zerofox logo
Advisories

Microsoft Patch Tuesday 06/14/2023 Notes

|by Alpha Team

banner image

Microsoft Patch Tuesday 06/14/2023 Notes

This advisory addresses and summarizes the vulnerabilities published by Microsoft this Patch Tuesday and highlights the most notable vulnerabilities that may impact our customers.

Recommendations

Keep up to date with the most recent vulnerabilities impacting you in our Vulnerabilities tab. Contact your account manager for more information. Be sure to apply patches promptly to mitigate these and other vulnerabilities.

Details

Highlights:

Microsoft's Patch Tuesday update for June 2023 contained 100 vulnerabilities, with:

  • 4 vulnerabilities rated as Critical
  • 38 remote code execution (RCE) vulnerabilities
  • 0 zero-day vulnerabilities

This batch of updates also includes fixes for 8 Remote Code Execution Vulnerabilities found in Visual Studio. (Microsoft defines a critical vulnerability as one whose exploitation could allow code execution without user interaction.)

Most notable vulnerabilities

This month’s Patch Tuesday cumulative Windows update is notable for not containing any actively exploited zero-day vulnerabilities, with March 2022 being the last such instance. However, there are still critical vulnerabilities that are either actively exploited or present a significant security risk. Microsoft has reported that CVE-2023-29357 (an Elevation of Privilege vulnerability) is under active exploitation, but has not provided further details.

Three different vulnerabilities (CVE-2023-29363, CVE-2023-32014, and CVE-2023-32015) present in the Windows Pragmatic General Multicast (PGM) protocol installed with the message queuing (MSMQ) service could allow a remote, unauthenticated attacker to execute code on an affected system and should be patched immediately.

CVE-2023-32031

CVE-2023-32031 (CVSS score: 8.8) is a security bypass vulnerability impacting Microsoft Exchange Server 2016 and 2019. Exploiting this vulnerability allows attackers to target exchange server accounts, potentially leading to arbitrary or remote code execution and unauthorized access.

The following products are affected:

  • Microsoft Exchange Server 2019 Cumulative Update 13
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 12

CVE-2023-29363

CVE-2023-29363 (CVSS score: 9.8) is one of three distinct critical remote code execution vulnerabilities, along with CVE-2023-32015 and CVE-2023-32014, targeting the Windows message queuing service. It requires the Message Queuing service to be running and TCP port 1801 actively listening on the target device.

The following products are affected:

  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
  • Windows Server 2008 for x64-based Systems Service Pack 2
  • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
  • Windows Server 2008 for 32-bit Systems Service Pack 2
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2016
  • Windows 10 Version 1607 for x64-based Systems
  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 for x64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2019
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows 10 Version 1809 for 32-bit Systems

CVE-2023-24897

CVE-2023-24897 (CVSS score: 7.8) is an Arbitrary Code Execution vulnerability affecting .NET and Visual Studio. The attack occurs within a compromised network or by manipulating someone through social engineering to execute the malicious code via compromised links.

The following products are affected:

  • Microsoft .NET Framework 3.5 AND 4.8
  • Microsoft .NET Framework 4.8
  • Microsoft .NET Framework 3.5 and 4.6.2
  • Microsoft .NET Framework 4.6.2
  • Microsoft .NET Framework 3.5 AND 4.8.1
  • Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2
  • Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2
  • Microsoft .NET Framework 3.5 AND 4.7.2
  • Microsoft Visual Studio 2022 version 17.6
  • .NET 6.0
  • .NET 7.0
  • Microsoft Visual Studio 2015 Update 3
  • Microsoft Visual Studio 2013 Update 5
  • Microsoft Visual Studio 2022 version 17.4
  • Microsoft Visual Studio 2022 version 17.0
  • Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
  • Microsoft Visual Studio 2022 version 17.2
  • Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)

CVE-2023-29362

CVE-2023-29362 (CVSS score: 9.8) is an RCE affecting the Remote Desktop Client program in Windows operating systems. It can be exploited by a remote, unauthenticated attacker with control over a Remote Desktop Server, when a user connects to a compromised Server using a vulnerable client.

The following products are affected:

  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2016
  • Windows 10 Version 1607 for x64-based Systems
  • Windows 10 for x64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2022
  • Remote Desktop client for Windows Desktop
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2019
  • Windows 10 Version 1809 for x64-based Systems

CVE-2023-29357

CVE-2023-29357 (CVSS score: 9.8) is an Elevation of Privilege vulnerability affecting Sharepoint Server. It allows an attacker to gain full admin rights without requiring any privileges or user interaction. By manipulating a JSON web token, the attacker can exploit this vulnerability. It is important to note that if you have AMSI integration and utilize Windows Defender, you are not susceptible to this risk

The following products are affected:

  • Microsoft SharePoint Server 2019

Users are advised to apply the latest security patches specified in Microsoft's June 2023 Patch Tuesday update and follow the mitigations and workarounds to best protect themselves from the risks of these and other vulnerabilities.

Tags: vulnerability/exploit,  technology,  all industries,  global