Microsoft Patch Tuesday Fixes 11 Critical Vulnerabilities, One Zero-Day

Microsoft’s first Patch Tuesday of 2023 addresses 98 vulnerabilities, more than twice as many as last month – including one zero-day flaw that’s being actively exploited, as well as 11 critical flaws. The zero-day, CVE-2023-21674, is a Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerability with a CVSS score of 8.8. The flaw, […]

執筆者
Jeff Goldman
Jeff Goldman
Jan 11, 2023
3 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Microsoft’s first Patch Tuesday of 2023 addresses 98 vulnerabilities, more than twice as many as last month – including one zero-day flaw that’s being actively exploited, as well as 11 critical flaws.

The zero-day, CVE-2023-21674, is a Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerability with a CVSS score of 8.8. The flaw, uncovered by Avast researchers, could provide an attacker with system privileges.

“Bugs of this type are often [used] to deliver malware or ransomware,” Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, noted in a blog post. “Considering this was reported to Microsoft by researchers from Avast, that scenario seems likely here.”

Critical Flaws in Exchange and SharePoint

Saeed Abbasi, manager of vulnerability and threat research at Qualys, also highlighted two critical vulnerabilities in Microsoft SharePoint Server and Exchange Server.

“Both SharePoint and Exchange are critical tools that many organizations use to collaborate and complete daily tasks – making these vulnerabilities extremely attractive in the eyes of an attacker,” Abbasi said by email.

The first is a Microsoft Exchange Server elevation of privilege vulnerability, identified as CVE-2023-21763 and CVE-2023-21764, which could provide an attacker with system privileges.

The second, CVE-2023-21743, impacts Microsoft SharePoint Server. An unauthenticated, remote attacker, Abbasi said, “could exploit this vulnerability to establish an anonymous connection to the SharePoint server, bypassing security measures.”

“…people who scream ‘Just patch it!’ show they have never actually had to patch an enterprise in the real world”

-Dustin Childs, Trend Micro

In this case, Childs noted, sysadmins need to take an extra step to protect themselves. “To fully resolve this bug, you must also trigger a SharePoint upgrade action that’s also included in this update,” he wrote. “Full details on how to do this are in the bulletin.”

“Situations like this are why people who scream ‘Just patch it!’ show they have never actually had to patch an enterprise in the real world,” Childs added.

Advertisement

Also read: Is the Answer to Vulnerabilities Patch Management as a Service?

Other Key Flaws

In a recent blog post, Mike Walters, vice president of vulnerability and threat research at Action1, highlighted CVE-2023-21726, a Windows Credential Manager flaw with a CVSS score of 7.8 that Microsoft says is likely to be exploited in the wild. “It has low complexity, uses the local vector, and requires low privileges and no user interaction,” he wrote.

Another flaw, CVE-2023-21549, in the Windows SMB Witness Service, is an elevation of privilege vulnerability with a CVSS score of 8.8. “To exploit this vulnerability, an attacker can run a specially crafted malicious script that executes a Remote Procedure Call (RPC) call to an RPC host running the SMB Witness service,” Walters wrote.

Walters also noted that nine Windows Kernel vulnerabilities were patched – eight elevation of privilege flaws, and one information disclosure flaw. “The potential risk from these vulnerabilities is high since they affect all devices that run any Windows OS, starting from Windows 7,” he wrote.

Read next: MITRE ResilienCyCon: You Will Be Breached So Be Ready

Jeff Goldman

eSecurity Planet contributor Jeff Goldman has been a technology journalist for more than 20 years and an eSecurity Planet writer since 2009. He's also written extensively about wireless and broadband infrastructure and semiconductor engineering. He started his career at MTV, but soon decided that technology writing was a more promising path.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。