Microsoft Patch Tuesday, November 2023 Edition
ID: 3acbb78d-aa2a-51ba-8dd8-adb962d6e442
STIX ID: report--3acbb78d-aa2a-51ba-8dd8-adb962d6e442
Feed Name: Krebs on Security
Microsoft released fixes for more than fifty vulnerabilities in Windows and related products, including three zero-day flaws actively exploited in the wild: a SmartScreen bypass (CVE-2023-36025), a DWM Core Library local privilege escalation to SYSTEM (CVE-2023-36033), and a Cloud Files Mini Filter Driver elevation (CVE-2023-36036). The bulletin also flags several Exchange vulnerabilities and other high-severity bugs disclosed prior to patches; organizations are urged to prioritize updates, back up systems, and hunt for related indicators such as .url attachments and suspicious process spawns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
