Microsoft’s October Patch Update Addresses 105 Vulnerabilities

In Microsoft’s regular patch day for October, the company has addressed a total of 105 vulnerabilities. Fortunately, only a few of these vulnerabilities are rated as critical according to the Common Vulnerability Scoring System (CVSS). This update includes fixes for various security issues in Microsoft’s software and services. Notably, several of the addressed vulnerabilities have been actively exploited by threat actors.

Exploited Vulnerabilities

The October update addresses several vulnerabilities that have already been exploited in the wild. These include:

HTTP2 Rapid Reset Bug (CVE-2023-44487): This vulnerability has been actively exploited and was recently reported in iTnews.

Wordpad Bug (CVE-2023-36563): This vulnerability could result in the exposure of user credentials. It’s notable that this bug affects other applications that use Wordpad functionality, such as Outlook and Word.

Skype for Business Privilege Escalation (CVE-2023-41763): This is another vulnerability that has been actively exploited. It allows for privilege escalation in Skype for Business.

Wordpad Vulnerability

The Wordpad bug stands out as particularly problematic due to two key issues:

It can expose user credentials when linked objects are present in OLESTREAM, and these functions authenticate to the server where the link source is located. If the OLESTREAM comes from an untrusted source, NTLM credentials may be disclosed to a remote malicious server.

The vulnerability is inherited by other applications using Wordpad functionality, including Outlook and Word.

Several of the vulnerabilities addressed in this update have CVSS scores exceeding 9.0, indicating critical severity. For example:

CVE-2023-36434: A privilege escalation issue in the Windows IIS server, though Microsoft deems exploitation unlikely due to it being a brute-force vulnerability that strong passwords should mitigate.

CVE-2023-35349 and CVE-2023-36697: These are remote code execution (RCE) vulnerabilities in Microsoft’s Message Queuing. While no specific details are provided for CVE-2023-35349, CVE-2023-36697 requires attackers to convince a user on the target machine to connect to a malicious server or compromise a legitimate MSMQ server host to run as a malicious server.

Microsoft’s October patch update is a significant effort to address multiple vulnerabilities in its software and services. The update also highlights the importance of prompt patching to mitigate security risks. Several of the vulnerabilities were already being exploited, underscoring the need for organizations and users to keep their systems up to date with the latest security updates and patches to protect against emerging threats.

Bibi Zuhra
Bibi Zuhra
Bibi Zuhra has a Master's degree in public administration and a Certificate in Entrepreneurship from Santa Rosa Junior college (California). Bibi has worked in research & marketing, and in policymaking, and also has more than four years of experience as an SEO Content Writer, and news articles for e-commerce, tourism, business, education, and lifestyle. she believe words have the power to change the world, and she try to do that through her work.

Similar Articles

Comments

Most Popular