Security readout for executives and security teams
Plain-English summary
This is a Windows printer driver information disclosure issue. It is not rated as remote code execution, but Microsoft’s CVSS indicates a local, low-privileged user could expose highly sensitive information. Business urgency is moderate and should be handled through normal Windows patch governance.
Executive priority
Treat as a moderate-priority confidentiality issue. It does not indicate remote takeover, but affected Windows fleets should be patched because successful exploitation could disclose sensitive information to a local low-privileged user.
Technical view
CVE-2023-35306 affects Microsoft PostScript and PCL6 Class Printer Driver across listed Windows client and server versions. The CVSS vector is local, low complexity, low privileges required, no user interaction, confidentiality high, and no integrity or availability impact. CWE-20 is listed.
Likely exposure
Exposure is likely on affected Windows 10, Windows 11, Windows Server 2012/2016/2019/2022 systems before the applicable Microsoft remediation. The source bundle does not prove exposure beyond the listed products and versions.
Exploitation context
CISA KEV status is false in the bundle, and the CVSS exploit maturity is unproven. The sources do not show active exploitation, public exploit availability, or remote unauthenticated attack paths.
Researcher notes
The public bundle is sparse: it identifies the component, affected Windows versions, CWE-20, CVSS, and Microsoft advisory, but not root-cause details or exploit mechanics. Avoid assuming printer service configuration changes are sufficient without Microsoft guidance.
Mitigation direction
- Use Microsoft’s advisory to identify applicable updates for each Windows version.
- Install the relevant Microsoft security updates through normal patch management.
- Prioritize systems allowing local interactive or shared-user access.
- Review vendor guidance before applying compensating controls not named in sources.
Validation and detection
- Inventory Windows versions against the affected product list.
- Verify CVE-2023-35306 remediation status in patch management records.
- Check whether affected server core installations are included in scope.
- Confirm exceptions are documented with owner, reason, and remediation date.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-20: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2023-35306 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C1.83.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
5.5MediumVector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Source materials
- CVE List V5 sourceCVE List V5
- Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure VulnerabilityCVE reference · vendor-advisory
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Improper Input Validation
Improper Input Validation represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
