HomeUpdatesMicrosoft: Patch Tuesday December 2023 released

Microsoft: Patch Tuesday December 2023 released

Microsoft released the December 2023 Patch Tuesday updates yesterday , bringing fixes for 34 vulnerabilities and one zero-day vulnerability in AMD processors .

Microsoft Patch Tuesday

Among the vulnerabilities fixed are eight that could allow remote code execution (RCE). However, Microsoft only rated three of them as critical. In total, there were four critical bugs: one in Power Platform (Spoofing), two in Internet Connection Sharing (RCE), and one in Windows MSHTML Platform (RCE).

See also: CISA adds two Qlik Sense vulnerabilities to the KEV List

In the list below, you can see the categories of vulnerabilities fixed in Microsoft's December Patch Tuesday:

  • 10 vulnerabilities that allow for elevation of privilege
  • 8 vulnerabilities that allow remote code execution
  • 6 vulnerabilities that allow information disclosure
  • 5 vulnerabilities that allow Denial of Service attacks
  • 5 Spoofing vulnerabilities

The total number of 34 vulnerabilities does not include 8 Microsoft Edge that were fixed on December 7.

See also: Apple fixes zero-day vulnerabilities in older iPhones

Microsoft: Patch Tuesday December 2023 released

Patch Tuesday: Fixes a zero-day vulnerability

The December 2023 Patch Tuesday fixes a zero-day in AMD CPUs that was publicly disclosed in August. The vulnerability, “CVE-2023-20588 – AMD Speculative Leaks,” is a division-by-zero bug in certain AMD processors that could expose sensitive data.

Despite being disclosed in August, AMD has not provided any fixes. It has simply suggested the following: “For affected products, AMD recommends following best software development practices,” an AMD bulletin states.

“Developers can mitigate this issue by ensuring that privileged data is not used in division operations before changing privilege boundaries. AMD believes the potential impact of this vulnerability is low because it requires local access.“.

See also: Backup Migration: WordPress plugin vulnerable to critical vulnerability

As part of the December updates, Microsoft released a security update that resolves this bug on affected AMD.

Microsoft Patch Tuesday December 2023: All vulnerabilities fixed

In the table below, you can see all the vulnerabilities that Microsoft is patching this month in its products:

