Microsoft has released its August 2023 Patch Tuesday security updates to fix multiple vulnerabilities across its products, including two reported vulnerabilities that are currently being exploited in the wild. 

Based on the official release notes from Microsoft, there are a total of 74 Microsoft CVEs and 12 non-Microsoft CVEs.

_____________________________

A. List of the Vulnerabilities

Microsoft CVEs

CVE TitleCVEBase ScoreExploitability
Microsoft OfficeADV230003 Exploitation Detected
Memory Integrity System Readiness Scan ToolADV230004 Exploitation Detected
Microsoft Exchange ServerCVE-2023-217099.8Exploitation Less Likely
Microsoft TeamsCVE-2023-293288.8Exploitation Less Likely
Microsoft TeamsCVE-2023-293308.8Exploitation Less Likely
Windows KernelCVE-2023-353597.8Exploitation More Likely
Microsoft Exchange ServerCVE-2023-353688.8Exploitation Less Likely
Microsoft Office ExcelCVE-2023-353717.8Exploitation Less Likely
Microsoft Office VisioCVE-2023-353727.8Exploitation Less Likely
Windows Message QueuingCVE-2023-353766.5Exploitation Less Likely
Windows Message QueuingCVE-2023-353776.5Exploitation Less Likely
Windows Projected File SystemCVE-2023-353787Exploitation Less Likely
Windows Reliability Analysis Metrics Calculation EngineCVE-2023-353797.8Exploitation Less Likely
Windows KernelCVE-2023-353807.8Exploitation More Likely
Windows Fax and Scan ServiceCVE-2023-353818.8Exploitation Less Likely
Windows KernelCVE-2023-353827.8Exploitation More Likely
Windows Message QueuingCVE-2023-353837.5Exploitation Less Likely
Windows HTML PlatformCVE-2023-353845.4Exploitation More Likely
Windows Message QueuingCVE-2023-353859.8Exploitation Less Likely
Windows KernelCVE-2023-353867.8Exploitation More Likely
Windows Bluetooth A2DP driverCVE-2023-353878.8Exploitation Less Likely
Microsoft Exchange ServerCVE-2023-353888Exploitation More Likely
Microsoft DynamicsCVE-2023-353896.5Exploitation Less Likely
.NET CoreCVE-2023-353907.8Exploitation Less Likely
ASP.NET and Visual StudioCVE-2023-353917.1Exploitation Less Likely
Azure HDInsightsCVE-2023-353934.5Exploitation Less Likely
Azure HDInsightsCVE-2023-353944.6Exploitation Less Likely
Microsoft Office VisioCVE-2023-368657.8Exploitation Less Likely
Microsoft Office VisioCVE-2023-368667.8Exploitation Less Likely
Azure DevOpsCVE-2023-368696.3Exploitation Less Likely
.NET FrameworkCVE-2023-368737.4Exploitation Less Likely
Reliability Analysis Metrics Calculation EngineCVE-2023-368767.1Exploitation Less Likely
Azure HDInsightsCVE-2023-368774.5Exploitation Less Likely
Azure HDInsightsCVE-2023-368814.5Exploitation Less Likely
Microsoft WDAC OLE DB provider for SQLCVE-2023-368828.8Exploitation Less Likely
Windows Group PolicyCVE-2023-368895.5Exploitation Less Likely
Microsoft Office SharePointCVE-2023-368906.5Exploitation Less Likely
Microsoft Office SharePointCVE-2023-368918Exploitation Less Likely
Microsoft Office SharePointCVE-2023-368928Exploitation Less Likely
Microsoft Office OutlookCVE-2023-368936.5Exploitation Less Likely
Microsoft Office SharePointCVE-2023-368946.5Exploitation Less Likely
Microsoft Office OutlookCVE-2023-368957.8Exploitation Less Likely
Microsoft Office ExcelCVE-2023-368967.8Exploitation Less Likely
Microsoft OfficeCVE-2023-368978.1Exploitation Less Likely
Tablet Windows User InterfaceCVE-2023-368987.8Exploitation Less Likely
ASP.NETCVE-2023-368997.5Exploitation Less Likely
Windows Common Log File System DriverCVE-2023-369007.8Exploitation More Likely
Windows System Assessment ToolCVE-2023-369037.8Exploitation Less Likely
Windows Cloud Files Mini Filter DriverCVE-2023-369047.8Exploitation Less Likely
Windows Wireless Wide Area Network ServiceCVE-2023-369055.5Exploitation Less Likely
Windows Cryptographic ServicesCVE-2023-369065.5Exploitation Less Likely
Windows Cryptographic ServicesCVE-2023-369075.5Exploitation Less Likely
Role: Windows Hyper-VCVE-2023-369085.7Exploitation Less Likely
Windows Message QueuingCVE-2023-369096.5Exploitation Less Likely
Windows Message QueuingCVE-2023-369109.8Exploitation Less Likely
Windows Message QueuingCVE-2023-369119.8Exploitation Less Likely
Windows Message QueuingCVE-2023-369127.5Exploitation Less Likely
Windows Message QueuingCVE-2023-369136.5Exploitation Less Likely
Windows Smart CardCVE-2023-369145.5Exploitation Less Likely
Windows KernelCVE-2023-381547.8Exploitation Unlikely
Microsoft Edge (Chromium-based)CVE-2023-381576.5Exploitation Less Likely
Dynamics Business Central ControlCVE-2023-381677.2Exploitation Less Likely
SQL ServerCVE-2023-381698.8Exploitation Less Likely
Microsoft Windows Codecs LibraryCVE-2023-381707.8Exploitation Less Likely
Windows Message QueuingCVE-2023-381727.5Exploitation Less Likely
Windows DefenderCVE-2023-381757.8Exploitation Less Likely
Azure ArcCVE-2023-381767Exploitation Less Likely
.NET CoreCVE-2023-381787.5Exploitation Less Likely
ASP .NETCVE-2023-381807.5Exploitation More Likely
Microsoft Exchange ServerCVE-2023-381818.8Exploitation Less Likely
Microsoft Exchange ServerCVE-2023-381828Exploitation More Likely
Windows LDAP – Lightweight Directory Access ProtocolCVE-2023-381847.5Exploitation Less Likely
Microsoft Exchange ServerCVE-2023-381858.8Exploitation Less Likely
Windows Mobile Device ManagementCVE-2023-381867.8Exploitation Less Likely
Azure HDInsightsCVE-2023-381884.5Exploitation Less Likely
Windows Message QueuingCVE-2023-382546.5Exploitation Less Likely

