Bleeping Computer

Microsoft January 2023 Patch Tuesday fixes 98 flaws, 1 zero-day


TagCVE IDCVE TitleSeverity.NET CoreCVE-2023-21538.NET Denial of Service VulnerabilityImportant3D BuilderCVE-2023-217823D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217813D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217833D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217843D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217913D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217933D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217863D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217903D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217803D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217923D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217893D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217853D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217873D Builder Remote Code Execution VulnerabilityImportant3D BuilderCVE-2023-217883D Builder Remote Code Execution VulnerabilityImportantAzure Service Fabric ContainerCVE-2023-21531Azure Service Fabric Container Elevation of Privilege VulnerabilityImportantMicrosoft Bluetooth DriverCVE-2023-21739Windows Bluetooth Driver Elevation of Privilege VulnerabilityImportantMicrosoft Exchange ServerCVE-2023-21764Microsoft Exchange Server Elevation of Privilege VulnerabilityImportantMicrosoft Exchange ServerCVE-2023-21763Microsoft Exchange Server Elevation of Privilege VulnerabilityImportantMicrosoft Exchange ServerCVE-2023-21762Microsoft Exchange Server Spoofing VulnerabilityImportantMicrosoft Exchange ServerCVE-2023-21761Microsoft Exchange Server Information Disclosure VulnerabilityImportantMicrosoft Exchange ServerCVE-2023-21745Microsoft Exchange Server Spoofing VulnerabilityImportantMicrosoft Graphics ComponentCVE-2023-21680Windows Win32k Elevation of Privilege VulnerabilityImportantMicrosoft Graphics ComponentCVE-2023-21532Windows GDI Elevation of Privilege VulnerabilityImportantMicrosoft Graphics ComponentCVE-2023-21552Windows GDI Elevation of Privilege VulnerabilityImportantMicrosoft Local Security Authority Server (lsasrv)CVE-2023-21728Windows Netlogon Denial of Service VulnerabilityImportantMicrosoft Message QueuingCVE-2023-21537Microsoft Message Queuing (MSMQ) Elevation of Privilege VulnerabilityImportantMicrosoft OfficeCVE-2023-21734Microsoft Office Remote Code Execution VulnerabilityImportantMicrosoft OfficeCVE-2023-21735Microsoft Office Remote Code Execution VulnerabilityImportantMicrosoft Office SharePointCVE-2023-21742Microsoft SharePoint Server Remote Code Execution VulnerabilityImportantMicrosoft Office SharePointCVE-2023-21743Microsoft SharePoint Server Security Feature Bypass VulnerabilityCriticalMicrosoft Office SharePointCVE-2023-21744Microsoft SharePoint Server Remote Code Execution VulnerabilityImportantMicrosoft Office VisioCVE-2023-21741Microsoft Office Visio Information Disclosure VulnerabilityImportantMicrosoft Office VisioCVE-2023-21736Microsoft Office Visio Remote Code Execution VulnerabilityImportantMicrosoft Office VisioCVE-2023-21737Microsoft Office Visio Remote Code Execution VulnerabilityImportantMicrosoft Office VisioCVE-2023-21738Microsoft Office Visio Remote Code Execution VulnerabilityImportantMicrosoft WDAC OLE DB provider for SQLCVE-2023-21681Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution VulnerabilityImportantVisual Studio CodeCVE-2023-21779Visual Studio Code Remote Code ExecutionImportantWindows ALPCCVE-2023-21674Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege VulnerabilityImportantWindows Ancillary Function Driver for WinSockCVE-2023-21768Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportantWindows Authentication MethodsCVE-2023-21539Windows Authentication Remote Code Execution VulnerabilityImportantWindows Backup EngineCVE-2023-21752Windows Backup Service Elevation of Privilege VulnerabilityImportantWindows Bind Filter DriverCVE-2023-21733Windows Bind Filter Driver Elevation of Privilege VulnerabilityImportantWindows BitLockerCVE-2023-21563BitLocker Security Feature Bypass VulnerabilityImportantWindows Boot ManagerCVE-2023-21560Windows Boot Manager Security Feature Bypass VulnerabilityImportantWindows Credential ManagerCVE-2023-21726Windows Credential Manager User Interface Elevation of Privilege VulnerabilityImportantWindows Cryptographic ServicesCVE-2023-21559Windows Cryptographic Information Disclosure VulnerabilityImportantWindows Cryptographic ServicesCVE-2023-21551Microsoft Cryptographic Services Elevation of Privilege VulnerabilityCriticalWindows Cryptographic ServicesCVE-2023-21561Microsoft Cryptographic Services Elevation of Privilege VulnerabilityCriticalWindows Cryptographic ServicesCVE-2023-21540Windows Cryptographic Information Disclosure VulnerabilityImportantWindows Cryptographic ServicesCVE-2023-21730Microsoft Cryptographic Services Elevation of Privilege VulnerabilityCriticalWindows Cryptographic ServicesCVE-2023-21550Windows Cryptographic Information Disclosure VulnerabilityImportantWindows DWM Core LibraryCVE-2023-21724Microsoft DWM Core Library Elevation of Privilege VulnerabilityImportantWindows