ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft September 2023 Patch Tuesday fixed 2 actively exploited zero

criticalVulnerability exploited in the wildimportance 60CVE-2023-36802CVE-2023-36761

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-36761
Information Disclosure Flaw in Microsoft Word Actively Exploited (CVE-2023-36761)

CVE-2023-36761 is an information disclosure vulnerability in Microsoft Word caused by improper input validation (CWE-20). It is triggered when a user opens a specially crafted document, requiring user interaction but no authentication or special privileges, per the CVSS vector (AV:N/PR:N/UI:R). A successful attacker gains access to sensitive information from the affected system, with public reporting indicating the flaw can leak authentication material such as NTLM credentials. Anyone running affected versions of Word, including Word within Microsoft 365 Apps, Microsoft Office, and Office LTSC, is exposed, and the flaw was fixed in Microsoft's September 2023 Patch Tuesday updates. The vulnerability was exploited as a zero-day before patching: CISA added it to the Known Exploited Vulnerabilities catalog on September 12, 2023, and its EPSS score of 19.0% (97th percentile) signals elevated near-term exploitation risk.

Do: Apply Microsoft's September 2023 security updates for Microsoft 365 Apps, Office, Office LTSC, and Word immediately, per vendor instructions and CISA KEV requirements. Until patched, treat unsolicited documents as untrusted and consider restricting outbound SMB/NTLM traffic to limit credential leakage. Given confirmed in-the-wild exploitation and no known public PoC, prioritize this KEV remediation and verify patch deployment across endpoints.

6.520% KEV
  • Microsoft Word Supported versions per Microsoft's advisory; fixed in September 2023 security updates (no specific version ranges provided in source data)
  • Microsoft 365 Apps (Word component) Supported versions; fixed in September 2023 security updates
  • Microsoft Office Supported versions; fixed in September 2023 security updates
  • +1 more
masshundreds of millions of users/devices (Word ships with Microsoft 365 and Office across enterprise and consumer fleets)
CVE-2023-36802
Use-After-Free Privilege Escalation in Microsoft Streaming Service Proxy

CVE-2023-36802 is a use-after-free vulnerability (CWE-416) in the Microsoft Streaming Service Proxy, a component that ships with Windows, that allows an attacker to escalate privileges. It is triggered by a local attacker who can already execute code on a target machine and interacts with the streaming service proxy component in a way that mishandles freed memory. Successful exploitation typically yields elevated (SYSTEM/kernel-level) privileges, giving an attacker full control of the host and making it a common link in chained attack sequences alongside other exploits. Any Windows system carrying the affected component is potentially affected, which in practice means a very broad installed base of Windows client and server machines. The flaw is being actively exploited — CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-12 — though no public proof-of-concept is known and Microsoft's severity scoring was not yet available in the source data; EPSS estimates a high 27.5% chance of exploitation within 30 days (98th percentile).

Do: Apply Microsoft's security updates for this vulnerability via the vendor's mitigation instructions (Windows Update/patch channel), as required by the CISA KEV listing, prioritizing internet-reachable and multi-user Windows hosts. Since exploitation requires local access, limit who can run code on Windows systems and review endpoints for signs of local privilege escalation activity; confirm the patch landed by checking installed updates against Microsoft's advisory.

7.828% KEV
  • Microsoft Streaming Service Proxy
mass≈hundreds of millions of Windows devices (the Streaming Service Proxy component ships with Windows, so exposure broadly mirrors the Windows install base)
Full article195 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 13, 2023

Microsoft September 2023 Patch Tuesday addressed 59 new flaws, including two vulnerabilities under active attack.

Microsoft September 2023 Patch Tuesday security updates addressed 59 vulnerabilities, including two actively exploited zero-day.

The flaws addressed by the company impact Microsoft Windows and Windows Components; Exchange Server; Office and Office Components; .NET and Visual Studio; Azure; Microsoft Dynamics; and Windows Defender.

The company also addressed two external bugs and four Chromium bugs.

Five of the vulnerabilities fixed by the IT giant are rated Critical, 55 are rated Important, and one is rated Moderate in severity.

“Two of the CVEs released today are listed as being under active attack at the time of release while only one is listed as publicly known.” reported ZDI.

The two actively exploited zero-day vulnerabilities are:

  • CVE-2023-36802 – Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability – An attacker can trigger the vulnerability to gain SYSTEM privileges.
  • CVE-2023-36761 – Microsoft Word Information Disclosure Vulnerability – An attacker can exploit this vulnerability to lead the disclosure of NTLM hashes

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft September 2023 Patch Tuesday)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/150743/security/microsoft-september-2023-patch-tuesday.html