (MSMQ; safe section-pointer helpers across all header types)

Pre-patch version 10.0.22621.963
Post-patch version 10.0.22621.1555
Function Address Change Note
KERNEL32.DLL::AcquireSRWLockExclusive EXTERNAL:0000011d -> EXTERNAL:00000113 refcount, address, calling similarity 1.0
newstr 1800a0d48 -> 1800a3208 length, address similarity 1.0
wil_details_GetNtDllModuleHandle 18005b828 -> 1800401c0 refcount, address, calling similarity 1.0
CUserHeader::SectionIsValid 18008426c -> 1800865f8 code, length, address, called similarity 0.8
CDebugSection::SectionIsValid 1800836d4 -> 1800858f0 code, length, address, called similarity 0.43
CBaseMqfHeader::SectionIsValid 1800834c0 -> 1800856a4 code, length, address, called similarity 0.43
CXactHeader::SectionIsValid 1800846c4 -> 180086a88 code, length, address, called similarity 0.4
CMessageTransport::ReceiveResponseFailed 1800a75b0 -> 1800a9a70 refcount, address similarity 1.0
wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi'' 180002680 -> 1800023f0 code, length, address similarity 0.9
wil::details::StringCchPrintfA 1800595c0 -> 18003e5f8 code, length, address, called similarity 0.38
CPropertyHeader::SectionIsValid 180083d74 -> 1800860a0 code, length, address, called similarity 0.54
__GSHandlerCheck 180004f48 -> 180004f98 refcount, address similarity 1.0
_guard_xfg_dispatch_icall_nop 1800df980 -> 1800e1e40 refcount, address, calling similarity 0.89
atexit 1800048ac -> 1800048fc refcount, address, calling similarity 1.0
wil::details::unique_storage<wil::details::resource_policy<_TP_TIMER*___ptr64,void_(__cdecl*)(_TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),wistd::integral_constant<unsigned___int64,0>,_TP_TIMER*___ptr64,_TP_TIMER*___ptr64,0,std::nullptr_t>_>::reset 18005b4a8 -> 18003f9b0 refcount, address, calling similarity 1.0
__CxxFrameHandler4 180004744 -> 180004794 refcount, address similarity 0.86
CQmPacket::CQmPacket 1800377d8 -> 1800380ac code, length, address, called similarity 0.31
GetSafeDataAndAdvancePointer<unsigned_long> 180037328 -> 18003752c refcount, address, calling similarity 1.0
wil::ProcessShutdownInProgress 180056650 -> 18003c9d0 refcount, address, calling similarity 1.0
CMsgDeadletterHeader::SectionIsValid 180083a0c -> 180085cf0 code, length, address, called similarity 0.41
KERNEL32.DLL::CreateThreadpoolTimer EXTERNAL:0000012a -> EXTERNAL:00000120 refcount, address, calling similarity 1.0
CSSlNegotiation::Complete_ReadHandShakeResponse 1800c8c30 -> 1800cb0f0 refcount, address similarity 1.0
wistd::unique_ptr<void,wil::process_heap_deleter>::reset 18005b484 -> 18003f98c refcount, address, calling similarity 1.0
CUserHeader::QueueSize 18003901c -> 18003cbe4 code, length, address, calling, called similarity 0.76
CMsgGroupHeader::SectionIsValid 180083b28 -> 180085e30 code, length, address, called similarity 0.41
wil::details_abi::heap_buffer::push_back 18005b1e0 -> 18003f884 refcount, address, calling similarity 1.0
wil::details::EnsureCoalescedTimer_SetTimer 180051c98 -> 18003a090 refcount, address, calling similarity 1.0
StringCchVPrintfW 18005963c -> 18003e644 code, length, address, called similarity 0.39
ReportAndThrow 180039154 -> 18003d930 refcount, address, calling similarity 0.95
wil_details_GetKernelBaseModuleHandle 18005b7f0 -> 180040188 refcount, address, calling similarity 1.0
StringCchCopyA 180049ecc -> 18003e5c0 code, refcount, length, address, called similarity 0.42
KERNEL32.DLL::GetProcAddress EXTERNAL:00000109 -> EXTERNAL:00000110 refcount, address, calling similarity 1.0
CSecurityHeader::SectionIsValid 180083ec8 -> 180086224 code, length, address, called similarity 0.77
wil::details::unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<wil::details::resource_policy<_RTL_SRWLOCK*___ptr64,void_(__cdecl*)(_RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),wistd::integral_constant<unsigned___int64,1>,_RTL_SRWLOCK*___ptr64,_RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> 18004fb04 -> 18003908c refcount, address, calling similarity 1.0
wil::details::unique_storage<wil::details::resource_policy<_TP_TIMER*___ptr64,void_(__cdecl*)(_TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),wistd::integral_constant<unsigned___int64,0>,_TP_TIMER*___ptr64,_TP_TIMER*___ptr64,0,std::nullptr_t>_>::~unique_storage<wil::details::resource_policy<_TP_TIMER*___ptr64,void_(__cdecl*)(_TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),wistd::integral_constant<unsigned___int64,0>,_TP_TIMER*___ptr64,_TP_TIMER*___ptr64,0,std::nullptr_t>_> 18004fb54 -> 1800390dc refcount, address, calling similarity 1.0
__GSHandlerCheck_EH4 1800df880 -> 1800e1d40 refcount, address similarity 1.0
__security_check_cookie 180004760 -> 1800047b0 refcount, address, calling similarity 1.0
View full diff report View RCA report Download PoC

Known Exploits