Microsoft patches four exploited zero-days, but lags with fixes for a fifth (CVE-2023-36884)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-32049 | Windows SmartScreen Security Feature Bypass Exploited in the Wild (CVE-2023-32049) CVE-2023-32049 is a security feature bypass in Microsoft Windows Defender SmartScreen, the mechanism that warns users before they run downloaded or untrusted content; specially crafted content delivered over the network causes SmartScreen to skip that warning when a user opens it. The flaw requires user interaction (CVSS vector AV:N/AC:L/UI:R), so attackers must lure a victim into clicking or opening the crafted URL or file, and in exchange they gain the ability to run content without the expected SmartScreen prompt, typically as a link in a chain that delivers malware or establishes initial access. All users of Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2016/2019/2022 are affected. The flaw was fixed in Microsoft's July 2023 Patch Tuesday batch (132 vulnerabilities, six under active attack) and was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-11, confirming in-the-wild exploitation; no public proof-of-concept is known and ransomware use is unknown. Do: Apply Microsoft's July 2023 (or later) cumulative Windows security updates on every affected Windows 10, Windows 11, and Windows Server release, per the vendor instructions and CISA KEV required action. After patching, verify SmartScreen and Mark-of-the-Web warning behavior remain enabled and intact, and prioritize fleet-wide rollout given confirmed in-the-wild exploitation; treat unpatched users as susceptible to warning-free delivery of malicious files and links. | 8.8 group max | 4% | KEV |
| masshundreds of millions of endpoints and servers (the affected Windows 10/11 and Server releases make up the large majority of the supported Windows installed… | |
| CVE-2023-35311 | TOCTOU Security Feature Bypass in Microsoft Outlook (Exploited in the Wild) CVE-2023-35311 is a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) in Microsoft Outlook that allows a security feature to be bypassed. It is triggered remotely over the network when a user interacts with a specially crafted email; per Microsoft's advisory, the attacker needs to know the target's mailbox email address. Successful exploitation defeats Outlook's security check (scored high for confidentiality and integrity impact), lowering the barrier for follow-on actions such as malware delivery via email content. The flaw affects Outlook as delivered with Microsoft 365 Apps, Office, and Office LTSC. It is confirmed exploited in the wild (added to CISA KEV on 2023-07-11) and was fixed in Microsoft's July 2023 Patch Tuesday; no public proof-of-concept is known. Do: Apply the July 2023 Patch Tuesday security updates (released July 11, 2023) for Outlook, Office, Microsoft 365 Apps, and Office LTSC as soon as possible, since the flaw is being exploited in the wild and is on CISA's KEV list (U.S. civilian agency deadline August 1, 2023). After patching, verify Outlook and Office build numbers reflect the July 2023 updates, and review mailboxes for suspicious emails that users interacted with around the security prompt. Ransomware use is unknown, so treat any unpatched internet-active mail clients as priority targets in patch cycles. | 8.8 | 16% | KEV |
| masshundreds of millions of Outlook users worldwide |
Full article706 words · extracted from helpnetsecurity.com · click to collapse
For July 2023 Patch Tuesday, Microsoft has delivered 130 patches; among them are four for vulnerabilites actively exploited by attackers, but no patch for CVE-2023-36884, an Office and Windows HTML RCE vulnerability exploited in targeted attacks aimed at defense and government entities in Europe and North America.

About CVE-2023-36884
“Microsoft is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products. Microsoft is aware of targeted attacks that attempt to exploit these vulnerabilities by using specially-crafted Microsoft Office documents,” the company said in the advisory for that particular CVE-numbered vulnerability.
Reported by Microsoft, Google Threat Analysis Group, and Volexity researchers, CVE-2023-36884 has been abused via booby-trapped Microsoft Word documents ostensibly related to the Ukrainian World Congress.
“Storm-0978 (DEV-0978; also referred to as RomCom, the name of their backdoor, by other vendors) is a cybercriminal group based out of Russia, known to conduct opportunistic ransomware and extortion-only operations, as well as targeted credential-gathering campaigns likely in support of intelligence operations,” Microsoft Threat Intelligence has shared.
“Storm-0978 operates, develops, and distributes the RomCom backdoor. The actor also deploys the Underground ransomware, which is closely related to the Industrial Spy ransomware first observed in the wild in May 2022. The actor’s latest campaign detected in June 2023 involved abuse of CVE-2023-36884 to deliver a backdoor with similarities to RomCom.”
Previously, BlackBerry researchers shared their discovery of two malicious documents that seem to have been used by RomCom in those same campaigns.
The good news (for enterprise users and consumers) is that the attacks are highly targeted. The bad news is that Microsoft has yet to deliver patches for this issue.
Dustin Childs, head of threat awareness at Trend Micro Inc.’s Zero Day Initiative, says that though Microsoft considers this issue “Important”, admins would to well to treat it as “Critical”. Microsoft has advised on mitigations to reduce the risk of exploitation until the fixes are ready.
“Identified exploit activity includes abuse of CVE-2023-36884, including a remote code execution vulnerability exploited via Microsoft Word documents in June 2023, as well as abuse of vulnerabilities contributing to a security feature bypass,” Microsoft Threat Intelligence has noted.
(Might one of the security feature bypass vulnerabilities they are talking about be CVE-2023-32049, patches for which have been released today? Microsoft does not say.)
Other exploited vulnerabilities
CVE-2023-32049 is a vulnerability that allows attackers to bypass the Open File – Security Warning prompt. Flagged by Microsoft Threat Intelligence and the Microsoft Office Product Group security team, it requires user interaction to be exploited.
But it is nevertheless being exploited, and patching it should be a priority.
Microsoft has also patched:
- CVE-2023-35311, a vulnerability that is being used to bypass the Microsoft Outlook Security Notice prompt
- CVE-2023-36874, an elevation of privilege (EoP) flaw in the Windows Error Reporting Service, exploited to gain administrator privileges (exploitation reported by Google TAG researchers)
- CVE-2023-32046, an EoP vulnerability in the Windows MSHTML Platform that allowed attackers to gain the rights of the user that is running the affected application
Removing malicious signed drivers
“Microsoft also issued guidance regarding the malicious use of signed drivers through its Microsoft Windows Hardware Developer Program (MWHDP),” noted Satnam Narang, senior staff research engineer at Tenable.
“It was determined that certain Microsoft Partner Center developer accounts submitted malicious drivers to gain a Microsoft signature. The abuse of these signed drivers was discovered as part of post-exploitation activity, which required an attacker to gain administrative privileges on the targeted system first before running the malicious signed drivers.”
Microsoft says they launched an investigation in the matter when they were notified of this activity by Sophos on February 9, 2023, and that Trend Micro and Cisco released reports containing additional details.
“All the developer accounts involved in this incident were immediately suspended,” the company added. “Offline scans will be required to detect malicious drivers which might have been installed prior to March 2, 2023, when new Microsoft detections were implemented.”
The signed drivers seem to have been used in attacks targeting online gamers in China.
UPDATE (July 12, 2023, 06:25 a.m. ET):
Microsoft has also published details about an attack campaign by China-based hackers aimed at compromising government email accounts by exploiting a token validation issue.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/07/11/cve-2023-36884/