Microsoft Releases Updates to Patch Critical Flaws in Windows and Other Software

June 14, 2023Ravi LakshmananPatch Tuesday / Vulnerability

microsoft

Microsoft has released fixes for the Windows operating system and other software components to fix major security flaws as part of its June 2023 Patch Tuesday updates.

Of the 73 flaws, the severity is rated 6 as Critical, 63 as Critical, 2 as Moderate, and 1 as Low. This also includes his three issues that the tech giant addressed with his Chromium-based Edge browser.

It’s worth noting that Microsoft has also closed 26 other Edge flaws (all rooted in Chromium itself) since the release of the May Patch Tuesday update. This constitutes his CVE-2023-3079, a zero-day bug that Google disclosed last week as being actively exploited in the wild.

cyber security

The June 2023 update is also the first update in months not to feature a zero-day flaw in a Microsoft product that was publicly known or under active attack at the time of its release.

Topping the list of fixes is CVE-2023-29357 (CVSS score: 9.8). This is a privilege escalation flaw in SharePoint Server that an attacker could exploit to gain administrative privileges.

“An attacker with access to a spoofed JWT authentication token could use it to bypass authentication and perform network attacks that could gain access to the privileges of the authenticated user,” Microsoft said. “Attackers do not need privileges and users do not need to take any action.”

Three critical remote code execution bugs in Windows Pragmatic General Multicast (PGM) (CVE-2023-29363, CVE-2023-32014, and CVE-2023-32015, CVSS score: 9.8) have also been patched by Redmond. . These can be weaponized. Attempts to remotely execute code and trigger malicious code. ”

Microsoft previously announced in April 2023 a similar in the same component (CVE-2023-28250, CVSS score: 9.8), a protocol designed to reliably deliver packets between multiple network members. Addressed a defect in

upcoming webinars

🔐 Mastering API Security: Understanding Your True Attack Surface

Discover untapped vulnerabilities in your API ecosystem and take proactive steps towards ironclad security. Join us for an insightful webinar!

join the session

Two remote code execution bugs (CVE-2023-28310 and CVE-2023-32031) affecting Exchange Server have also been resolved by the technology giant. These bugs could allow an authenticated attacker to perform remote code execution on an affected installation.

Software patches from other vendors

In addition to Microsoft, other vendors have released security updates over the past few weeks that fix several vulnerabilities, including:

Did you enjoy this article? Follow us twitter You can read more exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *