logo

Microsoft April 2023 Patch Tuesday Highlights: everything you need to know

ID: 9862ee2c-7b84-5b84-b1dd-61157970384d

STIX ID: report--9862ee2c-7b84-5b84-b1dd-61157970384d

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2023-04-13

Date Updated: 2026-05-01

...
...

Microsoft’s April Patch Tuesday fixes include two notable vulnerabilities: CVE-2023-21554 (critical unauthenticated RCE in MSMQ, aka QueueJumper) and CVE-2023-28252 (CLFS elevation-of-privilege exploited in the wild to deploy Nokoyawa ransomware). Researchers observed active exploitation of the CLFS bug with associated IoCs (file artifacts, hashes, and C2 domains); many cloud environments remained unpatched shortly after release. Recommended actions are to apply the April KBs, disable MSMQ or block TCP/1801 if unable to patch, and hunt for the provided IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.