iTnews Asia
  • Home
  • News
  • Security

Microsoft patches 94 vulnerabilities

Microsoft patches 94 vulnerabilities

Patch Tuesday comes around.

By Richard Chirgwin on Jun 14, 2023 11:52AM

Microsoft has addressed 94 vulnerabilities in this month’s Patch Tuesday, but just four rate greater than nine (9) on the Common Vulnerability Scoring System and none are flagged as under exploitation.

Windows Pragmatic General Multicast (PGM) is subject to three critical vulnerabilities: CVE-2023-32015, CVE-2023-32014, and CVE-2023-29363.

All three offer remote code execution, Microsoft’s advisories explain; all have a vulnerability score of 9.8.

“When Windows message queuing service is running in a PGM Server environment, an attacker could send a specially crafted file over the network to achieve remote code execution and attempt to trigger malicious code," it wrote.

The other top-rated bug is CVE-2023-29357, a SharePoint vulnerability that gives a successful attacker administrator privileges.

“An attacker who has gained access to spoofed JWT authentication tokens can use them to execute a network attack which bypasses authentication and allows them to gain access to the privileges of an authenticated user,” Microsoft wrote.

“The attacker needs no privileges, nor does the user need to perform any action.”

According to the SANS Institute, there are two Microsoft Exchange patches that warrant attention, even though they rate lower than critical.

“Exploitation requires authentication, so these remote code execution vulnerabilities are only regarded as important. But based on history with similar flaws, this issue is worth watching,” the institute’s Johannes Ullrich said. 

CVE-2023-28310 allows an “authenticated attacker who is on the same intranet as the Exchange server can achieve remote code execution via a PowerShell remoting session”, while CVE-2023-32031 would let an authenticated user “attempt to trigger malicious code in the context of the server's account through a network call.”

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
microsoft patch tuesday security software

Related Articles

  • Continuous defense is essential to mitigate growing supply chain risks
  • Half of firms that cut customer service staff due to AI will rehire by 2027
  • AI-as-a-Service emerges as a new operating model for enterprises
  • How severe will ransomware attacks become in 2026?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Tips on how to harness AI to transform your DDoS protection into proactive cyber defence

Tips on how to harness AI to transform your DDoS protection into proactive cyber defence

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

How severe will ransomware attacks become in 2026?

How severe will ransomware attacks become in 2026?

Malaysia's Maxis Berhad investigates claims on alleged data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.