Security News > 2023 > August > Microsoft Releases Patches for 74 New Vulnerabilities in August Update
Microsoft has patched a total of 74 flaws in its software as part of the company's Patch Tuesday updates for August 2023, down from the voluminous 132 vulnerabilities the company fixed last month.
Microsoft said that installing the latest update "Stops the attack chain" leading to the remote code execution bug.
Also patched by the tech giant are numerous remote code execution flaws in Microsoft Message Queuing and Microsoft Teams as well as a number of spoofing vulnerabilities in Azure Apache Ambari, Azure Apache Hadoop, Azure Apache Hive, Azure Apache Oozie, Azure DevOps Server, Azure HDInsight Jupyter, and.
On top of that, Redmond has resolved six denial-of-service and two information disclosure flaws in MSMQ, and follows a number of other problems discovered in the same service that could result in remote code execution and DoS. Three other vulnerabilities of note are CVE-2023-35388, CVE-2023-38182, and CVE-2023-38185 - remote code execution flaws in Exchange Server - the first two of which have been tagged with an "Exploitation More Likely" assessment.
Microsoft further acknowledged the availability of a proof-of-concept exploit for a DoS vulnerability in.
Lastly, the update also includes patches for five privilege escalation flaws in the Windows Kernel that could be weaponized by a threat actor with local access to the target machine to gain SYSTEM privileges.
News URL
https://thehackernews.com/2023/08/microsoft-releases-patches-for-74-new.html
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-08-08 | CVE-2023-38185 | Unspecified vulnerability in Microsoft Exchange Server 2016/2019 Microsoft Exchange Server Remote Code Execution Vulnerability | 8.8 |
2023-08-08 | CVE-2023-38182 | Unspecified vulnerability in Microsoft Exchange Server 2016/2019 Microsoft Exchange Server Remote Code Execution Vulnerability low complexity microsoft | 8.0 |
2023-08-08 | CVE-2023-35388 | Unspecified vulnerability in Microsoft Exchange Server 2016/2019 Microsoft Exchange Server Remote Code Execution Vulnerability low complexity microsoft | 8.0 |