zerofox logo
Advisories

Microsoft Patch Tuesday 11/10/2023 Notes

|by Alpha Team

banner image

Microsoft Patch Tuesday 10/11/2023 Notes

This advisory addresses and summarizes the vulnerabilities published by Microsoft this Patch Tuesday and highlights the most notable vulnerabilities that may impact our customers.

Recommendations

Keep up to date with the most recent vulnerabilities impacting you in our Vulnerabilities tab. Contact your account manager for more information. Be sure to apply patches promptly to mitigate these and other vulnerabilities.

Details

Highlights:

Microsoft's Patch Tuesday update for October 2023 contained 104 vulnerabilities, with:

  • 3 zero-day vulnerabilities
  • 12 vulnerabilities rated as Critical
  • 52 Vulnerabilities rated as High

(Microsoft defines a critical vulnerability as one whose exploitation could allow code execution without user interaction.)

Most notable vulnerabilities

This month’s patches include three actively exploited zero-day vulnerabilities(CVE-2023-44487 , CVE-2023-41763 and CVE-2023-36563). The most notable among them being CVE-2023-44487, which is not limited to Windows and stems from a World Wide Web HTTP/2 protocol that attackers have exploited to launch DDoS Attacks on a much more massive scale than through conventional means.

CVE-2023-44487

CVE-2023-44487 (CVSS score: 7.5) is a HTTP/2 Rapid Reset Attack exploit. The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. Microsoft, has stated that they have released both a patch, as well as a temporary workaround.

The following products are affected:

  • Windows Server 2016 (Server Core installation)
  • Windows Server 2016
  • Windows 10 Version 1607 for x64-based Systems
  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2019
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows 10 Version 1809 for 32-bit Systems
  • ASP.NET Core 7.0
  • Microsoft Visual Studio 2022 version 17.7
  • Microsoft Visual Studio 2022 version 17.6
  • Microsoft Visual Studio 2022 version 17.4
  • Microsoft Visual Studio 2022 version 17.2
  • .NET 7.0
  • ASP.NET Core 6.0
  • .NET 6.0

CVE-2023-41763

CVE-2023-41763 (CVSS score: 5.4) is a Skype for Business Elevation of Privilege Vulnerability. While it is at a lower threat score at 5.4, that is already being exploited in the wild, and allows an attacker to obtain critical information like IP address and ports which could be used to map further attacks.

The following product is affected:

  • Skype for Business Server 2019 CU7
  • Skype for Business Server 2015 CU13

CVE-2023-36563

CVE-2023-36563 (CVSS score: 6.5) is a Microsoft WordPad Information Disclosure Vulnerability. An attacker must be able to either access the system and run a specially crafted application or convince a user to access the specially crafted file. CISA has added the vulnerability to its Known Exploited Vulnerabilities Catalog and requested users to patch it before October 31, 2023.

The following products are affected:

  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
  • Windows Server 2008 for x64-based Systems Service Pack 2
  • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
  • Windows Server 2008 for 32-bit Systems Service Pack 2
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2016
  • Windows 10 Version 1607 for x64-based Systems
  • Windows Server 2019
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows 10 Version 1809 for 32-bit Systems
  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 for x64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

CVE-2023-36434

CVE-2023-36434 (CVSS score: 9.8) is CVE-2023-36434 is an Escalation of Privilege vulnerability in Windows IIS server. The attack is made possible through an attacker brute forcing login credentials. Since the chances of successful attack can vary and depend upon password complexity, it has been considered “High” rather than “Critical” despite the high CVSS score.

The following products are affected:

  • Windows 10 Version 1607 for x64-based Systems
  • Windows Server 2008 for x64-based Systems Service Pack 2
  • Windows 10 Version 1809 for 32-bit Systems
  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows Server 2019
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows Server 2022
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows Server 2022 (Server Core installation)
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 for x64-based Systems
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2012
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2019 (Server Core installation)
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows Server 2016
  • Windows Server 2008 for 32-bit Systems Service Pack 2
  • Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Users are advised to apply the latest security patches specified in Microsoft's October 2023 Patch Tuesday update and follow the mitigations and workarounds to best protect themselves from the risks of these and other vulnerabilities.

Tags: DIB, tlp:green