Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2023-36028

CVE-2023-36028: Windows 10 1507 PEAP RCE Vulnerability

CVE-2023-36028 is a remote code execution vulnerability in Microsoft Protected Extensible Authentication Protocol (PEAP) for Windows 10 1507. This article covers technical details, affected versions, impact, and mitigation.

Updated:

CVE-2023-36028 Overview

CVE-2023-36028 is a remote code execution vulnerability in the Microsoft Protected Extensible Authentication Protocol (PEAP) implementation on Windows. The flaw stems from a heap-based buffer overflow [CWE-122] triggered when the PEAP service processes specially crafted network messages. An unauthenticated attacker can send malicious packets to a server configured with the Network Policy Server (NPS) role and PEAP, leading to arbitrary code execution in the context of the service. Microsoft published the advisory on November 14, 2023, and the issue affects supported releases of Windows 10, Windows 11, and Windows Server.

Critical Impact

Unauthenticated network attackers can execute code on Windows servers running PEAP-enabled Network Policy Server, undermining enterprise Wi-Fi and VPN authentication infrastructure.

Affected Products

  • Microsoft Windows 10 (versions 1507, 1607, 1809, 21H2, 22H2)
  • Microsoft Windows 11 (versions 21H2, 22H2, 23H2)
  • Microsoft Windows Server 2016, 2019, and 2022

Discovery Timeline

  • 2023-11-14 - Microsoft releases security update for CVE-2023-36028
  • 2023-11-14 - CVE-2023-36028 published to NVD
  • 2024-11-21 - Last updated in NVD database

Technical Details for CVE-2023-36028

Vulnerability Analysis

The vulnerability resides in the PEAP implementation used by Windows for 802.1X and VPN authentication scenarios. PEAP encapsulates the Extensible Authentication Protocol (EAP) inside a TLS tunnel and is commonly deployed on Network Policy Server (NPS) instances acting as RADIUS authenticators. Improper handling of attacker-supplied PEAP message data causes a heap-based buffer overflow during parsing, classified as [CWE-122].

Successful exploitation grants the attacker arbitrary code execution in the security context of the PEAP-handling service. The attack requires no privileges, no user interaction, and is reachable over the network, giving it a high impact on confidentiality, integrity, and availability of the targeted system. EPSS data places the probability of exploitation activity at approximately 0.536%.

Root Cause

The root cause is improper validation of length or size fields within PEAP protocol messages. When the vulnerable code copies attacker-controlled data into a heap buffer without enforcing correct bounds, adjacent heap structures can be overwritten. An attacker who shapes the heap can pivot the corruption into code execution.

Attack Vector

An attacker sends a crafted PEAP message to a Windows host that has PEAP configured as an authentication method, typically a server running the Network Policy Server role for wireless or VPN authentication. Because PEAP exchanges occur prior to user authentication, the attacker does not need valid credentials. The traffic path commonly traverses RADIUS infrastructure, making perimeter NPS deployments exposed targets.

No public proof-of-concept exploit code is referenced in the NVD record for this issue. Refer to the Microsoft Security Update CVE-2023-36028 advisory for vendor technical detail.

Detection Methods for CVE-2023-36028

Indicators of Compromise

  • Unexpected crashes, restarts, or memory faults in the IAS or NPS service processes on Windows Server hosts
  • Anomalous RADIUS or 802.1X authentication traffic patterns from unrecognized clients targeting NPS infrastructure
  • New or unauthorized child processes spawned by the Network Policy Server service following inbound PEAP traffic

Detection Strategies

  • Hunt in endpoint and EDR telemetry for child processes created by NPS-related service binaries, which should rarely launch additional executables
  • Correlate RADIUS authentication failures with service crash events on NPS hosts to surface exploitation attempts
  • Use behavioral detection on Windows servers to flag in-memory code execution or shellcode patterns within authentication service contexts

Monitoring Recommendations

  • Forward Windows event logs, NPS accounting logs, and EDR process telemetry into a centralized SIEM such as Singularity Data Lake for correlation
  • Track PEAP and RADIUS traffic volume baselines, alerting on spikes or malformed packets reaching NPS listeners
  • Monitor patch state of Windows servers exposed to authentication traffic and alert when systems drift from the November 2023 cumulative update or later

How to Mitigate CVE-2023-36028

Immediate Actions Required

  • Apply the November 2023 Microsoft security updates referenced in the Microsoft Security Update CVE-2023-36028 advisory to all affected Windows 10, Windows 11, and Windows Server systems
  • Inventory every Windows host running the Network Policy Server role or otherwise exposing PEAP, and prioritize patching internet- or perimeter-facing instances
  • Restrict RADIUS and 802.1X traffic to known authenticator IP addresses using firewall rules and network segmentation

Patch Information

Microsoft addressed CVE-2023-36028 in the November 14, 2023 monthly security updates. Each affected Windows 10, Windows 11, and Windows Server release received a cumulative update that replaces the vulnerable PEAP component. Administrators should review the Microsoft Security Update CVE-2023-36028 page for the KB articles that correspond to each supported build.

Workarounds

  • Disable PEAP as an authentication method on Network Policy Server where it is not strictly required, replacing it with an alternative EAP method
  • Limit exposure by placing NPS servers behind segmented network zones that only permit RADIUS traffic from authorized network access devices
  • Where patching is delayed, monitor PEAP-enabled hosts continuously with endpoint detection tooling such as Singularity Endpoint to identify exploitation attempts targeting the authentication service

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.