Patch Tuesday Archive
Patch Tuesday January 2023
Total CVEs
102
Critical
12
Important
88
Exploited
1
Publicly Disclosed
1
All CVEs this month 102
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2023-21540 | Windows Cryptographic Information Disclosure Vulnerability | Important | 5.5 |
Windows Cryptographic Services | - | - | - |
| CVE-2023-21552 | Windows GDI Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2023-21712 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Point-to-Point Tunneling Protocol | - | - | - |
| CVE-2023-21524 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Local Security Authority (LSA) | - | - | - |
| CVE-2023-21535 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Secure Socket Tunneling Protocol (SSTP) | - | - | - |
| CVE-2023-21531 | Azure Service Fabric Container Elevation of Privilege Vulnerability | Important | 7 |
Azure Service Fabric Container | - | - | - |
| CVE-2023-21538 | .NET Denial of Service Vulnerability | Important | 7.5 |
.NET Core | - | - | - |
| CVE-2023-21546 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-21547 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | Important | 7.5 |
Windows Internet Key Exchange (IKE) Protocol | - | - | - |
| CVE-2023-21539 | Windows Authentication Remote Code Execution Vulnerability | Important | 7.5 |
Windows Authentication Methods | - | - | - |
| CVE-2023-21541 | Windows Task Scheduler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Task Scheduler | - | - | - |
| CVE-2023-21542 | Windows Installer Elevation of Privilege Vulnerability | Important | 7 |
Windows Installer | - | - | - |
| CVE-2023-21543 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-21548 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Secure Socket Tunneling Protocol (SSTP) | - | - | - |
| CVE-2023-21549 | Windows SMB Witness Service Elevation of Privilege Vulnerability | Important | 8.8 |
Windows SMB | - | Yes | - |
| CVE-2023-21550 | Windows Cryptographic Information Disclosure Vulnerability | Important | 5.5 |
Windows Cryptographic Services | - | - | - |
| CVE-2023-21551 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Critical | 7.8 |
Windows Cryptographic Services | - | - | - |
| CVE-2023-21555 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-21556 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-21557 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | Important | 7.5 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2023-21558 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Error Reporting | - | - | - |
| CVE-2023-21559 | Windows Cryptographic Information Disclosure Vulnerability | Important | 5.5 |
Windows Cryptographic Services | - | - | - |
| CVE-2023-21560 | Windows Boot Manager Security Feature Bypass Vulnerability | Important | 6.6 |
Windows Boot Manager | - | - | - |
| CVE-2023-21561 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Critical | 7.8 |
Windows Cryptographic Services | - | - | - |
| CVE-2023-21563 | BitLocker Security Feature Bypass Vulnerability | Important | 6.8 |
Windows BitLocker | - | - | - |
| CVE-2023-21674 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Important | 8.8 |
Windows ALPC | Yes | - | - |
| CVE-2023-21676 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 8.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2023-21677 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Important | 7.5 |
Windows IKE Extension | - | - | - |
| CVE-2023-21678 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2023-21679 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-21680 | Windows Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2023-21681 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2023-21682 | Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability | Important | 5.3 |
Windows Point-to-Point Tunneling Protocol | - | - | - |
| CVE-2023-21683 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Important | 7.5 |
Windows IKE Extension | - | - | - |
| CVE-2023-21724 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2023-21725 | Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability | Important | 6.3 |
Windows Malicious Software Removal Tool | - | - | - |
| CVE-2023-21726 | Windows Credential Manager User Interface Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Credential Manager | - | - | - |
| CVE-2023-21728 | Windows Netlogon Denial of Service Vulnerability | Important | 7.5 |
Microsoft Local Security Authority Server (lsasrv) | - | - | - |
| CVE-2023-21730 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Critical | 7.8 |
Windows Cryptographic Services | - | - | - |
| CVE-2023-21732 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Windows ODBC Driver | - | - | - |
| CVE-2023-21733 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | Important | 7 |
Windows Bind Filter Driver | - | - | - |
| CVE-2023-21734 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2023-21735 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2023-21736 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2023-21737 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2023-21738 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2023-21739 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Bluetooth Driver | - | - | - |
| CVE-2023-21741 | Microsoft Office Visio Information Disclosure Vulnerability | Important | 7.1 |
Microsoft Office Visio | - | - | - |
