Microsoft Patch Tuesday, August 2023 Edition
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-21709 | Microsoft Exchange Server Elevation of Privilege Vulnerability Microsoft Exchange Server Elevation of Privilege Vulnerability NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2023-36884 | Race Condition RCE in Microsoft Windows Search CVE-2023-36884 is a race condition (TOCTOU) vulnerability in Microsoft Windows Search that permits remote code execution, rated 7.5 (high) on CVSS 3.1. It is triggered over the network with user interaction — for example, when a user opens or interacts with a specially crafted document that causes the vulnerable search code path to race, allowing arbitrary code execution in the context of the current user. An attacker gains code execution on the victim's Windows system, which the RomCom threat actor chained with Firefox flaws to deploy backdoors against political targets, and CISA notes known ransomware use. Virtually every supported Windows client and server release at the time is affected, spanning Windows 10 1507 through 22H2, Windows 11 21H2/22H2, and Windows Server 2008 through 2022. The flaw was actively exploited as a zero-day before being fixed in the July 2023 Patch Tuesday; it was added to the CISA KEV catalog on 2023-07-17 and carries a 98.9% EPSS score (100th percentile). Do: Apply the July 2023 Patch Tuesday Windows security updates to all Windows 10, Windows 11, and Windows Server systems, prioritizing high-value and frequently attacked endpoints since the bug was exploited as a zero-day by RomCom and carries a KEV deadline (US civilian agencies were directed to remediate by August 1, 2023). Because exploitation requires user interaction, caution users against opening untrusted documents, and verify patch status via your patch management or vulnerability scanner against the KEV requirement. If patching is not possible, follow vendor mitigations per CISA's required action or discontinue use. | 7.5 | 99% | KEV ransomware |
| mass≈1 billion+ Windows devices (Windows 10/11 installed base) plus the enterprise Windows Server estate | |
| CVE-2023-36910 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2023-38180 | Unauthenticated DoS in Microsoft .NET, ASP.NET Core and Visual Studio 2022 CVE-2023-38180 is a denial-of-service vulnerability in Microsoft .NET and Visual Studio 2022 caused by uncontrolled resource consumption (CWE-400). Per the CVSS vector, a remote, unauthenticated attacker can trigger it over the network with no privileges or user interaction required, causing affected applications or services to exhaust resources and become unavailable. The attacker gains only availability impact (high availability severity, no confidentiality or integrity impact), but this can take down ASP.NET Core web applications and other .NET-based services. Any organization running vulnerable .NET runtimes, ASP.NET Core applications, or Visual Studio 2022 is exposed, and Fedora also ships affected .NET packages. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-08-09, it was among the two actively exploited flaws fixed in Microsoft's August 2023 Patch Tuesday, and EPSS assigns a 14.0% 30-day exploitation probability (96th percentile). Do: Apply the August 2023 Microsoft security updates for all affected .NET, ASP.NET Core, and Visual Studio 2022 versions listed in Microsoft's advisory, and install the updated .NET packages on Fedora; because this flaw is in CISA's KEV catalog, the required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. After updating, rebuild or restart .NET applications so they run on the patched runtime, and monitor internet-facing .NET services for signs of resource-exhaustion denial-of-service. No public proof-of-concept is known, but active exploitation has been reported, so patching should be treated as urgent. | 7.5 | 14% | KEV |
| masshundreds of millions of potential installations (ubiquity of the .NET runtime and ASP.NET Core in server and web deployments) |
Full article575 words · extracted from krebsonsecurity.com · click to collapse
Microsoft Corp. today issued software updates to plug more than 70 security holes in its Windows operating systems and related products, including multiple zero-day vulnerabilities currently being exploited in the wild.

Six of the flaws fixed today earned Microsoft’s “critical” rating, meaning malware or miscreants could use them to install software on a vulnerable Windows system without any help from users.
Last month, Microsoft acknowledged a series of zero-day vulnerabilities in a variety of Microsoft products that were discovered and exploited in-the-wild attacks. They were assigned a single placeholder designation of CVE-2023-36884.
Satnam Narang, senior staff research engineer at Tenable, said the August patch batch addresses CVE-2023-36884, which involves bypassing the Windows Search Security feature.
“Microsoft also released ADV230003, a defense-in-depth update designed to stop the attack chain associated that leads to the exploitation of this CVE,” Narang said. “Given that this has already been successfully exploited in the wild as a zero-day, organizations should prioritize patching this vulnerability and applying the defense-in-depth update as soon as possible.”
Redmond patched another flaw that is already seeing active attacks — CVE-2023-38180 — a weakness in .NET and Visual Studio that leads to a denial-of-service condition on vulnerable servers.
“Although the attacker would need to be on the same network as the target system, this vulnerability does not require the attacker to have acquired user privileges,” on the target system, wrote Nikolas Cemerikic, cyber security engineer at Immersive Labs.
Narang said the software giant also patched six vulnerabilities in Microsoft Exchange Server, including CVE-2023-21709, an elevation of privilege flaw that was assigned a CVSSv3 (threat) score of 9.8 out of a possible 10, even though Microsoft rates it as an important flaw, not critical.
“An unauthenticated attacker could exploit this vulnerability by conducting a brute-force attack against valid user accounts,” Narang said. “Despite the high rating, the belief is that brute-force attacks won’t be successful against accounts with strong passwords. However, if weak passwords are in use, this would make brute-force attempts more successful. The remaining five vulnerabilities range from a spoofing flaw and multiple remote code execution bugs, though the most severe of the bunch also require credentials for a valid account.”
Experts at security firm Automox called attention to CVE-2023-36910, a remote code execution bug in the Microsoft Message Queuing service that can be exploited remotely and without privileges to execute code on vulnerable Windows 10, 11 and Server 2008-2022 systems. Microsoft says it considers this vulnerability “less likely” to be exploited, and Automox says while the message queuing service is not enabled by default in Windows and is less common today, any device with it enabled is at critical risk.
Separately, Adobe has issued a critical security update for Acrobat and Reader that resolves at least 30 security vulnerabilities in those products. Adobe said it is not aware of any exploits in the wild targeting these flaws. The company also issued security updates for Adobe Commerce and Adobe Dimension.
If you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a fair chance other readers have experienced the same and may chime in here with useful tips.
Additional reading:
-SANS Internet Storm Center listing of each Microsoft vulnerability patched today, indexed by severity and affected component.
–AskWoody.com, which keeps tabs on any developing problems related to the availability or installation of these updates.
Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2023/08/microsoft-patch-tuesday-august-2023-edition/