Share via

How can we remediate CVE-2023-38039 which is showing in lot of Windows servers?

Anonymous
2023-10-04T11:47:40+00:00

A lot of Windows servers are showing Curl 7.84 <= 8.2.1 Header DoS (CVE-2023-38039) as High vulnerability in Tenable scans. We did not see any updates for Curl in Windows Updates and also could not find any document that provides a guidance on this. Please advice. Thanks.

Windows for business | Windows Server | Windows cloud | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

  1. Anonymous
    2023-11-15T08:59:18+00:00

    Hi Saura,

    KB5032196 is for Windows Server 2019 as well

    1 person found this answer helpful.
    0 comments No comments

18 additional answers

Sort by: Most helpful
  1. Anonymous
    2023-10-12T16:41:28+00:00

    This needs to be escalated for a response from Microsoft corporate... It is 100% unacceptable and indefensible for Microsoft to incorporate open-source code in a way that requires only Microsoft packaged updates and fixes, when Microsoft has no intention of maintaining the code they decided to incorporate! This is another example of Microsoft doing things the programming community doesn't want while ensuring Windows is more vulnerable than ever before.

    If Microsoft won't meet industry-standard patching deadlines, STOP INCORPORATING MORE OPEN SOURCE CODE into the OS but REQUIRING MS PACKAGED FIXES!

    This is exactly like the old Macromedia Flash problem. STOP IT.

    40+ people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2023-10-06T15:33:21+00:00

    I highly recommend against any attempt to manually update the embedded Windows curl files. Replacing them changes the file hash that Microsoft expects to see when curl is addressed in a cumulative update. The entire update will fail to install.

    This advice is based on personal experience with the previous curl finding in Tenable.

    20+ people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2023-10-16T07:11:05+00:00

    It's frustrating to see that the October 2023 updates did not include remediation for CURL vulnerability. If Microsoft does not have skillset and expertise with open source products to provide remediation steps for High vulnerabilities then I think they should stop shipping it with their Windows OS. I hope the Developers acts ASAP on the challenges faced by the Admins and the support teams with CURL vulnerability. Thanks.

    9 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2023-10-12T13:07:33+00:00

    where do you see this categorized as a medium? we have it prevelantly through our entire environment and CVE-2023-38039 is a high and about to breach the 30 day discovery and it was not addressed in the October patch release.

    https://nvd.nist.gov/vuln/detail/CVE-2023-38039

    4 people found this answer helpful.
    0 comments No comments