← Vulnerability feed

Vulnerability record · CVE-2023-38151 · published 14 November 2023

CVE-2023-38151: Microsoft host integration server use of uninitialized resource vulnerability

Microsoft · Host Integration Server

Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability

8.8 CVSS 3.1 High EPSS 1.8% · top 22.6% CWE-908 · Use of uninitialized resource
8.8CVSS 3.1 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-38151 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed5.0CVE-2011-2007Microsoft host integration server improper input validation vulnerabilityMicrosoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service o…EPSS 23%5.0CVE-2011-2008Microsoft host integration server improper input validation vulnerabilityMicrosoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service o…EPSS 21%7.8CVE-2026-85880Windows ALPC heap buffer overflow allows local privilege escalationA heap-based buffer overflow in the Windows ALPC subsystem, combined with use of an uninitialized resource, lets an attacker with existing local acce…KEVEPSS 3.6%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed5.5CVE-2024-50302Linux kernel HID core uninitialized report buffer leaks kernel memoryThe Linux kernel HID core allocates a report buffer without zero-initializing it, so residual kernel memory can be exposed through crafted HID report…KEVEPSS 0.81%analysed5.5CVE-2024-29745Android Pixel firmware uninitialized data information disclosureCVE-2024-29745 is an information disclosure flaw in Android on Pixel devices caused by use of uninitialized data (CWE-908). A local attacker can read…KEVEPSS 0.48%analysed

Source: NIST National Vulnerability Database (record CVE-2023-38151), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.