AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-3438

MEDIUM · CVSS 4.4 EPSS 0.24%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-07-03 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.4. It affects Windows.

CVE
CVE-2023-3438
Severity
MEDIUM
CVSS
4.4
EPSS
0.24%
Windows

Original NVD Description

An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe). The misconfiguration allowed an unauthorized local user to insert arbitrary code into the unquoted service path to obtain privilege escalation and stop antimalware services.

Related CVEs

Other vulnerabilities affecting the same vendor(s)