Error ReportingCVE-2023-21558Windows Error Reporting Service Elevation of Privilege VulnerabilityImportantWindows Event TracingCVE-2023-21536Event Tracing for Windows Information Disclosure VulnerabilityImportantWindows IKE ExtensionCVE-2023-21758Windows Internet Key Exchange (IKE) Extension Denial of Service VulnerabilityImportantWindows IKE ExtensionCVE-2023-21683Windows Internet Key Exchange (IKE) Extension Denial of Service VulnerabilityImportantWindows IKE ExtensionCVE-2023-21677Windows Internet Key Exchange (IKE) Extension Denial of Service VulnerabilityImportantWindows InstallerCVE-2023-21542Windows Installer Elevation of Privilege VulnerabilityImportantWindows Internet Key Exchange (IKE) ProtocolCVE-2023-21547Internet Key Exchange (IKE) Protocol Denial of Service VulnerabilityImportantWindows iSCSICVE-2023-21527Windows iSCSI Service Denial of Service VulnerabilityImportantWindows KernelCVE-2023-21755Windows Kernel Elevation of Privilege VulnerabilityImportantWindows KernelCVE-2023-21753Event Tracing for Windows Information Disclosure VulnerabilityImportantWindows Layer 2 Tunneling ProtocolCVE-2023-21556Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution VulnerabilityCriticalWindows Layer 2 Tunneling ProtocolCVE-2023-21555Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution VulnerabilityCriticalWindows Layer 2 Tunneling ProtocolCVE-2023-21543Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution VulnerabilityCriticalWindows Layer 2 Tunneling ProtocolCVE-2023-21546Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution VulnerabilityCriticalWindows Layer 2 Tunneling ProtocolCVE-2023-21679Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution VulnerabilityCriticalWindows LDAP – Lightweight Directory Access ProtocolCVE-2023-21676Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityImportantWindows LDAP – Lightweight Directory Access ProtocolCVE-2023-21557Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityImportantWindows Local Security Authority (LSA)CVE-2023-21524Windows Local Security Authority (LSA) Elevation of Privilege VulnerabilityImportantWindows Local Session Manager (LSM)CVE-2023-21771Windows Local Session Manager (LSM) Elevation of Privilege VulnerabilityImportantWindows Malicious Software Removal ToolCVE-2023-21725Windows Malicious Software Removal Tool Elevation of Privilege VulnerabilityImportantWindows Management InstrumentationCVE-2023-21754Windows Kernel Elevation of Privilege VulnerabilityImportantWindows NTLMCVE-2023-21746Windows NTLM Elevation of Privilege VulnerabilityImportantWindows ODBC DriverCVE-2023-21732Microsoft ODBC Driver Remote Code Execution VulnerabilityImportantWindows Overlay FilterCVE-2023-21766Windows Overlay Filter Information Disclosure VulnerabilityImportantWindows Overlay FilterCVE-2023-21767Windows Overlay Filter Elevation of Privilege VulnerabilityImportantWindows Point-to-Point Tunneling ProtocolCVE-2023-21682Windows Point-to-Point Protocol (PPP) Information Disclosure VulnerabilityImportantWindows Print Spooler ComponentsCVE-2023-21760Windows Print Spooler Elevation of Privilege VulnerabilityImportantWindows Print Spooler ComponentsCVE-2023-21765Windows Print Spooler Elevation of Privilege VulnerabilityImportantWindows Print Spooler ComponentsCVE-2023-21678Windows Print Spooler Elevation of Privilege VulnerabilityImportantWindows Remote Access Service L2TP DriverCVE-2023-21757Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service VulnerabilityImportantWindows RPC APICVE-2023-21525Remote Procedure Call Runtime Denial of Service VulnerabilityImportantWindows Secure Socket Tunneling Protocol (SSTP)CVE-2023-21548Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityCriticalWindows Secure Socket Tunneling Protocol (SSTP)CVE-2023-21535Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityCriticalWindows Smart CardCVE-2023-21759Windows Smart Card Resource Management Server Security Feature Bypass VulnerabilityImportantWindows Task SchedulerCVE-2023-21541Windows Task Scheduler Elevation of Privilege VulnerabilityImportantWindows Virtual Registry ProviderCVE-2023-21772Windows Kernel Elevation of Privilege VulnerabilityImportantWindows Virtual Registry ProviderCVE-2023-21748Windows Kernel Elevation of Privilege VulnerabilityImportantWindows Virtual Registry ProviderCVE-2023-21773Windows Kernel Elevation of Privilege VulnerabilityImportantWindows Virtual Registry ProviderCVE-2023-21747Windows Kernel Elevation of Privilege VulnerabilityImportantWindows Virtual Registry ProviderCVE-2023-21776Windows Kernel Information Disclosure VulnerabilityImportantWindows Virtual Registry ProviderCVE-2023-21774Windows Kernel Elevation of Privilege VulnerabilityImportantWindows Virtual Registry ProviderCVE-2023-21750Windows Kernel Elevation of Privilege VulnerabilityImportantWindows Virtual Registry ProviderCVE-2023-21675Windows Kernel Elevation of Privilege VulnerabilityImportantWindows Virtual Registry ProviderCVE-2023-21749Windows Kernel Elevation of Privilege VulnerabilityImportantWindows Workstation ServiceCVE-2023-21549Windows SMB Witness Service Elevation of Privilege VulnerabilityImportant



Source link