logo

CVE-2023-38146: ThemeBleed vulnerability exploit

ID: 91e910f7-8fc0-5d49-9044-a8055a027a8f

STIX ID: report--91e910f7-8fc0-5d49-9044-a8055a027a8f

Feed Name: ThreatLocker Blog

Threat Score
85/100

Date Published: 2025-01-03

Date Updated: 2026-05-01

...
...

CVE-2023-38146 is a critical zero-day remote code execution vulnerability in Windows 11 that can be exploited by opening specially crafted ".theme" files (which reference malicious ".msstyles"), enabling attackers to execute arbitrary code; ThreatLocker reproduced the exploit (ThemeBleed) and the advisory recommends applying Microsoft patches, updating security intelligence, and using ThreatLocker allowlisting and Ringfencing™ to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.