13 September 2023

Microsoft’s September 2023 Patch Tuesday fixes nearly 60 flaws, two zero-days


Microsoft’s September 2023 Patch Tuesday fixes nearly 60 flaws, two zero-days

Microsoft has released its monthly batch of security updates that address nearly 60 security vulnerabilities in various products, including two zero-day issues under active exploitation.

One of the exploited zero-days is CVE-2023-36761, an information disclosure issue in MS Word that allows a remote attacker to gain access to potentially sensitive information by tricking a victim into opening a specially crafted file and obtaining the NTLM hash of the current account.

The second zero-day (CVE-2023-36802) has been described as a privilege escalation bug in Microsoft Streaming Service Proxy that can be used by a local attacker to execute arbitrary code with SYSTEM privileges.

Besides the above-mentioned zero-day flaws, Microsoft has fixed numerous high-risk flaws affecting Windows Defender, Visual Studio Code, Microsoft .Net Framework, Identity Linux Broker, Microsoft Windows Themes, Microsoft Word, Edge, and other products.

In related news, Adobe has also released security updates to patch a zero-day vulnerability in Acrobat and Reader said to have been exploited in hacker attacks.

The vulnerability is tracked as CVE-2023-26369 and can let attackers gain remote code execution by tricking a victim into opening a malicious PDF file.

The company didn’t share any details regarding the nature of the exploit apart from saying that it is aware “that CVE-2023-26369 has been exploited in the wild in limited attacks targeting Adobe Acrobat and Reader.”

In addition, Mozilla has rushed to patch a zero-day vulnerability (CVE-2023-4863) in Firefox and Thunderbird software that has been actively exploited in the wild, a day after Google released a fix for the same issue in its Chrome browser.

Back to the list

Latest Posts

Cyber Security Week in Review: September 6, 2024

Cyber Security Week in Review: September 6, 2024

In brief: the US charges Russian GRU hackers for attacks on Ukraine, Apache, Cisco, Zyxel patch high-risk flaws, Google fixes Android zero-day, and more.
6 September 2024
Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Some of the documents appeared to be part of legitimate Red Team exercises, while other were intended for malicious purposes.
5 September 2024
US seizes 32 domains linked to Russian Doppelganger influence campaign

US seizes 32 domains linked to Russian Doppelganger influence campaign

The domains, used to disseminate propaganda, were seized as part of a broader effort to disrupt Russia’s attempts to interfere in the 2024 US Presidential Election.
5 September 2024