Microsoft Patch Tuesday – December 2023

Microsoft Patch Tuesday – December 2023


Microsoft patched 34 CVEs in its December 2023 Patch Tuesday release, zero day fix for AMD, four rated critical and 29 rated as important. This does not include 8 Microsoft Edge flaws fixed on December 7th.

A separate advisory from AMD is available with more information on the vulnerability.

While eight remote code execution bugs were fixed, Microsoft only rated three as critical. In total, there were four critical vulnerabilities, with one in Power Platform (Spoofing), two in Internet Connection Sharing (RCE), and one in Windows MSHTML Platform (RCE).

AMD Leaks

CVE-2023-20588 AMD Speculative Leaks’ vulnerability is a division-by-zero bug in specific AMD processors that could potentially return sensitive data. The flaw was disclosed in August 2023, with AMD not providing any fixes other than recommending the following mitigation.

For affected products, AMD recommends following software development best practices. Developers can mitigate this issue by ensuring that no privileged data is used in division operations prior to changing privilege boundaries. AMD believes that the potential impact of this vulnerability is low because it requires local access.

Advertisements

Microsoft Power Platform Connector Spoofing Vulnerability

CVE-2023-36019 is a spoofing vulnerability in the Microsoft Power Platform Connector. It was assigned a CVSSv3 score of 9.6 and is rated “Exploitation Less Likely”. This vulnerability relates to custom connectors, specifically the per-connector redirect URI. Microsoft says that an attacker could exploit this vulnerability to spoof a legitimate link or file to direct a victim to a malicious link or application.

This vulnerability has been mitigated as of November 17, as Microsoft has required that any new custom connectors using OAuth 2.0 authentication will be assigned a per-connector redirect URI automatically. However, existing connectors will need to be updated to use per-connector redirect URIs before February 17th, 2024.

Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

CVE-2023-35641 and CVE-2023-35630 are RCE vulnerabilities affecting the Internet Connection Sharing service in Windows, a service that allows an internet connected device to share its connection with other devices on a local area network. Both vulnerabilities were assigned CVSSv3 scores of 8.8 and rated as critical.

Exploitation of CVE-2023-35641, which Microsoft rated as “Exploitation More Likely,” can be achieved by sending a specially crafted DHCP message to a server running the ICS service. Exploitation of CVE-2023-35630, which Microsoft rated as “Exploitation Less Likely,” requires an attacker to modify the length field in a DHCPv6 message.

Advertisements

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-36696 is an EoP vulnerability in the Microsoft Windows Cloud Files Mini Filter Driver (cldflt.sys). It was assigned a CVSSv3 score of 7.8 and is rated as important and “Exploitation More Likely.” An attacker could exploit this vulnerability as part of post-compromise activity to elevate privileges to SYSTEM.

This flaw was reported to Microsoft by security researcher Rancho Ice. This is Ice’s second EoP vulnerability in the Cloud Files Mini Filter Driver disclosed to Microsoft in 2023 and is the sixth EoP vulnerability in the Cloud Files Mini Filter Driver disclosed in 2023 and the eight in the last two years.

Windows MSHTML Platform Remote Code Execution Vulnerability

CVE-2023-35628 is a RCE vulnerability affecting the Windows MSHTML platform. The vulnerability was assigned a CVSSv3 score of 8.1 and is rated as “Exploitation More Likely.” An attacker could exploit this vulnerability by sending a specifically crafted email which will automatically be processed when it is retrieved by Microsoft Outlook. Exploitation occurs before the email is viewed in the Preview Pane. While this is a critical vulnerability, Microsoft does note that successful exploitation would require the attacker to use “complex memory shaping techniques,” which may limit the successful use of this vulnerability to very skilled attackers.