TagsCVE IDCVE TitleSeverity
Azure Connected Machine AgentCVE-2023-35624Azure Connected Machine Agent Elevation of Privilege VulnerabilityImportant
Azure Machine LearningCVE-2023-35625Azure Machine Learning Compute Instance for SDK Users Information Disclosure VulnerabilityImportant
ChipsetsCVE-2023-20588AMD: CVE-2023-20588 AMD Speculative Leaks Security NoticeImportant
Microsoft Bluetooth DriverCVE-2023-35634Windows Bluetooth Driver Remote Code Execution VulnerabilityImportant
Microsoft DynamicsCVE-2023-35621Microsoft Dynamics 365 Finance and Operations Denial of Service VulnerabilityImportant
Microsoft DynamicsCVE-2023-36020Microsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityImportant
Microsoft Edge (Chromium-based)CVE-2023-35618Microsoft Edge (Chromium-based) Elevation of Privilege VulnerabilityModerate
Microsoft Edge (Chromium-based)CVE-2023-36880Microsoft Edge (Chromium-based) Information Disclosure VulnerabilityLow
Microsoft Edge (Chromium-based)CVE-2023-38174Microsoft Edge (Chromium-based) Information Disclosure VulnerabilityLow
Microsoft Edge (Chromium-based)CVE-2023-6509Chromium: CVE-2023-6509 Use after free in Side Panel SearchUnknown
Microsoft Edge (Chromium-based)CVE-2023-6512Chromium: CVE-2023-6512 Inappropriate implementation in Web Browser UIUnknown
Microsoft Edge (Chromium-based)CVE-2023-6508Chromium: CVE-2023-6508 Use after free in Media StreamUnknown
Microsoft Edge (Chromium-based)CVE-2023-6511Chromium: CVE-2023-6511 Inappropriate implementation in AutofillUnknown
Microsoft Edge (Chromium-based)CVE-2023-6510Chromium: CVE-2023-6510 Use after free in Media CaptureUnknown
Microsoft Office OutlookCVE-2023-35636Microsoft Outlook Information Disclosure VulnerabilityImportant
Microsoft Office OutlookCVE-2023-35619Microsoft Outlook for Mac Spoofing VulnerabilityImportant
Microsoft Office WordCVE-2023-36009Microsoft Word Information Disclosure VulnerabilityImportant
Microsoft Power Platform ConnectorCVE-2023-36019Microsoft Power Platform Connector Spoofing VulnerabilityCritical
Microsoft WDAC OLE DB provider for SQLCVE-2023-36006Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution VulnerabilityImportant
Microsoft Windows DNSCVE-2023-35622Windows DNS Spoofing VulnerabilityImportant
Windows Cloud Files Mini Filter DriverCVE-2023-36696Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityImportant
Windows DefenderCVE-2023-36010Microsoft Defender Denial of Service VulnerabilityImportant
Windows DHCP ServerCVE-2023-35643DHCP Server Service Information Disclosure VulnerabilityImportant
Windows DHCP ServerCVE-2023-35638DHCP Server Denial of Service VulnerabilityImportant
Windows DHCP ServerCVE-2023-36012DHCP Server Service Information Disclosure VulnerabilityImportant
Windows DPAPI (Data Protection Application Programming Interface)CVE-2023-36004Windows DPAPI (Data Protection Application Programming Interface) Spoofing VulnerabilityImportant
Windows Internet Connection Sharing (ICS)CVE-2023-35642Internet Connection Sharing (ICS) Denial of Service VulnerabilityImportant
Windows Internet Connection Sharing (ICS)CVE-2023-35630Internet Connection Sharing (ICS) Remote Code Execution VulnerabilityCritical
Windows Internet Connection Sharing (ICS)CVE-2023-35632Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Internet Connection Sharing (ICS)CVE-2023-35641Internet Connection Sharing (ICS) Remote Code Execution VulnerabilityCritical
Windows KernelCVE-2023-35633Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2023-35635Windows Kernel Denial of Service VulnerabilityImportant
Windows Kernel-Mode DriversCVE-2023-35644Windows Sysmain Service Elevation of PrivilegeImportant
Windows Local Security Authority Subsystem Service (LSASS)CVE-2023-36391Local Security Authority Subsystem Service Elevation of Privilege VulnerabilityImportant
Windows MediaCVE-2023-21740Windows Media Remote Code Execution VulnerabilityImportant
Windows MSHTML PlatformCVE-2023-35628Windows MSHTML Platform Remote Code Execution VulnerabilityCritical
Windows ODBC DriverCVE-2023-35639Microsoft ODBC Driver Remote Code Execution VulnerabilityImportant
Windows Telephony ServerCVE-2023-36005Windows Telephony Server Elevation of Privilege VulnerabilityImportant
Windows USB Mass Storage Class DriverCVE-2023-35629Microsoft USBHUB 3.0 Device Driver Remote Code Execution VulnerabilityImportant
Windows Win32KCVE-2023-36011Win32k Elevation of Privilege VulnerabilityImportant
Windows Win32KCVE-2023-35631Win32k Elevation of Privilege VulnerabilityImportant
XAML DiagnosticsCVE-2023-36003XAML Diagnostics Elevation of Privilege VulnerabilityImportant

Microsoft Patch Tuesday is a practice followed by Microsoft, where on the second Tuesday of each month, it releases updates and fixes for its operating systems , programs, and applications. These updates typically include security fixes, performance improvements, and new features.

The purpose of Microsoft Patch Tuesday is to provide Microsoft users with the best possible user experience by fixing issues and ensuring the security of their systems. Microsoft Patch Tuesday is important for several reasons. First, security updates help protect systems from security vulnerabilities and malware . These updates fix known security issues and strengthen the resilience of systems against attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS