Yesterday, Microsoft released the November 2023 Patch Tuesday, which includes security for about 60 vulnerabilities. Five of these vulnerabilities are zero-days.

Microsoft Patch Tuesday is a practice followed by Microsoft, where on the second Tuesday of each month it releases updates and fixes for its operating systems , programs and applications. These updates usually include security fixes, performance improvements and new features. The purpose of Microsoft Patch Tuesday is to provide Microsoft users with the best possible user experience by fixing problems and ensuring the security of their systems.
Microsoft Patch Tuesday is important for several reasons. First, security updates help protect systems from vulnerabilities and malware. These updates fix known security issues and make systems more resilient to attacks.
See also: QNAP patches critical command injection vulnerabilities in QTS OS
The new Patch Tuesday patch fixes fourteen remote code execution (RCE) vulnerabilities , but Microsoft only rated one as critical. The other two critical vulnerabilities are one that allows disclosure information and another that leads to execution of programs on the host with SYSTEM privileges.
The categories of vulnerabilities fixed in Microsoft's November Patch Tuesday are:
- 16 vulnerabilities that allow for elevation of privilege
- 15 vulnerabilities that allow remote code execution
- 11 spoofing vulnerabilities
- 6 vulnerabilities that allow security features to be bypassed
- 6 vulnerabilities that allow information disclosure
- 5 vulnerabilities that allow Denial of Service attacks
5 zero-day vulnerabilities
Microsoft Patch Tuesday November 2023 fixes five zero-day vulnerabilities. Microsoft classifies a vulnerability as a zero-day if it is publicly disclosed or actively exploited without an official patch being released. Here, we have both cases.
See also: Veeam patches serious vulnerabilities in Veeam ONE
Three zero-day vulnerabilities have been used in attacks:
CVE-2023-36036 – Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Microsoft has fixed a bug in the Windows Cloud Files Mini Filterthat could allow attackers to gain elevated privileges on the vulnerable system.
“An attacker who successfully exploited this vulnerability could gain SYSTEM,” Microsoft explains.
It is not known how the bug was exploited in attacks. We also do not know who exploited the vulnerability.
The vulnerability was discovered internally by the Microsoft Threat Intelligence Security Response Center.
CVE-2023-36033 – Windows DWM Core Library Elevation of Privilege Vulnerability
This Patch Tuesday, Microsoft is also fixing another zero-day vulnerability in the Windows DWM Core Library that also allows elevation of privilege to SYSTEM. This vulnerability has been exploited in attacks and has been publicly disclosed.
“An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” Microsoft explains.
Microsoft says the flaw was discovered by Quan Jin(@jq0904) from DBAPPsecurity WeBin Lab, but did not share details about how it was used in attacks.
CVE-2023-36025 – Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft has also fixed a bug in Windows SmartScreen that was exploited by cybercriminals and allows a malicious Internet Shortcut to bypass security checks and warnings.
“The attacker could bypass Windows Defender SmartScreen checks and related prompts,” Microsoft explains.
“The user would have to click on a specially crafted Internet Shortcut (.URL) or a hyperlink that points to an Internet Shortcut file to be compromised by the attacker,” Microsoft continues.
Microsoft says the flaw was discovered by Will Metcalf (Splunk), Microsoft Threat Intelligence, and the Microsoft Office Product Group Security Team.
See also: Citrix: Immediate action to fix critical issue in NetScaler

The latest zero-day vulnerabilities fixed with Microsoft's November Patch Tuesday are:
CVE-2023-36413 – Microsoft Office Security Feature Bypass Vulnerability
A vulnerability in Microsoft Office that allows the bypass of security.
CVE-2023-36038 — CVE-2023-36038 — ASP.NET Core Denial of Service Vulnerability
A vulnerability that allows Denial of Service attacks.
However, Microsoft says that these vulnerabilities have not been used in attacks. They have simply been publicly disclosed.
Microsoft Patch Tuesday November 2023
In the table below, you can see in detail the vulnerabilities that Microsoft fixed this month:
| Tags | CVE ID | CVE Title | Severity |
|---|---|---|---|
| .NET Framework | CVE-2023-36049 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | Important |
| ASP.NET | CVE-2023-36560 | ASP.NET Security Feature Bypass Vulnerability | Important |
| ASP.NET | CVE-2023-36038 | ASP.NET Core Denial of Service Vulnerability | Important |
| ASP.NET | CVE-2023-36558 | ASP.NET Core – Security Feature Bypass Vulnerability | Important |
| Azure | CVE-2023-36052 | Azure CLI REST Command Information Disclosure Vulnerability | Critical |
| Azure | CVE-2023-38151 | Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability | Important |
| Azure | CVE-2023-36021 | Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability | Important |
| Azure DevOps | CVE-2023-36437 | Azure DevOps Server Remote Code Execution Vulnerability | Important |
| Mariner | CVE-2020-1747 | Unknown | Unknown |
| Mariner | CVE-2023-46316 | Unknown | Unknown |
| Mariner | CVE-2023-46753 | Unknown | Unknown |
| Mariner | CVE-2020-8554 | Unknown | Unknown |
| Mariner | CVE-2020-14343 | Unknown | Unknown |
| Microsoft Bluetooth Driver | CVE-2023-24023 | Miter: CVE-2023-24023 Bluetooth Vulnerability | Important |
| Microsoft Dynamics | CVE-2023-36016 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important |
| Microsoft Dynamics | CVE-2023-36007 | Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability | Important |
| Microsoft Dynamics | CVE-2023-36031 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important |
| Microsoft Dynamics | CVE-2023-36410 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important |
| Microsoft Dynamics 365 Sales | CVE-2023-36030 | Microsoft Dynamics 365 Sales Spoofing Vulnerability | Important |
| Microsoft Edge (Chromium-based) | CVE-2023-36014 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Moderate |
| Microsoft Edge (Chromium-based) | CVE-2023-5996 | Chromium: CVE-2023-5996 Use after free in WebAudio | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-36022 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Moderate |
| Microsoft Edge (Chromium-based) | CVE-2023-36027 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important |
| Microsoft Edge (Chromium-based) | CVE-2023-36029 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Moderate |
| Microsoft Edge (Chromium-based) | CVE-2023-5480 | Chromium: CVE-2023-5480 Inappropriate implementation in Payments | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-5856 | Chromium: CVE-2023-5856 Use after free in Side Panel | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-5855 | Chromium: CVE-2023-5855 Use after free in Reading Mode | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-5854 | Chromium: CVE-2023-5854 Use after free in Profiles | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-5859 | Chromium: CVE-2023-5859 Incorrect security UI in Picture In Picture | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-5858 | Chromium: CVE-2023-5858 Inappropriate implementation in WebApp Provider | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-5857 | Chromium: CVE-2023-5857 Inappropriate implementation in Downloads | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-5850 | Chromium: CVE-2023-5850 Incorrect security UI in Downloads | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-5849 | Chromium: CVE-2023-5849 Integer overflow in USB | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-5482 | Chromium: CVE-2023-5482 Insufficient data validation in USB | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-5853 | Chromium: CVE-2023-5853 Incorrect security UI in Downloads | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-5852 | Chromium: CVE-2023-5852 Use after free in Printing | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-5851 | Chromium: CVE-2023-5851 Inappropriate implementation in Downloads | Unknown |
| Microsoft Edge (Chromium-based) | CVE-2023-36024 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important |
| Microsoft Edge (Chromium-based) | CVE-2023-36034 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Moderate |
| Microsoft Exchange Server | CVE-2023-36439 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important |
| Microsoft Exchange Server | CVE-2023-36050 | Microsoft Exchange Server Spoofing Vulnerability | Important |
| Microsoft Exchange Server | CVE-2023-36039 | Microsoft Exchange Server Spoofing Vulnerability | Important |
