Security News > 2023 > October > Microsoft October 2023 Patch Tuesday fixes 3 zero-days, 104 flaws

Microsoft October 2023 Patch Tuesday fixes 3 zero-days, 104 flaws
2023-10-10 17:49

Today is Microsoft's October 2023 Patch Tuesday, with security updates for 104 flaws, including three actively exploited zero-day vulnerabilities.

While forty-five remote code execution bugs were fixed, Microsoft only rated twelve vulnerabilities as 'Critical,' all of which are RCE flaws.

The total count of 104 flaws does not include one Chromium vulnerability tracked as CVE-2023-5346, which was fixed by Google on October 3rd and ported to Microsoft Edge.

This month's Patch Tuesday fixes three zero-day vulnerabilities, with all of them exploited in attacks and two of them publicly disclosed.

Microsoft has fixed an actively exploited vulnerability that can be used to steal NTLM hashes when opening a document in WordPad. "To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system," explains Microsoft.

Below is the complete list of resolved vulnerabilities in the October 2023 Patch Tuesday updates.


News URL

https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2023-patch-tuesday-fixes-3-zero-days-104-flaws/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-10-05 CVE-2023-5346 Type Confusion vulnerability in multiple products
Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject CWE-843
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 714 869 4793 4397 3718 13777