Skip to main content

Microsoft Windows Snipping Tool Information Disclosure Vulnerability

Release Date: 31 Mar 2023 6671 Views

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

A vulnerability has been identified in Microsoft Windows Snipping Tool, a remote user can exploit this vulnerability to trigger information disclosure on the targeted system.

 

Note:
Proof of Concept exploit code is publicly available for CVE-2023-28303.


Impact

  • Information Disclosure

System / Technologies affected

  • Snip & Sketch in Windows 10 prior to 10.2008.3001.0
  • Snipping Tool in Windows 11 prior to 11.2302.20.0

Please refer to the link below for detail:

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28303


Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor.

  • Windows 10:Update to version 10.2008.3001.0 or later
  • Windows 11: Update to version 11.2302.20.0 or later

 

 


Vulnerability Identifier


Source


Related Link