Non-Microsoft CVEs

CNATagCVE
Advanced Micro Devices Inc.Microsoft WindowsCVE-2023-20569
ChromeMicrosoft Edge (Chromium-based)CVE-2023-4068
ChromeMicrosoft Edge (Chromium-based)CVE-2023-4069
ChromeMicrosoft Edge (Chromium-based)CVE-2023-4070
ChromeMicrosoft Edge (Chromium-based)CVE-2023-4071
ChromeMicrosoft Edge (Chromium-based)CVE-2023-4072
ChromeMicrosoft Edge (Chromium-based)CVE-2023-4073
ChromeMicrosoft Edge (Chromium-based)CVE-2023-4074
ChromeMicrosoft Edge (Chromium-based)CVE-2023-4075
ChromeMicrosoft Edge (Chromium-based)CVE-2023-4076
ChromeMicrosoft Edge (Chromium-based)CVE-2023-4077
ChromeMicrosoft Edge (Chromium-based)CVE-2023-4078

B. Actions to be taken

CERT-PH recommends the following actions be taken:

  • Kindly review and apply the necessary updates to mitigate future threats.
  • For additional information, kindly refer to the official report
    • https://msrc.microsoft.com/update-guide/releaseNote/2023-Aug
    • https://msrc.microsoft.com/update-guide/vulnerability