Microsoft Monthly Security Update (November 2023)
RISK: High Risk
TYPE: Operating Systems - Windows OS
Microsoft has released monthly security update for their products:
Vulnerable Product | Risk Level | Impacts | Notes |
Browser | Medium Risk | Remote Code Execution Elevation of Privilege Spoofing | |
Azure | Medium Risk | Remote Code Execution Information Disclosure Security Restriction Bypass | |
Windows | High Risk | Elevation of Privilege Information Disclosure Remote Code Execution Denial of Service Spoofing Security Restriction Bypass | CVE-2023-36025 is being exploited in the wild. The vulnerability allows a malicious internet shortcut to bypass secuirty checks and warnings.
CVE-2023-36033 is being exploited in the wild. The vulnerability can be expoloited to gain SYSTEM privileges.
CVE-2023-36036 is being exploited in the wild. The vulnerability can be exploited to gain SYSTEM privileges. |
Extended Security Updates (ESU) | High Risk | Elevation of Privilege Information Disclosure Remote Code Execution Denial of Service Security Restriction Bypass | CVE-2023-36025 is being exploited in the wild. The vulnerability allows a malicious internet shortcut to bypass secuirty checks and warnings.
CVE-2023-36033 is being exploited in the wild. The vulnerability can be expoloited to gain SYSTEM privileges.
CVE-2023-36036 is being exploited in the wild. The vulnerability can be exploited to gain SYSTEM privileges. |
Developer Tools | Medium Risk | Security Restriction Bypass Elevation of Privilege Denial of Service Spoofing | |
System Center | Medium Risk | Elevation of Privilege Information Disclosure | |
Microsoft Office | Medium Risk | Security Restriction Bypass Remote Code Execution | |
Microsoft Dynamics | Low Risk | Spoofing | |
Exchange Server | Medium Risk | Remote Code Execution Spoofing | |
Mariner | Low Risk | Denial of Service |
Number of 'Extremely High Risk' product(s): 0
Number of 'High Risk' product(s): 2
Number of 'Medium Risk' product(s): 6
Number of 'Low Risk' product(s): 2
Evaluation of overall 'Risk Level': High Risk
Impact
- Remote Code Execution
- Denial of Service
- Elevation of Privilege
- Information Disclosure
- Security Restriction Bypass
- Spoofing
System / Technologies affected
- Browser
- Windows
- Extended Security Updates (ESU)
- Developer Tools
- Azure
- Microsoft Office
- SQL Server
- Microsoft Dynamics
- Exchange Server
- Mariner
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Apply fixes issued by the vendor.
Vulnerability Identifier
Source
Related Link
Related Tags
Share with