August 2023 Patch Tuesday: Microsoft fixes critical bugs in Teams, MSMQ
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-21709 | Microsoft Exchange Server Elevation of Privilege Vulnerability Microsoft Exchange Server Elevation of Privilege Vulnerability NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2023-29328 +1 in the same advisory: …29330 | Microsoft Teams Remote Code Execution Vulnerability Microsoft Teams Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2023-36884 | Race Condition RCE in Microsoft Windows Search CVE-2023-36884 is a race condition (TOCTOU) vulnerability in Microsoft Windows Search that permits remote code execution, rated 7.5 (high) on CVSS 3.1. It is triggered over the network with user interaction — for example, when a user opens or interacts with a specially crafted document that causes the vulnerable search code path to race, allowing arbitrary code execution in the context of the current user. An attacker gains code execution on the victim's Windows system, which the RomCom threat actor chained with Firefox flaws to deploy backdoors against political targets, and CISA notes known ransomware use. Virtually every supported Windows client and server release at the time is affected, spanning Windows 10 1507 through 22H2, Windows 11 21H2/22H2, and Windows Server 2008 through 2022. The flaw was actively exploited as a zero-day before being fixed in the July 2023 Patch Tuesday; it was added to the CISA KEV catalog on 2023-07-17 and carries a 98.9% EPSS score (100th percentile). Do: Apply the July 2023 Patch Tuesday Windows security updates to all Windows 10, Windows 11, and Windows Server systems, prioritizing high-value and frequently attacked endpoints since the bug was exploited as a zero-day by RomCom and carries a KEV deadline (US civilian agencies were directed to remediate by August 1, 2023). Because exploitation requires user interaction, caution users against opening untrusted documents, and verify patch status via your patch management or vulnerability scanner against the KEV requirement. If patching is not possible, follow vendor mitigations per CISA's required action or discontinue use. | 7.5 | 99% | KEV ransomware |
| mass≈1 billion+ Windows devices (Windows 10/11 installed base) plus the enterprise Windows Server estate | |
| CVE-2023-36895 | Microsoft Outlook Remote Code Execution Vulnerability Microsoft Outlook Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2023-38180 | Unauthenticated DoS in Microsoft .NET, ASP.NET Core and Visual Studio 2022 CVE-2023-38180 is a denial-of-service vulnerability in Microsoft .NET and Visual Studio 2022 caused by uncontrolled resource consumption (CWE-400). Per the CVSS vector, a remote, unauthenticated attacker can trigger it over the network with no privileges or user interaction required, causing affected applications or services to exhaust resources and become unavailable. The attacker gains only availability impact (high availability severity, no confidentiality or integrity impact), but this can take down ASP.NET Core web applications and other .NET-based services. Any organization running vulnerable .NET runtimes, ASP.NET Core applications, or Visual Studio 2022 is exposed, and Fedora also ships affected .NET packages. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-08-09, it was among the two actively exploited flaws fixed in Microsoft's August 2023 Patch Tuesday, and EPSS assigns a 14.0% 30-day exploitation probability (96th percentile). Do: Apply the August 2023 Microsoft security updates for all affected .NET, ASP.NET Core, and Visual Studio 2022 versions listed in Microsoft's advisory, and install the updated .NET packages on Fedora; because this flaw is in CISA's KEV catalog, the required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. After updating, rebuild or restart .NET applications so they run on the patched runtime, and monitor internet-facing .NET services for signs of resource-exhaustion denial-of-service. No public proof-of-concept is known, but active exploitation has been reported, so patching should be treated as urgent. | 7.5 | 14% | KEV |
| masshundreds of millions of potential installations (ubiquity of the .NET runtime and ASP.NET Core in server and web deployments) |
Full article521 words · extracted from helpnetsecurity.com · click to collapse
August 2023 Patch Tuesday is here; among the 76 CVE-numbered issues fixed by Microsoft this time around is a DoS vulnerability in .NET and Visual Studio (CVE-2023-38180) for which proof-of-exploit code exists.

Other than the fact that a patch is available, practically no other information has been shared by the company about CVE-2023-38180.
Vulnerabilities in Microsoft Office and Exchange Server
There is a Microsoft Office “Defense in Depth Update” available that, according to Microsoft, stops the attack chain leading to CVE-2023-36884, a Windows Search RCE vulnerability that has been previously exploited by Russian hackers in targeted attacks.
“Microsoft recommends installing the Office updates discussed in this advisory as well as installing the Windows updates from August 2023,” the company says. (Though, at the time of writing, the advisory for CVE-2023-36884 still points to the July cumulative Windows updates.)
Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, says that although it has been rated Important, CVE-2023-21709 – an elevation of privilege in Microsoft Exchange – should be considered Critical.
“This vulnerability allows a remote, unauthenticated attacker to log in as another user. In this case, you’re elevating from no permissions to being able to authenticate to the server, which makes all of those post-authentication exploits (…) viable,” he noted.
“To address CVE-2023-21709, administrators must perform additional actions and can run the CVE-2023-21709.ps1 script that we have released,” says the Microsoft Exchange team says.
“We have validated the script and CVE resolution on supported versions of Exchange Server only. We recommend updating to August [security updates] first and then running the script.”
Vulnerabilities in Microsoft Teams and Message Queuing
On this August 2023 Patch Tuesday, Childs also flagged CVE-2023-29328 and CVE-2023-29330, two flaws affecting Microsoft Teams that could be exploited by an attacker after they convince the victim to join a Microsoft Teams meeting.
Microsoft (naturally) doesn’t say how the bugs can be exploited, but says that they may allow an unprivileged attacker to perform remote code execution in the context of the victim user, access the victim’s information and alter it, and potentially cause downtime for the client machine.
Other critical vulnerabilities fixed this time around are three RCE flaws in Microsoft Message Queuing (MSMQ) and an Outlook RCE (CVE-2023-36895).
“There are 11 total bugs impacting Message Queuing getting fixed this month, and it’s clear that the research community is paying close attention to this service. While we haven’t detected active exploits targeting Message Queuing yet, it’s like just a matter of time as example PoCs exist. You can block TCP port 1801 as a mitigation, but the better choice is to test and deploy the update quickly,” Childs advised.
“While MSMQ is not enabled by default and is less common today, any device with it enabled is at critical risk,” noted Automox CISO Jason Kikta, and pointed users towards a Worklet that can help users check to see if the service is enabled and listening on TCP port 1801, stop the service and disable it from starting, and create an inbound firewall block rule for TCP port 1801 to prevent exploitation attacks over the network.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/08/08/august-2023-patch-tuesday/