5.4

CVE-2023-36769

Microsoft OneNote Spoofing Vulnerability

Data is provided by the National Vulnerability Database (NVD)
MicrosoftOnenote Version2013 Updatesp1 SwEdition-
MicrosoftOnenote Version2013 Updatesp1 SwEditionrt
MicrosoftOnenote Version2016
MicrosoftOnenote Version2019
MicrosoftOnenote Version2021 SwEditionltsc
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.1% 0.294
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
secure@microsoft.com 4.6 2.1 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.