Security News > 2023 > February > Update Now: Microsoft Releases Patches for 3 Actively Exploited Windows Vulnerabilities

Update Now: Microsoft Releases Patches for 3 Actively Exploited Windows Vulnerabilities
2023-02-15 04:21

The updates are in addition to 22 flaws the Windows maker patched in its Chromium-based Edge browser over the past month.

"The attack itself is carried out locally by a user with authentication to the targeted system," Microsoft said in advisory for CVE-2023-21715.

CVE-2023-23376 is also the third actively exploited zero-day flaw in the CLFS component after CVE-2022-24521 and CVE-2022-37969, which were addressed by Microsoft in April and September 2022.

"The Windows Common Log File System Driver is a component of the Windows operating system that manages and maintains a high-performance, transaction-based log file system," Immersive Labs' Nikolas Cemerikic said.

"It is an essential component of the Windows operating system, and any vulnerabilities in this driver could have significant implications for the security and reliability of the system."

Also addressed by Microsoft are multiple RCE defects in Exchange Server, ODBC Driver, PostScript Printer Driver, and SQL Server as well as denial-of-service issues impacting Windows iSCSI Service and Windows Secure Channel.


News URL

https://thehackernews.com/2023/02/update-now-microsoft-releases-patches.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-02-14 CVE-2023-23376 Unspecified vulnerability in Microsoft products
Windows Common Log File System Driver Elevation of Privilege Vulnerability
local
low complexity
microsoft
7.8
2023-02-14 CVE-2023-21715 Incorrect Authorization vulnerability in Microsoft 365 Apps
Microsoft Publisher Security Features Bypass Vulnerability
local
low complexity
microsoft CWE-863
5.0
2022-09-13 CVE-2022-37969 Out-of-bounds Write vulnerability in Microsoft products
Windows Common Log File System Driver Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-787
7.8
2022-04-15 CVE-2022-24521 Improper Input Validation vulnerability in Microsoft products
Windows Common Log File System Driver Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-20
7.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 678 805 4494 4179 3706 13184