Microsoft Patch Tuesday 06/14/2023 Notes
|by Alpha Team

Microsoft Patch Tuesday 06/14/2023 Notes
This advisory addresses and summarizes the vulnerabilities published by Microsoft this Patch Tuesday and highlights the most notable vulnerabilities that may impact our customers.
Recommendations
Keep up to date with the most recent vulnerabilities impacting you in our Vulnerabilities tab. Contact your account manager for more information. Be sure to apply patches promptly to mitigate these and other vulnerabilities.
Details
Highlights:
Microsoft's Patch Tuesday update for June 2023 contained 100 vulnerabilities, with:
- 4 vulnerabilities rated as Critical
- 38 remote code execution (RCE) vulnerabilities
- 0 zero-day vulnerabilities
This batch of updates also includes fixes for 8 Remote Code Execution Vulnerabilities found in Visual Studio. (Microsoft defines a critical vulnerability as one whose exploitation could allow code execution without user interaction.)
Most notable vulnerabilities
This month’s Patch Tuesday cumulative Windows update is notable for not containing any actively exploited zero-day vulnerabilities, with March 2022 being the last such instance. However, there are still critical vulnerabilities that are either actively exploited or present a significant security risk. Microsoft has reported that CVE-2023-29357 (an Elevation of Privilege vulnerability) is under active exploitation, but has not provided further details.
Three different vulnerabilities (CVE-2023-29363, CVE-2023-32014, and CVE-2023-32015) present in the Windows Pragmatic General Multicast (PGM) protocol installed with the message queuing (MSMQ) service could allow a remote, unauthenticated attacker to execute code on an affected system and should be patched immediately.
CVE-2023-32031
CVE-2023-32031 (CVSS score: 8.8) is a security bypass vulnerability impacting Microsoft Exchange Server 2016 and 2019. Exploiting this vulnerability allows attackers to target exchange server accounts, potentially leading to arbitrary or remote code execution and unauthorized access.
The following products are affected:
- Microsoft Exchange Server 2019 Cumulative Update 13
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 12
CVE-2023-29363
CVE-2023-29363 (CVSS score: 9.8) is one of three distinct critical remote code execution vulnerabilities, along with CVE-2023-32015 and CVE-2023-32014, targeting the Windows message queuing service. It requires the Message Queuing service to be running and TCP port 1801 actively listening on the target device.
The following products are affected:
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 (Server Core installation)
- Windows Server 2012
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2016 (Server Core installation)
- Windows Server 2016
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 Version 22H2 for 32-bit Systems
- Windows 10 Version 22H2 for ARM64-based Systems
- Windows 10 Version 22H2 for x64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022 (Server Core installation)
- Windows Server 2022
- Windows Server 2019 (Server Core installation)
- Windows Server 2019
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
CVE-2023-24897
CVE-2023-24897 (CVSS score: 7.8) is an Arbitrary Code Execution vulnerability affecting .NET and Visual Studio. The attack occurs within a compromised network or by manipulating someone through social engineering to execute the malicious code via compromised links.
The following products are affected:
- Microsoft .NET Framework 3.5 AND 4.8
- Microsoft .NET Framework 4.8
- Microsoft .NET Framework 3.5 and 4.6.2
- Microsoft .NET Framework 4.6.2
- Microsoft .NET Framework 3.5 AND 4.8.1
- Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2
- Microsoft .NET Framework 3.5 AND 4.7.2
- Microsoft Visual Studio 2022 version 17.6
- .NET 6.0
- .NET 7.0
- Microsoft Visual Studio 2015 Update 3
- Microsoft Visual Studio 2013 Update 5
- Microsoft Visual Studio 2022 version 17.4
- Microsoft Visual Studio 2022 version 17.0
- Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
- Microsoft Visual Studio 2022 version 17.2
- Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
CVE-2023-29362
CVE-2023-29362 (CVSS score: 9.8) is an RCE affecting the Remote Desktop Client program in Windows operating systems. It can be exploited by a remote, unauthenticated attacker with control over a Remote Desktop Server, when a user connects to a compromised Server using a vulnerable client.
The following products are affected:
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 (Server Core installation)
- Windows Server 2012
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2016 (Server Core installation)
- Windows Server 2016
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 for x64-based Systems
- Windows 10 Version 22H2 for x64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022 (Server Core installation)
- Windows Server 2022
- Remote Desktop client for Windows Desktop
- Windows Server 2019 (Server Core installation)
- Windows Server 2019
- Windows 10 Version 1809 for x64-based Systems
CVE-2023-29357
CVE-2023-29357 (CVSS score: 9.8) is an Elevation of Privilege vulnerability affecting Sharepoint Server. It allows an attacker to gain full admin rights without requiring any privileges or user interaction. By manipulating a JSON web token, the attacker can exploit this vulnerability. It is important to note that if you have AMSI integration and utilize Windows Defender, you are not susceptible to this risk
The following products are affected:
- Microsoft SharePoint Server 2019
Users are advised to apply the latest security patches specified in Microsoft's June 2023 Patch Tuesday update and follow the mitigations and workarounds to best protect themselves from the risks of these and other vulnerabilities.
Tags: vulnerability/exploit, technology, all industries, global