Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2023-28219

CVE-2023-28219: Windows 10 1507 L2TP RCE Vulnerability

CVE-2023-28219 is a remote code execution vulnerability in Microsoft Windows 10 1507 Layer 2 Tunneling Protocol that enables attackers to execute arbitrary code. This article covers technical details, impact, and mitigation.

Updated:

CVE-2023-28219 Overview

CVE-2023-28219 is a remote code execution vulnerability in the Microsoft Windows implementation of the Layer 2 Tunneling Protocol (L2TP). The flaw affects supported versions of Windows 10, Windows 11, and Windows Server from 2008 through 2022. An unauthenticated attacker can target the L2TP service over the network to execute arbitrary code on the affected system. Microsoft addressed the issue in the April 2023 Patch Tuesday security update cycle. The vulnerability carries an EPSS probability of 7.553%, placing it in the 91st percentile of likelihood for exploitation activity.

Critical Impact

Successful exploitation grants remote code execution on the targeted host, allowing attackers to compromise the confidentiality, integrity, and availability of Windows endpoints and servers exposing L2TP.

Affected Products

  • Microsoft Windows 10 (versions 1507, 1607, 1809, 20H2, 21H2, 22H2)
  • Microsoft Windows 11 (versions 21H2, 22H2)
  • Microsoft Windows Server 2008, 2012, 2016, 2019, and 2022

Discovery Timeline

  • 2023-04-11 - CVE-2023-28219 published to the National Vulnerability Database
  • 2023-04-11 - Microsoft released a security update addressing the vulnerability
  • 2024-11-21 - Last updated in the NVD database

Technical Details for CVE-2023-28219

Vulnerability Analysis

The vulnerability resides in the Windows Routing and Remote Access Service (RRAS) component that processes Layer 2 Tunneling Protocol traffic. A remote attacker can send specially crafted L2TP packets to a vulnerable host and trigger code execution in the context of the affected service. The attack vector is network-based and requires no authentication or user interaction. Microsoft assigned the issue [CWE-591] (Sensitive Data Storage in Improperly Locked Memory), indicating that the vulnerability involves protocol state handling that does not properly protect data in memory during L2TP session processing.

Because L2TP is commonly used as a VPN protocol on Windows Server deployments, exposed RRAS endpoints present a network-reachable attack surface. Exploitation requires the attacker to win specific runtime conditions on the target, which raises the attack complexity but does not eliminate the threat for internet-exposed services.

Root Cause

The root cause is improper handling of memory storing sensitive protocol state in the L2TP processing path. The flawed logic allows an attacker-controlled packet sequence to influence memory used by the service, enabling code execution when the attacker triggers the right conditions during packet processing.

Attack Vector

Attackers reach the vulnerable code path by sending malicious L2TP packets to a Windows host running RRAS or otherwise listening on the L2TP port (UDP 1701) and the associated IPsec encapsulation ports (UDP 500 and UDP 4500). No credentials and no user interaction are required. The most exposed systems are VPN gateways and edge servers that publish L2TP/IPsec services to untrusted networks. No public proof-of-concept exploit code is referenced in the available CVE data.

Detection Methods for CVE-2023-28219

Indicators of Compromise

  • Unexpected RRAS or svchost.exe process crashes or restarts correlated with inbound L2TP traffic on UDP 1701
  • Anomalous child processes spawned by services hosting the L2TP stack
  • Outbound connections from RRAS hosts to unfamiliar external addresses following L2TP session activity
  • Windows Event Log entries showing RasMan or RemoteAccess service faults without administrator-initiated changes

Detection Strategies

  • Monitor network telemetry for malformed or anomalously fragmented L2TP packets directed at Windows VPN endpoints
  • Alert on process lineage where RRAS-related services launch interpreters, command shells, or networking utilities
  • Correlate IDS or firewall signatures for L2TP protocol anomalies with endpoint telemetry on the receiving host

Monitoring Recommendations

  • Inventory all systems exposing UDP 1701, 500, and 4500 and ensure they are tracked for patch compliance
  • Centralize Windows Event Logs and RRAS operational logs in a SIEM to retain context for retrospective analysis
  • Baseline normal L2TP session volumes and alert on sudden spikes or sustained connection attempts from single sources

How to Mitigate CVE-2023-28219

Immediate Actions Required

  • Apply the April 2023 Microsoft security update for CVE-2023-28219 to all affected Windows 10, Windows 11, and Windows Server systems
  • Identify any servers running RRAS with L2TP enabled and prioritize patching of internet-facing instances
  • Restrict inbound L2TP traffic at perimeter firewalls to known VPN peers until patching is complete

Patch Information

Microsoft published a vendor advisory and cumulative security updates that remediate the flaw across all supported Windows versions. Refer to the Microsoft Security Update CVE-2023-28219 advisory for the specific KB numbers that apply to each Windows release.

Workarounds

  • Disable the L2TP VPN protocol on Windows hosts where it is not required for business operations
  • Block UDP ports 1701, 500, and 4500 at the network perimeter when L2TP is not in active use
  • Place L2TP VPN gateways behind network segmentation that limits exposure to trusted source networks only
bash
# Configuration example: list and disable L2TP ports in RRAS using PowerShell
Get-VpnServerConfiguration
Set-VpnServerConfiguration -TunnelType IKEv2
# Block L2TP-related ports at the host firewall
New-NetFirewallRule -DisplayName "Block L2TP UDP 1701" -Direction Inbound -Protocol UDP -LocalPort 1701 -Action Block
New-NetFirewallRule -DisplayName "Block IPsec UDP 500" -Direction Inbound -Protocol UDP -LocalPort 500 -Action Block
New-NetFirewallRule -DisplayName "Block IPsec NAT-T UDP 4500" -Direction Inbound -Protocol UDP -LocalPort 4500 -Action Block

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.