CVE-2023-45232: exploitation status and patch state

CVE-2023-45232 · CVSS 7.5 HIGH · EPSS 2%

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

Is CVE-2023-45232 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2023-45232

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.