Microsoft’s latest Patch Tuesday includes a set of 49 patches, two of which are being actively exploited in the wild. Both of these exploited vulnerabilities are sub-critical: CVE-2023-29336, a local privilege escalation vulnerability in the Win32k subsystem, and CVE-2023-24932, a secure boot bypass that would allow a local attacker with admin credentials to alter a system’s boot policy. Only two vulnerabilities have CVSS scores above 9, including CVE-2023-24943, a remote code execution vulnerability in the Windows pragmatic general multicast server, which can be triggered when the Windows Message Queuing service is running in a PGM Server environment. The other high-scoring vulnerability is CVE-2023-24941, a remote code execution vulnerability in the Windows network file system v4.1, which can be triggered by an unauthenticated, specially crafted call to a network file system service. Other vulnerabilities include an Outlook OLE vulnerability and bugs in SharePoint server, LDAP, and the Windows secure socket tunnelling protocol. Microsoft’s advisory has recommended replacing PGM with newer technologies and that users configure Outlook to only display text.