Advertisements

Patch Tuesday Summary

CVE IDCVE TitleSeverity
CVE-2023-36019Microsoft Power Platform Connector Spoofing VulnerabilityCritical
CVE-2023-35630Internet Connection Sharing (ICS) Remote Code Execution VulnerabilityCritical
CVE-2023-35641Internet Connection Sharing (ICS) Remote Code Execution VulnerabilityCritical
CVE-2023-35628Windows MSHTML Platform Remote Code Execution VulnerabilityCritical
CVE-2023-35624Azure Connected Machine Agent Elevation of Privilege VulnerabilityImportant
CVE-2023-35625Azure Machine Learning Compute Instance for SDK Users Information Disclosure VulnerabilityImportant
CVE-2023-20588AMD: CVE-2023-20588 AMD Speculative Leaks Security NoticeImportant
CVE-2023-35634Windows Bluetooth Driver Remote Code Execution VulnerabilityImportant
CVE-2023-35621Microsoft Dynamics 365 Finance and Operations Denial of Service VulnerabilityImportant
CVE-2023-36020Microsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityImportant
CVE-2023-35636Microsoft Outlook Information Disclosure VulnerabilityImportant
CVE-2023-35619Microsoft Outlook for Mac Spoofing VulnerabilityImportant
CVE-2023-36009Microsoft Word Information Disclosure VulnerabilityImportant
CVE-2023-36006Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution VulnerabilityImportant
CVE-2023-35622Windows DNS Spoofing VulnerabilityImportant
CVE-2023-36696Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityImportant
CVE-2023-36010Microsoft Defender Denial of Service VulnerabilityImportant
CVE-2023-35643DHCP Server Service Information Disclosure VulnerabilityImportant
CVE-2023-35638DHCP Server Service Denial of Service VulnerabilityImportant
CVE-2023-36012DHCP Server Service Information Disclosure VulnerabilityImportant
CVE-2023-36004Windows DPAPI (Data Protection Application Programming Interface) Spoofing VulnerabilityImportant
CVE-2023-35642Internet Connection Sharing (ICS) Denial of Service VulnerabilityImportant
CVE-2023-35632Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
CVE-2023-35633Windows Kernel Elevation of Privilege VulnerabilityImportant
CVE-2023-35635Windows Kernel Denial of Service VulnerabilityImportant
CVE-2023-35644Windows Sysmain Service Elevation of PrivilegeImportant
CVE-2023-36391Local Security Authority Subsystem Service Elevation of Privilege VulnerabilityImportant
CVE-2023-21740Windows Media Remote Code Execution VulnerabilityImportant
CVE-2023-35639Microsoft ODBC Driver Remote Code Execution VulnerabilityImportant
CVE-2023-36005Windows Telephony Server Elevation of Privilege VulnerabilityImportant
CVE-2023-35629Microsoft USBHUB 3.0 Device Driver Remote Code Execution VulnerabilityImportant
CVE-2023-36011Win32k Elevation of Privilege VulnerabilityImportant
CVE-2023-35631Win32k Elevation of Privilege VulnerabilityImportant
CVE-2023-36003XAML Diagnostics Elevation of Privilege VulnerabilityImportant
CVE-2023-36880Microsoft Edge (Chromium-based) Information Disclosure VulnerabilityLow
CVE-2023-38174Microsoft Edge (Chromium-based) Information Disclosure VulnerabilityLow
CVE-2023-35618Microsoft Edge (Chromium-based) Elevation of Privilege VulnerabilityModerate
CVE-2023-6509Chromium: CVE-2023-6509 Use after free in Side Panel SearchUnknown
CVE-2023-6512Chromium: CVE-2023-6512 Inappropriate implementation in Web Browser UIUnknown
CVE-2023-6508Chromium: CVE-2023-6508 Use after free in Media StreamUnknown
CVE-2023-6511Chromium: CVE-2023-6511 Inappropriate implementation in AutofillUnknown
CVE-2023-6510Chromium: CVE-2023-6510 Use after free in Media CaptureUnknown

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.