June 2023 Patch Tuesday: Critical patches for Microsoft Windows, SharePoint, Exchange
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-32031 +1 in the same advisory: …28310 | Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 group max | 81% |
| — | ||
| CVE-2023-29357 | Privilege Escalation via JWT Authentication Bypass in Microsoft SharePoint Server Microsoft SharePoint Server contains a privilege escalation flaw (CWE-303, incorrect implementation of an authentication algorithm) in which an attacker can forge (spoof) JSON Web Token (JWT) authentication tokens that the server accepts as valid. An unauthenticated remote attacker who presents such spoofed tokens bypasses authentication entirely and gains administrator privileges on the affected SharePoint deployment. Organizations running on-premises Microsoft SharePoint Server are affected, including both internet-facing and internally hosted servers. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. No public proof-of-concept is catalogued, but the KEV listing and perfect EPSS score make urgent patching critical. Do: Apply Microsoft's SharePoint Server security updates immediately (the fix shipped in Microsoft's March 2023 Patch Tuesday updates for supported SharePoint Server versions), consistent with the CISA KEV required action. Until patched, restrict internet exposure of SharePoint servers and review authentication logs for anomalous or spoofed-token activity, hunting for signs of compromise given known ransomware use. If mitigations are unavailable, CISA advises discontinuing use of the product. | 9.8 | 100% | KEV ransomware |
| largetens of thousands of internet-exposed SharePoint servers, with likely 100,000+ total on-prem deployments | |
| CVE-2023-32015 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2023-3079 | Type Confusion in Google Chromium V8 Engine Exploited in the Wild CVE-2023-3079 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine that powers Google Chromium, triggerable remotely when a user visits or is directed to a specially crafted HTML page. Successful exploitation causes heap corruption, which a remote attacker can leverage to execute code within the affected browser's renderer process. Every browser or application built on the Chromium engine is potentially affected, explicitly including Google Chrome, Microsoft Edge, and Opera. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-07 with a required action to apply vendor updates, and EPSS assigns a 32.1% probability of exploitation activity in the next 30 days (98th percentile). No public proof-of-concept code is known, but the KEV listing confirms real-world attacks, making rapid patching of all Chromium-based browsers a priority. Do: Immediately update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers (including Chromium-embedded applications) to the latest vendor release, per the CISA KEV required action to apply updates per vendor instructions; confirm the update applied via the browser's About/Settings page. As a stopgap where patching is delayed, restrict browsing to trusted sites or disable JavaScript where feasible, since exploitation requires the renderer to process a crafted HTML page. | 8.8 | 32% | KEV PoC |
| mass3+ billion users (Chrome's global install base alone; Chromium-based Edge and Opera add hundreds of millions more) |
Full article514 words · extracted from helpnetsecurity.com · click to collapse
For June 2023 Patch Tuesday, Microsoft has delivered 70 new patches but, for once, none of the fixed vulnerabilities are currently exploited by attackers nor were publicly known before today!

Microsoft has previously fixed CVE-2023-3079, a type confusion vulnerability in Chromium’s V8 JavaScript engine, which was spotted being exploited by attackers to target Chrome users. Since Microsoft’s Edge browser is based on Chromium’ open-source codebase, Microsoft pushed out a patch on June 6, and the accompanying advisory is out today.
Vulnerabilities of note
Dustin Childs, head of threat awareness at Trend Micro Inc.’s Zero Day Initiative, has singled out CVE-2023-29357, a critical elevation of privilege (EoP) vulnerability in Microsoft SharePoint Server 2019, as deserving express patching.
“This bug was one of the bugs chained together during the Pwn2Own Vancouver contest held back in March. This particular bug was used to bypass authentication due to a flaw within the ValidateTokenIssuer method,” he noted.
Jason Kikta, CIO/CISO at Automox, explained further: “An attacker who gains access to spoofed JWT authentication tokens can then use them to execute a network attack, which bypasses authentication and allows them to gain access to the privileges of an authenticated user. The attacker needs no privileges nor does the user need to perform any action.”
Exfiltration of sensitive information is a priority for both criminal and state espionage actors. Therefore, mass exploitation against public-facing SharePoint instances in the near future is likely. Further, an actor is likely to exploit this vulnerability shortly after gaining access to a given internal corporate system, which reduces the potential response time before data is stolen. On-prem customers who have enabled the AMSI feature are protected from this vulnerability, but all others should patch within 24 hours to avoid exploitation.”
Three distinct vulnerabilities (CVE-2023-29363, CVE-2023-32014, CVE-2023-32015) affecting the Windows Pragmatic General Multicast (PGM) protocol installed with the message queuing (MSMQ) service could allow a remote, unauthenticated attacker to execute code on an affected system and should be also patched quickly.
“While not enabled by default, PGM isn’t an uncommon configuration. Let’s hope these bugs get fixed before any active exploitation starts,” Childs pointed out.
Then there’s CVE-2023-32031 – a RCE in Microsoft Exchange Server (2016 and 2109).
The attacker must be authenticated to exploit it, but if that requirement is fulfilled, the attacker could attempt to trigger malicious code in the context of the server’s account through a network call.
“With low attack complexity and privileges and no user interaction required, we recommend patching this one and CVE-2023-28310 within 24 hours to avoid exploitation,” Kitka advised.
“Both flaws are rated as important but are considered more likely to be exploited compared to some of the other vulnerabilities patched this month,” Satnam Narang, senior staff research engineer at Tenable, told Help Net Security.
“Unlike past Microsoft Exchange Server flaws that were rated higher and did not require authentication, these vulnerabilities require an attacker to be authenticated. That said, attackers can still potentially exploit these flaws if they’re able to obtain valid credentials, which is not as difficult as you’d expect.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/06/13/june-2023-patch-tuesday/