Site icon TheCyberThrone

Microsoft Patch Tuesday Review – Year 2023

Advertisements

Here is the summary of vulnerabilities released by microsoft month wise and severity wise. This didn’t includes the browser related vulnerabilities and vulnerabilities that released in previous years and updated in this year 2023

MonthsCriticalImportantModerateLowGrand Total
January1286  98
February771  78
March9691180
April890  98
May632  38
June5752183
July9122  131
August6683 77
September5551 61
October139211107
November455  59
December431  35
Grand Total8884683945
Advertisements

In addition to severity levels, Microsoft also categorizes vulnerabilities by seven impact levels: remote code execution (RCE), elevation of privilege (EoP), denial of service (DoS), information disclosure, spoofing, security feature bypass.

ImpactCriticalImportantModerateLowGrand Total
Remote Code Execution712781 350
Elevation of Privilege92281 238
Information Disclosure2115 1118
Denial of Service3104 2109
Spoofing1753 79
Security Feature Bypass2461 49
Defense in Depth  2 2
Grand Total8884683945
Advertisements

The peak month for Patch Tuesday in 2023 was July, when Microsoft patched 130+ CVEs. Only two months saw over 100 CVEs patched (July, October) while there were four months where Microsoft patched fewer than 60 CVEs (May, September, November, December).

MonthsVuln Count
January98
February79
March80
April98
May38
June83
July131
August77
September61
October107
November59
December34
Grand Total945
Advertisements

This section displays month wise vulnerabilities based on the impacts

MonthsRemote Code ExecutionElevation of PrivilegeInformation DisclosureDenial of ServiceSpoofingSecurity Feature BypassGrand Total
January333910102498
February40128107279
March272116410280
April45201096898
May128752438
June381851010283
July37331922713131
August231810813375
September2517935261
October4726121813107
November15167510659
December81065635
Grand Total3502381191097949945
Advertisements

The Patch Tuesday releases, has one of the important factors is the presence of zero-day vulnerabilities. Zero-day vulnerabilities are defined as vulnerabilities in software that have been exploited in the wild and/or have been publicly disclosed prior to patches becoming available.

Microsoft released patches for 23 zero-day vulnerabilities. Over half (52.2%) were EoP flaws. Security feature bypass vulnerabilities accounted for 26.1% of zero-days in 2023. These two categories combined for over three quarters (78.3%) of all zero-day vulnerabilities in 2023. While RCEs were the most prominent vulnerabilities across Patch Tuesday, they only accounted for 4.3% of zero-day flaws. The detailed analysis of these vulnerabilities will be done in the Zero day review post.

Looking back at Patch Tuesday for 2023, we see that the volume of CVEs patched were in-line with 2022 numbers and have remained far off from the peak in 2020. Despite the overall numbers, Patch Tuesday in 2023 was still eventful due to the presence of several zero-day flaws and a number of critical vulnerabilities across a variety of Microsoft products.

Exit mobile version