| Microsoft Exchange Server | CVE-2023-36035 | Microsoft Exchange Server Spoofing Vulnerability | Important |
| Microsoft Office | CVE-2023-36413 | Microsoft Office Security Feature Bypass Vulnerability | Important |
| Microsoft Office | CVE-2023-36045 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2023-36041 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2023-36037 | Microsoft Excel Security Feature Bypass Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2023-38177 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
| Microsoft Remote Registry Service | CVE-2023-36423 | Microsoft Remote Registry Service Remote Code Execution Vulnerability | Important |
| Microsoft Remote Registry Service | CVE-2023-36401 | Microsoft Remote Registry Service Remote Code Execution Vulnerability | Important |
| Microsoft WDAC OLE DB provider for SQL | CVE-2023-36402 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important |
| Microsoft Windows Search Component | CVE-2023-36394 | Windows Search Service Elevation of Privilege Vulnerability | Important |
| Microsoft Windows Speech | CVE-2023-36719 | Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability | Important |
| Open Management Infrastructure | CVE-2023-36043 | Open Management Infrastructure Information Disclosure Vulnerability | Important |
| Tablet Windows User Interface | CVE-2023-36393 | Windows User Interface Application Core Remote Code Execution Vulnerability | Important |
| Visual Studio | CVE-2023-36042 | Visual Studio Denial of Service Vulnerability | Important |
| Visual Studio Code | CVE-2023-36018 | Visual Studio Code Jupyter Extension Spoofing Vulnerability | Important |
| Windows Authentication Methods | CVE-2023-36047 | Windows Authentication Elevation of Privilege Vulnerability | Important |
| Windows Authentication Methods | CVE-2023-36428 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | Important |
| Windows Authentication Methods | CVE-2023-36046 | Windows Authentication Denial of Service Vulnerability | Important |
| Windows Cloud Files Mini Filter Driver | CVE-2023-36036 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important |
| Windows Common Log File System Driver | CVE-2023-36424 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important |
| Windows Compressed Folder | CVE-2023-36396 | Windows Compressed Folder Remote Code Execution Vulnerability | Important |
| Windows Defender | CVE-2023-36422 | Microsoft Windows Defender Elevation of Privilege Vulnerability | Important |
| Windows Deployment Services | CVE-2023-36395 | Windows Deployment Services Denial of Service Vulnerability | Important |
| Windows DHCP Server | CVE-2023-36392 | DHCP Server Denial of Service Vulnerability | Important |
| Windows Distributed File System (DFS) | CVE-2023-36425 | Windows Distributed File System (DFS) Remote Code Execution Vulnerability | Important |
| Windows DWM Core Library | CVE-2023-36033 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows HMAC Key Derivation | CVE-2023-36400 | Windows HMAC Key Derivation Elevation of Privilege Vulnerability | Critical |
| Windows Hyper-V | CVE-2023-36427 | Windows Hyper-V Elevation of Privilege Vulnerability | Important |
| Windows Hyper-V | CVE-2023-36407 | Windows Hyper-V Elevation of Privilege Vulnerability | Important |
| Windows Hyper-V | CVE-2023-36406 | Windows Hyper-V Information Disclosure Vulnerability | Important |
| Windows Hyper-V | CVE-2023-36408 | Windows Hyper-V Elevation of Privilege Vulnerability | Important |
| Windows Installer | CVE-2023-36705 | Windows Installer Elevation of Privilege Vulnerability | Important |
| Windows Internet Connection Sharing (ICS) | CVE-2023-36397 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | Critical |
| Windows Kernel | CVE-2023-36405 | Windows Kernel Elevation of Privilege Vulnerability | Important |
| Windows Kernel | CVE-2023-36404 | Windows Kernel Information Disclosure Vulnerability | Important |
| Windows Kernel | CVE-2023-36403 | Windows Kernel Elevation of Privilege Vulnerability | Important |
| Windows NTFS | CVE-2023-36398 | Windows NTFS Information Disclosure Vulnerability | Important |
| Windows Protected EAP (PEAP) | CVE-2023-36028 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Important |
| Windows Scripting | CVE-2023-36017 | Windows Scripting Engine Memory Corruption Vulnerability | Important |
| Windows SmartScreen | CVE-2023-36025 | Windows SmartScreen Security Feature Bypass Vulnerability | Important |
| Windows Storage | CVE-2023-36399 | Windows Storage Elevation of Privilege Vulnerability | Important |
Source: www.bleepingcomputer.com
