Microsoft Released an Update for Windows Snipping Tool Vulnerability

Published: 2023-03-25. Last Updated: 2023-03-25 19:56:15 UTC
by Guy Bruneau (Version: 1)
0 comment(s)

To exploit this vulnerability, the image must be created under very specific condition listed here.

According to the information provided by Microsoft, "The default Snipping Tool in Windows 10 and older versions are unaffected. Only Snip & Sketch in Windows 10 and Snipping Tool in Windows 11 are affected by this vulnerability. A security update has been released for these applications, which are available through the Microsoft Store."[1]

This is the information provide to verify if the system is affected: 

For Snip and Sketch installed on Windows 10, app versions 10.2008.3001.0 and later contain this update.
For Snipping Tool installed on Windows 11, app versions 11.2302.20.0 and later contain this update.

[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28303
[2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28303
[3] https://apps.microsoft.com/store/detail/snipping-tool/9MZ95KL8MR0L?hl=en-us&gl=us

-----------
Guy Bruneau IPSS Inc.
My Handler Page
Twitter: GuyBruneau
gbruneau at isc dot sans dot edu

0 comment(s)

Comments


Diary Archives