Security News > 2023 > November > Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws

Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws
2023-11-14 19:00

Today is Microsoft's November 2023 Patch Tuesday, which includes security updates for a total of 58 flaws and five zero-day vulnerabilities.

The total count of 58 flaws does not include 5 Mariner security updates and 20 Microsoft Edge security updates released earlier this month.

The flaw was discovered internally by the Microsoft Threat Intelligence Microsoft Security Response Center.

Microsoft has fixed an actively exploited and publicly disclosed Windows DWM Core Library vulnerability that can be used to elevate privileges to SYSTEM. "An attacker who successfully exploited this vulnerability could gain SYSTEM privileges," explains Microsoft.

Microsoft says that the flaw was discovered by Will Metcalf, Microsoft Threat Intelligence, and the Microsoft Office Product Group Security Team.

Microsoft says that two other publicly disclosed zero-day bugs, 'CVE-2023-36413 - Microsoft Office Security Feature Bypass Vulnerability' and the 'CVE-2023-36038 - ASP.NET Core Denial of Service Vulnerability,' were also fixed as part of today's Patch Tuesday.


News URL

https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2023-patch-tuesday-fixes-5-zero-days-58-flaws/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-36038 Unspecified vulnerability in Microsoft Asp.Net Core and Visual Studio 2022
ASP.NET Core Denial of Service Vulnerability
network
low complexity
microsoft
7.5
2023-11-14 CVE-2023-36413 Unspecified vulnerability in Microsoft products
Microsoft Office Security Feature Bypass Vulnerability
network
low complexity
microsoft
6.5

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 365 50 1369 2819 161 4399