Security News > 2023 > March > Microsoft Rolls Out Patches for 80 New Security Flaws — Two Under Active Attack

Microsoft's Patch Tuesday update for March 2023 is rolling out with remediations for a set of 80 security flaws, two of which have come under active exploitation in the wild.
The two vulnerabilities that have come under active attack include a Microsoft Outlook privilege escalation flaw and a Windows SmartScreen security feature bypass.
The disclosure also comes as the U.S. Cybersecurity and Infrastructure Security Agency added the two flaws to the Known Exploited Vulnerabilities catalog and announced a new pilot program that aims to warn critical infrastructure entities about "Vulnerabilities commonly associated with known ransomware exploitation."
Also closed out by Microsoft are a number of critical remote code execution flaws impacting HTTP Protocol Stack, Internet Control Message Protocol, and Remote Procedure Call Runtime.
Other notable mentions include patches for four privilege escalation bugs identified in the Windows Kernel, 10 remote code execution flaws affecting Microsoft PostScript and PCL6 Class Printer Driver, and a WebView2 spoofing vulnerability in the Edge browser.
Elsewhere, Microsoft also closed out two information disclosure flaws in Microsoft OneDrive for Android, one spoofing vulnerability in Office for Android, one security bypass bug in Microsoft OneDrive for iOS, and one privilege escalation issue in OneDrive for macOS. Rounding off the list are patches for two high-severity vulnerabilities in the Trusted Platform Module 2.0 reference library specification that could lead to information disclosure or privilege escalation.
News URL
https://thehackernews.com/2023/03/microsoft-rolls-out-patches-for-80-new.html
Related news
- Hidden Threats: How Microsoft 365 Backups Store Risks for Future Attacks (source)
- AI agents swarm Microsoft Security Copilot (source)
- AI-Powered SaaS Security: Keeping Pace with an Expanding Attack Surface (source)
- After Detecting 30B Phishing Attempts, Microsoft Adds Even More AI to Its Security Copilot (source)
- Android Malware Exploits a Microsoft-Related Security Blind Spot to Avoid Detection (source)
- Week in review: Chrome sandbox escape 0-day fixed, Microsoft adds new AI agents to Security Copilot (source)
- Microsoft Warns of Tax-Themed Email Attacks Using PDFs and QR Codes to Deliver Malware (source)
- April 2025 Patch Tuesday forecast: More AI security introduced by Microsoft (source)
- New TCESB Malware Found in Active Attacks Exploiting ESET Security Scanner (source)
- Google's got a hot cloud infosec startup, a new unified platform — and its eye on Microsoft's $20B+ security biz (source)