First Patch Tuesday of the new year did not disappoint as Microsoft revealed 98 vulnerabilities of which 11 are critical, and 87 are important.

The good news is Microsoft said all critical vulnerabilities are either less likely or unlikely to be exploited, except for the bypass vulnerability CVE-2023-21743 on Microsoft SharePoint Server machines, according to a report with Cisco Talos. This vulnerability has a low complexity and can be easily triggered by an attacker. In a network-based attack, an unauthenticated user could make an anonymous connection to the targeted SharePoint server.

Two critical vulnerabilities, which Microsoft considers to be “less likely” to be exploited due to their complexity are CVE-2023-21535 and CVE-2023-21548, Talos researchers said.

These are remote code execution (RCE) vulnerabilities in the Windows Secure Socket Tunneling Protocol (SSTP) which allow an unauthenticated attacker to send a specially crafted connection request to a RAS server, which could lead to remote code execution (RCE) on the RAS server and run unauthorized commands on the compromised system.

There are also five critical Remote Code Execution vulnerabilities which affect the Windows Layer 2 Tunneling Protocol (L2TP), Talos said. Successful exploitation could allow an unauthenticated attacker to execute code on RAS servers. These five vulnerabilities are CVE-2023-21543, CVE-2023-21546, CVE-2023-21555, CVE-2023-21556 and CVE-2023-21679.

Schneider Bold

The last critical vulnerability is CVE-2023-21730, which is a Remote Code Execution Vulnerability in the Windows Cryptographic Services. Microsoft did not released many details about the vulnerability, except that it is triggered from the network and of low complexity, Talos said.

Talos would also like to highlight six important vulnerabilities Microsoft considers “more likely” to be exploited and can be used for privilege elevation:

  • CVE-2023-21532 Windows GDI Elevation of Privilege Vulnerability
  • CVE-2023-21541 Windows Task Scheduler Elevation of Privilege Vulnerability
  • CVE-2023-21552 Windows GDI Elevation of Privilege Vulnerability
  • CVE-2023-21725 Microsoft Windows Defender Elevation of Privilege Vulnerability
  • CVE-2023-21726 Windows Credential Manager User Interface Elevation of Privilege Vulnerability
  • CVE-2023-21768 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Click here for a complete list of the vulnerabilities.

ISSSource

Pin It on Pinterest

Share This