Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Microsoft Windows: CVE-2023-36436: Windows MSHTML Platform Remote Code Execution Vulnerability

Severity
7
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Published
Oct 10, 2023
Added
Oct 10, 2023
Modified
Sep 5, 2025

Description

Windows MSHTML Platform Remote Code Execution Vulnerability

Solutions

microsoft-windows-windows_10-1507-kb5031377microsoft-windows-windows_10-1607-kb5031362microsoft-windows-windows_10-1809-kb5031361microsoft-windows-windows_10-21h2-kb5031356microsoft-windows-windows_10-22h2-kb5031356microsoft-windows-windows_11-21h2-kb5031358microsoft-windows-windows_11-22h2-kb5031354microsoft-windows-windows_server_2012-kb5031427microsoft-windows-windows_server_2012_r2-kb5031407microsoft-windows-windows_server_2016-1607-kb5031362microsoft-windows-windows_server_2019-1809-kb5031361microsoft-windows-windows_server_2022-21h2-kb5031364microsoft-windows-windows_server_2022-22h2-kb5031364msft-kb5031355-6753f44a-e668-4fbc-b16e-8d007ce725d7msft-kb5031355-7233c520-6c21-4117-bb9f-cf4998a4abd0msft-kb5031355-74c9dd20-eab2-4e14-9fdd-b58613e0c5b0msft-kb5031411-6ff09e07-29d8-4561-a6a3-72286549d09emsft-kb5031411-ae877d0e-9c3e-4875-b882-770428331f79

References

    Title
    Rapid7 Labs

    2026 Global Threat Landscape Report

    The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.