Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

Microsoft Patch Tuesday, December 2023 Edition

The final Patch Tuesday of 2023 is upon us, with Microsoft Corp. today releasing fixes for a relatively small number of security holes in its Windows operating systems and other software. Even more unusual, there are no known "zero-day" threats targeting any of the vulnerabilities in December's patch batch. Still, four of the updates pushed out today address "critical" vulnerabilities that Microsoft says can be exploited by malware or malcontents to seize complete control over a vulnerable Windows device with little or no help from users.

Krebs on Security
#vulnerability#web#mac#windows#microsoft#git#rce#zero_day#blog
Microsoft releases lightest Patch Tuesday in three years, no zero-days disclosed

The company’s regular set of advisories has included a vulnerability that’s been actively exploited in the wild in 10 months this year.

CVE-2023-21740

Windows Media Remote Code Execution Vulnerability

CVE-2023-35622

Windows DNS Spoofing Vulnerability

CVE-2023-35632

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2023-35633

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-35644

Windows Sysmain Service Elevation of Privilege

CVE-2023-36696

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-36005

Windows Telephony Server Elevation of Privilege Vulnerability

CVE-2023-36004

Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability