SB2023041216 - Multiple vulnerabilities in Microsoft Windows Lock Screen



SB2023041216 - Multiple vulnerabilities in Microsoft Windows Lock Screen

Published: April 12, 2023

Security Bulletin ID SB2023041216
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Security features bypass (CVE-ID: CVE-2023-28235)

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to security features bypass in Windows Lock Screen. An attacker with physical access can bypass the Windows Lock Screen security feature.


2) Security features bypass (CVE-ID: CVE-2023-28270)

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to security features bypass in Windows Lock Screen. An attacker with physical access can bypass authentication feature.


Remediation

Install update from vendor's website.