Microsoft April 2023 Patch Tuesday Highlights: everything you need to know
ID: 9862ee2c-7b84-5b84-b1dd-61157970384d
STIX ID: report--9862ee2c-7b84-5b84-b1dd-61157970384d
Feed Name: Wiz Blog
Microsoft’s April Patch Tuesday fixes include two notable vulnerabilities: CVE-2023-21554 (critical unauthenticated RCE in MSMQ, aka QueueJumper) and CVE-2023-28252 (CLFS elevation-of-privilege exploited in the wild to deploy Nokoyawa ransomware). Researchers observed active exploitation of the CLFS bug with associated IoCs (file artifacts, hashes, and C2 domains); many cloud environments remained unpatched shortly after release. Recommended actions are to apply the April KBs, disable MSMQ or block TCP/1801 if unable to patch, and hunt for the provided IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
