iTnews Asia
  • Home
  • News
  • Security

Microsoft patches 94 vulnerabilities

Microsoft patches 94 vulnerabilities

Patch Tuesday comes around.

By Richard Chirgwin on Jun 14, 2023 11:52AM

Microsoft has addressed 94 vulnerabilities in this month’s Patch Tuesday, but just four rate greater than nine (9) on the Common Vulnerability Scoring System and none are flagged as under exploitation.

Windows Pragmatic General Multicast (PGM) is subject to three critical vulnerabilities: CVE-2023-32015, CVE-2023-32014, and CVE-2023-29363.

All three offer remote code execution, Microsoft’s advisories explain; all have a vulnerability score of 9.8.

“When Windows message queuing service is running in a PGM Server environment, an attacker could send a specially crafted file over the network to achieve remote code execution and attempt to trigger malicious code," it wrote.

The other top-rated bug is CVE-2023-29357, a SharePoint vulnerability that gives a successful attacker administrator privileges.

“An attacker who has gained access to spoofed JWT authentication tokens can use them to execute a network attack which bypasses authentication and allows them to gain access to the privileges of an authenticated user,” Microsoft wrote.

“The attacker needs no privileges, nor does the user need to perform any action.”

According to the SANS Institute, there are two Microsoft Exchange patches that warrant attention, even though they rate lower than critical.

“Exploitation requires authentication, so these remote code execution vulnerabilities are only regarded as important. But based on history with similar flaws, this issue is worth watching,” the institute’s Johannes Ullrich said. 

CVE-2023-28310 allows an “authenticated attacker who is on the same intranet as the Exchange server can achieve remote code execution via a PowerShell remoting session”, while CVE-2023-32031 would let an authenticated user “attempt to trigger malicious code in the context of the server's account through a network call.”

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
microsoft patch tuesday security software

Related Articles

  • Malicious AI agents can severely disrupt APAC enterprises
  • A data-first AI strategy is critical to managing security threats in 2026
  • Malicious AI inputs are creating a new and critical security threat
  • AI governance must evolve alongside adoption in APAC
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Malicious AI agents can severely disrupt APAC enterprises

Malicious AI agents can severely disrupt APAC enterprises

A data-first AI strategy is critical to managing security threats in 2026

A data-first AI strategy is critical to managing security threats in 2026

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Rare earths mining companies targeted by social media campaign

Rare earths mining companies targeted by social media campaign

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.