iTnews Asia
  • Home
  • News
  • Security

Microsoft patches 94 vulnerabilities

Microsoft patches 94 vulnerabilities

Patch Tuesday comes around.

By Richard Chirgwin on Jun 14, 2023 11:52AM

Microsoft has addressed 94 vulnerabilities in this month’s Patch Tuesday, but just four rate greater than nine (9) on the Common Vulnerability Scoring System and none are flagged as under exploitation.

Windows Pragmatic General Multicast (PGM) is subject to three critical vulnerabilities: CVE-2023-32015, CVE-2023-32014, and CVE-2023-29363.

All three offer remote code execution, Microsoft’s advisories explain; all have a vulnerability score of 9.8.

“When Windows message queuing service is running in a PGM Server environment, an attacker could send a specially crafted file over the network to achieve remote code execution and attempt to trigger malicious code," it wrote.

The other top-rated bug is CVE-2023-29357, a SharePoint vulnerability that gives a successful attacker administrator privileges.

“An attacker who has gained access to spoofed JWT authentication tokens can use them to execute a network attack which bypasses authentication and allows them to gain access to the privileges of an authenticated user,” Microsoft wrote.

“The attacker needs no privileges, nor does the user need to perform any action.”

According to the SANS Institute, there are two Microsoft Exchange patches that warrant attention, even though they rate lower than critical.

“Exploitation requires authentication, so these remote code execution vulnerabilities are only regarded as important. But based on history with similar flaws, this issue is worth watching,” the institute’s Johannes Ullrich said. 

CVE-2023-28310 allows an “authenticated attacker who is on the same intranet as the Exchange server can achieve remote code execution via a PowerShell remoting session”, while CVE-2023-32031 would let an authenticated user “attempt to trigger malicious code in the context of the server's account through a network call.”

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
microsoft patch tuesday security software

Related Articles

  • Your organisation’s physical security can be a gateway for cybercriminals
  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
  • Is identity now the next parameter of cybersecurity breaches?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

The best way to outsmart your threat actors is to think like one

The best way to outsmart your threat actors is to think like one

What are the most pressing cyber security concerns going into 2025?

What are the most pressing cyber security concerns going into 2025?

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

How cybercriminals are exploiting LLMs to harm your business

How cybercriminals are exploiting LLMs to harm your business

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.