Microsoft Patch Tuesday 07/12/2023 Notes
|by Alpha Team

Microsoft Patch Tuesday 07/12/2023 Notes
This advisory addresses and summarizes the vulnerabilities published by Microsoft this Patch Tuesday and highlights the most notable vulnerabilities that may impact our customers.
Recommendations
Keep up to date with the most recent vulnerabilities impacting you in our Vulnerabilities tab. Contact your account manager for more information. Be sure to apply patches promptly to mitigate these and other vulnerabilities.
Details
Highlights:
Microsoft's Patch Tuesday update for July 2023 contained 131 vulnerabilities, with:
- 6 zero-day vulnerabilities
- 5 vulnerabilities rated as Critical
- 75 vulnerabilities rated as High
(Microsoft defines a critical vulnerability as one whose exploitation could allow code execution without user interaction.)
Most notable vulnerabilities
This month’s patches contain fixes for 5 Microsoft SharePoint Vulnerabilities and 3 Windows Remote Desktop Vulnerabilities. The bug tracked as CVE-2023-36884 is being exploited by threat actor group DEV-0978 (Storm-0978 / RomCom). Even though a patch has not been released for it yet, Microsoft has released mitigation guidance because of its severity and active exploitation.
**CVE-2023-33157 **
CVE-2023-33157 (CVSS score: 8.8) is a Microsoft SharePoint Remote Code Execution Vulnerability. Microsoft stated that it is more likely to be exploited.
The following products are affected:
- Microsoft SharePoint Server Subscription Edition
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Enterprise Server 2016
CVE-2023-35365
CVE-2023-35365 (CVSS score: 9.8) is a Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability. An attacker can send specially crafted packets to a server that has the Routing and Remote Access Service running to achieve RCE.
The following products are affected:
- Windows Server 2016 (Server Core installation)
- Windows Server 2016
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 Version 22H2 for 32-bit Systems
- Windows 10 Version 22H2 for ARM64-based Systems
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 (Server Core installation)
- Windows Server 2012
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows 10 Version 22H2 for x64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022 (Server Core installation)
- Windows Server 2022
- Windows Server 2019 (Server Core installation)
- Windows Server 2019
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
CVE-2023-29347
CVE-2023-29347 (CVSS score: 8.7) is a Windows Admin Center Spoofing Vulnerability. The vulnerability is located in the web server component of WAC, but the execution of malicious scripts occurs within the victim's browser. Remote, authenticated attackers have multiple avenues to exploit this vulnerability, including importing a malicious script into the WAC HTML form, importing a .csv file through the user interface, or utilizing the WAC API. Successful exploitation of this vulnerability grants the attacker the ability to perform operations on the WAC server using elevated privileges.
The following product is affected:
- Windows Admin Center
**CVE-2023-32057 **
CVE-2023-32057 (CVSS score: 9.8) is a Microsoft Message Queuing Remote Code Execution Vulnerability in the Microsoft Message Queuing (MSMQ) component of Windows operating systems. This vulnerability allows a remote unauthenticated attacker to execute arbitrary code by sending malicious MSMQ packets to a vulnerable MSMQ server. To successfully exploit this vulnerability, the Message Queuing service must be running on the affected server and listening on TCP port 1801.
The following products are affected:
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 (Server Core installation)
- Windows Server 2012
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows 10 Version 22H2 for 32-bit Systems
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2016 (Server Core installation)
- Windows Server 2016
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 Version 22H2 for ARM64-based Systems
- Windows 10 Version 22H2 for x64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022 (Server Core installation)
- Windows Server 2022
- Windows Server 2019 (Server Core installation)
- Windows Server 2019
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
**CVE-2023-32046 **
CVE-2023-32046 (CVSS score: 7.8) is a Windows MSHTML Platform Elevation of Privilege Vulnerability in Microsoft's MSHTML (Trident) engine, which was exploited as a zero-day in the wild. Patches are now available for all supported versions of Windows.
The following products are affected:
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 (Server Core installation)
- Windows Server 2012
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2016 (Server Core installation)
- Windows Server 2016
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 Version 22H2 for 32-bit Systems
- Windows 10 Version 22H2 for ARM64-based Systems
- Windows 10 Version 22H2 for x64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022 (Server Core installation)
- Windows Server 2022
- Windows Server 2019 (Server Core installation)
- Windows Server 2019
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
Users are advised to apply the latest security patches specified in Microsoft's July 2023 Patch Tuesday update and follow the mitigations and workarounds to best protect themselves from the risks of these and other vulnerabilities.
Tags: technology, all industries, global, vulnerability/exploit