Full Blind TCP/IP Hijacking Vulnerability in Windows 7 by Microsoft
CVE-2023-34367

6.5MEDIUM

Key Information:

Vendor
Microsoft
Status
Vendor
CVE Published:
14 June 2023

Summary

Windows 7 is susceptible to a full blind TCP/IP hijacking attack, allowing malicious actors to intercept and manipulate network communications without detection. This vulnerability extends not only to Windows 7 but also affects implementations of TCP/IP, including many IoT devices, making diverse systems increasingly vulnerable. Exploiting this issue through idle scan attacks enables adversaries to gain unauthorized access, posing significant risks to data integrity and overall network security. Organizations relying on affected systems should take appropriate measures to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.