Microsoft Patch Tuesday for May 2023 fixed 2 zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-24943 +1 in the same advisory: …24932 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 group max | 5% |
| — | ||
| CVE-2023-24941 | Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 95% |
| — | ||
| CVE-2023-24955 | Authenticated Code Injection RCE in Microsoft SharePoint Server (Actively Exploited) CVE-2023-24955 is a code injection vulnerability (CWE-94) in on-premises Microsoft SharePoint Server that enables remote code execution over the network (CVSS 3.1: 7.2, AV:N/AC:L/PR:H/UI:N). Exploitation requires authentication with high privileges — e.g., a SharePoint site administrator account — and no user interaction, so an attacker who has obtained elevated site credentials can send crafted requests that execute code on the SharePoint server. A successful attacker gains code execution in the context of the SharePoint service, with high impact on confidentiality, integrity, and availability, providing a foothold for lateral movement or ransomware deployment. Organizations running affected on-premises SharePoint Server releases are affected; the flaw was demonstrated at Pwn2Own and Microsoft patched it in the May 2023 Patch Tuesday updates. The bug is now exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-03-26 with known ransomware use, and EPSS places its 30-day exploitation probability at 85.4% (100th percentile). Do: Apply Microsoft's May 2023 (or later) security updates for SharePoint Server immediately, prioritizing internet-facing servers; CISA's KEV entry requires federal agencies to apply vendor mitigations or discontinue use of the product. Audit and tighten accounts holding SharePoint site-administrator rights, and hunt for signs of exploitation such as unexpected site-admin activity or unusual process launches from SharePoint service accounts. Public reporting on the 2024 exploitation suggests it may be chained with SharePoint privilege-escalation flaw CVE-2023-29357 to achieve unauthenticated access, so ensure both flaws are patched. | 7.2 | 85% | KEV ransomware |
| large≈ tens of thousands of on-premises SharePoint servers (10k–100k exposed systems) | |
| CVE-2023-29336 | Use-after-free privilege escalation to SYSTEM in Microsoft Win32k CVE-2023-29336 is a use-after-free flaw (CWE-416) in Microsoft's Win32k kernel component that allows privilege escalation to SYSTEM. It is triggered by code running on a Windows host that causes the Win32k driver to reference freed kernel memory; the exact trigger path is not detailed in the available data, but as a kernel elevation-of-privilege issue it requires local code execution or an attacker already holding a foothold on the machine. A successful exploit grants SYSTEM privileges, giving the attacker full control of the compromised host. Because Win32k ships in every supported Windows client and server, effectively the entire Windows installed base is exposed to the flaw. The vulnerability is confirmed exploited in the wild — CISA added it to the KEV catalog on 2023-05-09 — and EPSS places its 30-day exploitation probability at 40.9% (99th percentile), though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Apply Microsoft's current cumulative Windows security updates (issued May 2023, per the CISA KEV required action) across all Windows clients and servers, prioritizing servers and systems exposed to untrusted users since the flaw is being actively exploited. Until patched, limit untrusted local code execution and restrict remote entry points such as RDP, because local privilege escalation flaws are commonly chained into full compromises. Verify update installation after deployment; specific affected build numbers and any ransomware involvement are not stated in the available data. | 7.8 | 41% | KEV PoC |
| mass≈1 billion+ Windows devices (Win32k ships in every supported Windows client and server) |
Full article412 words · extracted from securityaffairs.com · click to collapse

Microsoft Patch Tuesday Security updates for May 2023 address a total of 40 vulnerabilities, including two zero-day actively exploited in attacks.
Microsoft’s May 2023 security updates address 40 vulnerabilities, including two zero-day flaws actively exploited in attacks. The flaws affect Microsoft Windows and Windows Components; Office and Office Components; Microsoft Edge (Chromium-based); SharePoint Server; Visual Studio; SysInternals; and Microsoft Teams.
Seven of the addressed vulnerabilities are rated Critical and 31 are rated Important in severity.
The two actively exploited zero-day vulnerabilities addressed with the relaese of Patch Tuesday Security updates for May 2023 are:
CVE-2023-29336 (CVSS 7.8) – Win32k Elevation of Privilege Vulnerability. This vulnerability is actively exploited in attacks. The flaw can be chained with a code execution bug to spread malware. The vulnerability was reported by researchers Jan Vojtěšek, Milánek, and Luigino Camastra from Avast Antivirus firm, a circumstance that suggests it was used as part of an exploit chain to deliver malware.
“An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.” reads the advisory.
CVE-2023-24932 (CVSS 6.7) – Secure Boot Security Feature Bypass Vulnerability. An attacker with physical access or Administrative rights to a target device could install an affected boot policy and bypass Secure Boot. The flaw was reported by Martin Smolar from ESET and Tomer Sne-or from SentinelOne.
Threat actors were spotted exploiting this flaw to install the BlackLotus UEFI bootkit.
“To exploit the vulnerability, an attacker who has physical access or Administrative rights to a target device could install an affected boot policy,” reads Microsoft’s advisory.
The most severe vulnerabilities addressed by Microsoft are:
- CVE-2023-24941 (CVSS 9.8) – Windows Network File System Remote Code Execution Vulnerability.
- CVE-2023-24943 (CVSS 9.8) – Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability.
Microsoft also addressed a remote code execution flaw in SharePoint Server, tracked as CVE-2023-24955, that was demonstrated by the Star Labs team at the Pwn2Own Vancouver 2023 exploit contest. The flaw was part of an exploit chain used to obtain code execution on the target server.
We are in the final!
Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections where is reported Securityaffairs or my name Pierluigi Paganini
Please nominate Security Affairs as your favorite blog.
Nominate Pierluigi Paganini and Security Affairs here here: https://docs.google.com/forms/d/e/1FAIpQLSepvnj8b7QzMdLh7vWEDQDqohjBUsHyn3x3xRdYGCetwVy2DA/viewform
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Microsoft)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/146007/security/microsoft-patch-tuesday-may-2023.html