CVE-2023-24907
Published: 14 March 2023
Summary
CVE-2023-24907 is a high-severity Heap-based Buffer Overflow (CWE-122) vulnerability in Microsoft Windows Server 2012. Its CVSS base score is 8.8 (High).
Operationally, ranked in the top 5.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
Deeper analysis
CVE-2023-24907 is a remote code execution vulnerability affecting the Microsoft PostScript and PCL6 Class Printer Driver. It carries a CVSS 3.1 base score of 8.8 and is associated with CWE-122. The flaw was publicly disclosed on 14 March 2023.
An attacker with low privileges can exploit the issue over a network connection without requiring user interaction. Successful exploitation grants the ability to execute arbitrary code with high impact to confidentiality, integrity, and availability on the affected system.
Microsoft has published official guidance for the vulnerability in its security update guide, including details on available patches and mitigation steps for affected printer driver components.
The associated EPSS score is currently 0.1322 and has remained at that peak value since disclosure, indicating moderate but stable exploitation probability without a material upward trajectory.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-28895
Vulnerability details
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.