
Microsoft patched 34 CVEs in its December 2023 Patch Tuesday release, zero day fix for AMD, four rated critical and 29 rated as important. This does not include 8 Microsoft Edge flaws fixed on December 7th.
A separate advisory from AMD is available with more information on the vulnerability.
While eight remote code execution bugs were fixed, Microsoft only rated three as critical. In total, there were four critical vulnerabilities, with one in Power Platform (Spoofing), two in Internet Connection Sharing (RCE), and one in Windows MSHTML Platform (RCE).
AMD Leaks
CVE-2023-20588 AMD Speculative Leaks’ vulnerability is a division-by-zero bug in specific AMD processors that could potentially return sensitive data. The flaw was disclosed in August 2023, with AMD not providing any fixes other than recommending the following mitigation.
For affected products, AMD recommends following software development best practices. Developers can mitigate this issue by ensuring that no privileged data is used in division operations prior to changing privilege boundaries. AMD believes that the potential impact of this vulnerability is low because it requires local access.
Microsoft Power Platform Connector Spoofing Vulnerability
CVE-2023-36019 is a spoofing vulnerability in the Microsoft Power Platform Connector. It was assigned a CVSSv3 score of 9.6 and is rated “Exploitation Less Likely”. This vulnerability relates to custom connectors, specifically the per-connector redirect URI. Microsoft says that an attacker could exploit this vulnerability to spoof a legitimate link or file to direct a victim to a malicious link or application.
This vulnerability has been mitigated as of November 17, as Microsoft has required that any new custom connectors using OAuth 2.0 authentication will be assigned a per-connector redirect URI automatically. However, existing connectors will need to be updated to use per-connector redirect URIs before February 17th, 2024.
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
CVE-2023-35641 and CVE-2023-35630 are RCE vulnerabilities affecting the Internet Connection Sharing service in Windows, a service that allows an internet connected device to share its connection with other devices on a local area network. Both vulnerabilities were assigned CVSSv3 scores of 8.8 and rated as critical.
Exploitation of CVE-2023-35641, which Microsoft rated as “Exploitation More Likely,” can be achieved by sending a specially crafted DHCP message to a server running the ICS service. Exploitation of CVE-2023-35630, which Microsoft rated as “Exploitation Less Likely,” requires an attacker to modify the length field in a DHCPv6 message.
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2023-36696 is an EoP vulnerability in the Microsoft Windows Cloud Files Mini Filter Driver (cldflt.sys). It was assigned a CVSSv3 score of 7.8 and is rated as important and “Exploitation More Likely.” An attacker could exploit this vulnerability as part of post-compromise activity to elevate privileges to SYSTEM.
This flaw was reported to Microsoft by security researcher Rancho Ice. This is Ice’s second EoP vulnerability in the Cloud Files Mini Filter Driver disclosed to Microsoft in 2023 and is the sixth EoP vulnerability in the Cloud Files Mini Filter Driver disclosed in 2023 and the eight in the last two years.
Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2023-35628 is a RCE vulnerability affecting the Windows MSHTML platform. The vulnerability was assigned a CVSSv3 score of 8.1 and is rated as “Exploitation More Likely.” An attacker could exploit this vulnerability by sending a specifically crafted email which will automatically be processed when it is retrieved by Microsoft Outlook. Exploitation occurs before the email is viewed in the Preview Pane. While this is a critical vulnerability, Microsoft does note that successful exploitation would require the attacker to use “complex memory shaping techniques,” which may limit the successful use of this vulnerability to very skilled attackers.
Patch Tuesday Summary
| CVE ID | CVE Title | Severity |
| CVE-2023-36019 | Microsoft Power Platform Connector Spoofing Vulnerability | Critical |
| CVE-2023-35630 | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | Critical |
| CVE-2023-35641 | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | Critical |
| CVE-2023-35628 | Windows MSHTML Platform Remote Code Execution Vulnerability | Critical |
| CVE-2023-35624 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | Important |
| CVE-2023-35625 | Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability | Important |
| CVE-2023-20588 | AMD: CVE-2023-20588 AMD Speculative Leaks Security Notice | Important |
| CVE-2023-35634 | Windows Bluetooth Driver Remote Code Execution Vulnerability | Important |
| CVE-2023-35621 | Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability | Important |
| CVE-2023-36020 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important |
| CVE-2023-35636 | Microsoft Outlook Information Disclosure Vulnerability | Important |
| CVE-2023-35619 | Microsoft Outlook for Mac Spoofing Vulnerability | Important |
| CVE-2023-36009 | Microsoft Word Information Disclosure Vulnerability | Important |
| CVE-2023-36006 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important |
| CVE-2023-35622 | Windows DNS Spoofing Vulnerability | Important |
| CVE-2023-36696 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important |
| CVE-2023-36010 | Microsoft Defender Denial of Service Vulnerability | Important |
| CVE-2023-35643 | DHCP Server Service Information Disclosure Vulnerability | Important |
| CVE-2023-35638 | DHCP Server Service Denial of Service Vulnerability | Important |
| CVE-2023-36012 | DHCP Server Service Information Disclosure Vulnerability | Important |
| CVE-2023-36004 | Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability | Important |
| CVE-2023-35642 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | Important |
| CVE-2023-35632 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| CVE-2023-35633 | Windows Kernel Elevation of Privilege Vulnerability | Important |
| CVE-2023-35635 | Windows Kernel Denial of Service Vulnerability | Important |
| CVE-2023-35644 | Windows Sysmain Service Elevation of Privilege | Important |
| CVE-2023-36391 | Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | Important |
| CVE-2023-21740 | Windows Media Remote Code Execution Vulnerability | Important |
| CVE-2023-35639 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important |
| CVE-2023-36005 | Windows Telephony Server Elevation of Privilege Vulnerability | Important |
| CVE-2023-35629 | Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability | Important |
| CVE-2023-36011 | Win32k Elevation of Privilege Vulnerability | Important |
| CVE-2023-35631 | Win32k Elevation of Privilege Vulnerability | Important |
| CVE-2023-36003 | XAML Diagnostics Elevation of Privilege Vulnerability | Important |
| CVE-2023-36880 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Low |
| CVE-2023-38174 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Low |
| CVE-2023-35618 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Moderate |
| CVE-2023-6509 | Chromium: CVE-2023-6509 Use after free in Side Panel Search | Unknown |
| CVE-2023-6512 | Chromium: CVE-2023-6512 Inappropriate implementation in Web Browser UI | Unknown |
| CVE-2023-6508 | Chromium: CVE-2023-6508 Use after free in Media Stream | Unknown |
| CVE-2023-6511 | Chromium: CVE-2023-6511 Inappropriate implementation in Autofill | Unknown |
| CVE-2023-6510 | Chromium: CVE-2023-6510 Use after free in Media Capture | Unknown |


