Security News

Cybersecurity news aggregator

🪟
HIGH Vulnerabilities Microsoft Security Response Center

CVE-2023-21806 Power BI Report Server Spoofing Vulnerability

CVE-2023-21806 is an important-severity spoofing vulnerability (CVSS 8.2) in Microsoft Power BI Report Server caused by improper input neutralization (CWE-79), allowing an authenticated attacker to execute cross-site scripting attacks by tricking a user into opening a malicious file. Affected versions are all releases prior to version 15.0.1111.115. The fix requires upgrading Power BI Report Server to version 15.0.1111.115 or later.
Read Full Article →

We use optional cookies to improve your experience on our websites, such as through social media connections, and to display personalized advertising based on your online activity. If you reject optional cookies, only cookies necessary to provide you the services will be used. You may change your selection by clicking “Manage Cookies” at the bottom of the page. Privacy Statement Third-Party Cookies AcceptRejectManage cookies MSRC  Customer Guidance  Security Update Guide  Vulnerabilities  CVE-2023-21806 Power BI Report Server Spoofing Vulnerability Recently updated On this page  CVE-2023-21806  Subscribe RSS PowerShell  API  CSAF Security Vulnerability Released: Feb 14, 2023 Last updated: Aug 19, 2026 Assigning CNA Microsoft CVE.org link CVE-2023-21806  Impact Spoofing Max Severity Important Weakness CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVSS Source Microsoft Vector String CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L/E:U/RL:O/RC:C Metrics CVSS:3.1 8.2 / 7.1  Base score metrics: 8.2 / Temporal score metrics: 7.1  Expand all  Collapse all Metric Value   Base score metrics(8) Attack Vector Network Attack Complexity Low Privileges Required Low User Interaction Required Scope Changed Confidentiality High Integrity Low Availability Low   Temporal score metrics(3) Exploit Code Maturity Unproven Remediation Level Official Fix Report Confidence Confirmed Please see Common Vulnerability Scoring System for more information on the definition of these metrics. Exploitability The following table provides an exploitability assessment for this vulnerability at the time of original publication. Publicly disclosed No Exploited No Exploitability assessment Exploitation Less Likely FAQ According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? An attacker would have to send the victim a malicious file that the victim would have to execute. According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must have permissions to access the target domain environment to be able to exploit this vulnerability. According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? The vulnerability is in the web server, but the malicious scripts execute in the victim’s browser on their machine. According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H). What does that mean for this vulnerability? There could be a loss of confidentiality if an unaware user clicked on a popup therefore creating an opportunity for an attacker to retrieve cookies or present the user with a dialog box to enter user credentials. According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of availability (A:L)? What does that mean for this vulnerability? The attacker cannot fully deny service availability across all infrastructure, hence low effect on availability. According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability? An attacker could modify the contents of a reports file creating the potential opportunity for Java Script to be run as part of the Spoofing vulnerability. Acknowledgements Microsoft recognizes the efforts of those in the security community who help us protect customers through coordinated vulnerability disclosure. See Acknowledgements for more information. Security Updates To determine the support lifecycle for your software, see the Microsoft Support Lifecycle. Release date Descending  Edit columns  Download  Filters  Product Family  Max Severity  Impact  Platform   Clear Release date  Product Platform Impact Max Severity Article Download Build Number Assigning CNA Loading... Disclaimer The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. Revisions version revisionDate description 1.2 Aug 19, 2026 Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. 1.1 Mar 1, 2023 Added an acknowledgement. This is an informational change only. 1.0 Feb 14, 2023 Information published.  How satisfied are you with the MSRC Security Update Guide? Rating  Broken  Bad  Below average  Average  Great!  Your Privacy Choices Consumer Health Privacy Privacy & Cookies

Share this article