ZeroHour

CVE-2023-36563

KEVmass2

Information Disclosure in Microsoft WordPad Exploited in the Wild

CISA: Microsoft WordPad Information Disclosure Vulnerability

CVSS 3.1
5.5 medium
EPSS
21%p97
Published
()
KEV added
AI analysis

CVE-2023-36563 is an information disclosure flaw (CWE-20, improper input validation) in Microsoft WordPad, the lightweight word processor bundled with supported Windows releases; Microsoft has published limited technical detail and CISA describes the flaw as unspecified. An attacker triggers it by persuading a user to open a specially crafted document in WordPad, where improper handling of the document content (including URL/remote-resource references) causes information to be disclosed to the attacker. A successful attacker gains access to sensitive information from the affected system rather than code execution, and exploitation requires user interaction with a malicious file. Any Windows installation with WordPad is potentially affected, making the population essentially the entire supported Windows installed base. Exploitation is confirmed: CISA added the flaw to its KEV catalog on 2023-10-10 and its advisory notes no public proof-of-concept is known and ransomware use is unknown; EPSS is 20.7% (97th percentile), indicating elevated near-term exploitation likelihood.

What to do: Apply Microsoft's October 10, 2023 Windows security updates, which include the WordPad fix, prioritizing systems where users open untrusted documents; until patched, follow Microsoft's mitigation guidance to disable the WordPad URL protocol handler via the published registry change. Note that WordPad has since been removed entirely in Windows 11 24H2, so those systems are no longer exposed; per CISA, any ransomware linkage is unknown.

Affected
Microsoft WordPad (word processor bundled with supported Windows releases)
Estimated exposure
mass≈1.4 billion Windows devices (WordPad ships by default with Windows) — WordPad is installed by default with supported Windows editions and Microsoft has cited roughly 1.4 billion active Windows devices, so the potential installed base is effectively the entire Windows fleet.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft WordPad Information Disclosure Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft WordPad
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news