KB to update Curl and fix the vulnerability CVE-2023-38545

Anonymous
2023-11-21T13:10:57+00:00

Please, is there KB to update Curl and fix the vulnerability CVE-2023-38545 "Microsoft Windows Curl Multiple Security Vulnerabilities"? There is no update on https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2023-38545 as of 11/14/2023.

Windows for business | Windows Server | Devices and deployment | Set up, install, or upgrade

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Anonymous
    2023-11-22T01:13:19+00:00

    Hello Beatriz Simiao

    The update containing 8.4.0 has been released.

    For Windows server 2019, the patch is KB5032196.

    For Windows server 2022, the patch is KB5032198.

    You can download it fromhttps://www.catalog.update.microsoft.com/home.aspx

    Image

    Best Regards,

    Hania Lian

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-05-08T12:40:19+00:00

    do we have a fix for CVE-2023-38545 on windows 2016 server ? I dont't see any update.
    we do have some internal servers ( not connected to public Internet though ) I need to update libcurl.dll to new version.
    do we have an update for office 2016/ server 2016

    path is as below,

    C:\Program Files\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\lib\LibCurl64.DllA\libcurl.dll

    0 comments No comments
  3. Anonymous
    2025-01-29T10:21:03+00:00

    Hi,

    Have you found a way to get 2016 server KB information for Curl or did you end up:

    1. manually installing curl latest version and then repointing the system environment?

    OR

    1. migrating operating system 2016 to 2019?

    OR

    any other workarounds?

    0 comments No comments