Microsoft has released its May 2023 Patch Tuesday security updates to fix multiple vulnerabilities across its products, including two reported vulnerabilities (CVE-2023-24932 and CVE-2023-29336) that are currently being exploited in the wild. 

Based on the official release notes from Microsoft, there are a total of 49 vulnerabilities. Of these vulnerabilities, six are classified as critical, 33 are classified as important, one is classified as moderate, and nine are classified as none.

_____________________________

A. List of Vulnerabilities

ProductDetailsImpactSeverity
Microsoft SharePoint Server Subscription EditionCVE-2023-24950SpoofingImportant
Windows 10 Version 22H2 for 32-bit SystemsCVE-2023-24949Elevation of PrivilegeImportant
Windows Server 2016 (Server Core installation)CVE-2023-24947Remote Code ExecutionImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-24903Remote Code ExecutionCritical
Microsoft Office LTSC for Mac 2021CVE-2023-29344Remote Code ExecutionImportant
Windows SysmonCVE-2023-29343Elevation of PrivilegeImportant
AV1 Video ExtensionCVE-2023-29341Remote Code ExecutionImportant
AV1 Video ExtensionCVE-2023-29340Remote Code ExecutionImportant
Visual Studio CodeCVE-2023-29338Information DisclosureImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-29336Elevation of PrivilegeImportant
Microsoft Word 2013 Service Pack 1 (64-bit editions)CVE-2023-29335Security Feature BypassImportant
Microsoft Office LTSC 2021 for 32-bit editionsCVE-2023-29333Denial of ServiceImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-29325Remote Code ExecutionCritical
Windows Server 2012 R2 (Server Core installation)CVE-2023-29324Security Feature BypassImportant
Microsoft SharePoint Server Subscription EditionCVE-2023-24955Remote Code ExecutionCritical
Microsoft SharePoint Server Subscription EditionCVE-2023-24954Information DisclosureImportant
Microsoft Excel 2013 Service Pack 1 (64-bit editions)CVE-2023-24953Remote Code ExecutionImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-24948Elevation of PrivilegeImportant
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)CVE-2023-24946Elevation of PrivilegeImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-24945Information DisclosureImportant
Windows 10 Version 22H2 for 32-bit SystemsCVE-2023-24944Information DisclosureImportant
Windows 10 Version 22H2 for 32-bit SystemsCVE-2023-24905Remote Code ExecutionImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-24943Remote Code ExecutionCritical
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)CVE-2023-24904Elevation of PrivilegeImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-24942Denial of ServiceImportant
Windows 11 Version 22H2 for x64-based SystemsCVE-2023-24902Elevation of PrivilegeImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-24941Remote Code ExecutionCritical
Windows Server 2012 R2 (Server Core installation)CVE-2023-24901Information DisclosureImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-24940Denial of ServiceImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-24900Information DisclosureImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-24939Denial of ServiceImportant
Windows 11 Version 22H2 for x64-based SystemsCVE-2023-24899Elevation of PrivilegeImportant
Windows Server 2022 (Server Core installation)CVE-2023-24898Denial of ServiceImportant
Microsoft Remote DesktopCVE-2023-28290Information DisclosureImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-28283Remote Code ExecutionCritical
Windows Server 2012 R2 (Server Core installation)CVE-2023-28251Security Feature BypassImportant
Windows Server 2012 R2 (Server Core installation)CVE-2023-24932Security Feature BypassImportant
Microsoft TeamsCVE-2023-24881Information DisclosureImportant
Microsoft Edge (Chromium-based)CVE-2023-29354Security Feature BypassModerate
Microsoft Edge (Chromium-based)CVE-2023-29350Elevation of PrivilegeImportant
Microsoft Edge (Chromium-based)CVE-2023-2468
Microsoft Edge (Chromium-based)CVE-2023-2467
Microsoft Edge (Chromium-based)CVE-2023-2466
Microsoft Edge (Chromium-based)CVE-2023-2465
Microsoft Edge (Chromium-based)CVE-2023-2464
Microsoft Edge (Chromium-based)CVE-2023-2463
Microsoft Edge (Chromium-based)CVE-2023-2462
Microsoft Edge (Chromium-based)CVE-2023-2460
Microsoft Edge (Chromium-based)CVE-2023-2459

____________________________

B. Actions to be Taken

CERT-PH recommends the following actions be taken:

  • Kindly review and apply the necessary updates to mitigate future threats.
  • For additional information, kindly refer to the official report
    • https://msrc.microsoft.com/update-guide/releaseNote/2023-May
    • https://msrc.microsoft.com/update-guide/vulnerability