| CVE-2023-21742 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-21743 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | Critical | 5.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-21744 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-21746 | Windows NTLM Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTLM | - | - | - |
| CVE-2023-21747 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Virtual Registry Provider | - | - | - |
| CVE-2023-21748 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Virtual Registry Provider | - | - | - |
| CVE-2023-21749 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Virtual Registry Provider | - | - | - |
| CVE-2023-21750 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.1 |
Windows Virtual Registry Provider | - | - | - |
| CVE-2023-21752 | Windows Backup Service Elevation of Privilege Vulnerability | Important | 7.1 |
Windows Backup Engine | - | - | - |
| CVE-2023-21753 | Event Tracing for Windows Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2023-21754 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Instrumentation | - | - | - |
| CVE-2023-21755 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-21757 | Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability | Important | 7.5 |
Windows Remote Access Service L2TP Driver | - | - | - |
| CVE-2023-21758 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Important | 7.5 |
Windows IKE Extension | - | - | - |
| CVE-2023-21759 | Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | Important | 3.3 |
Windows Smart Card | - | - | - |
| CVE-2023-21760 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.1 |
Windows Print Spooler Components | - | - | - |
| CVE-2023-21761 | Microsoft Exchange Server Information Disclosure Vulnerability | Important | 7.5 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-21762 | Microsoft Exchange Server Spoofing Vulnerability | Important | 8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-21763 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-21764 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-21765 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2023-21766 | Windows Overlay Filter Information Disclosure Vulnerability | Important | 4.7 |
Windows Overlay Filter | - | - | - |
| CVE-2023-21767 | Windows Overlay Filter Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Overlay Filter | - | - | - |
| CVE-2023-21768 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Ancillary Function Driver for WinSock | - | - | Yes |
| CVE-2023-21771 | Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability | Important | 7 |
Windows Local Session Manager (LSM) | - | - | - |
| CVE-2023-21772 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Virtual Registry Provider | - | - | - |
| CVE-2023-21773 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Virtual Registry Provider | - | - | - |
| CVE-2023-21774 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Virtual Registry Provider | - | - | - |
| CVE-2023-21776 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Virtual Registry Provider | - | - | - |
| CVE-2023-21781 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21782 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21784 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21786 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21791 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21793 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21796 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-21775 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Moderate | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-21795 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-21719 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Moderate | 6.5 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-21525 | Remote Procedure Call Runtime Denial of Service Vulnerability | Important | 5.3 |
Windows RPC API | - | - | - |
| CVE-2023-21527 | Windows iSCSI Service Denial of Service Vulnerability | Important | 7.5 |
Windows iSCSI | - | - | - |
| CVE-2023-21532 | Windows GDI Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Graphics Component | - | - | - |
| CVE-2023-21536 | Event Tracing for Windows Information Disclosure Vulnerability | Important | 4.7 |
Windows Event Tracing | - | - | - |
| CVE-2023-21537 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Message Queuing | - | - | - |
| CVE-2023-21675 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Virtual Registry Provider | - | - | - |
| CVE-2023-21745 | Microsoft Exchange Server Spoofing Vulnerability | Important | 8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-21779 | Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2023-21783 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21785 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21787 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21788 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21789 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21790 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21792 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 41 | 3 |
| Remote Code Execution | 34 | 8 |
| Denial of Service | 10 | - |
| Information Disclosure | 10 | - |
| Security Feature Bypass | 5 | 1 |
| Spoofing | 2 | - |
Affected Products 49
| Product | CVEs | Exploited |
|---|---|---|
| 3D Builder | 13 | - |
| Windows Virtual Registry Provider | 9 | - |
| Windows Cryptographic Services | 6 | - |
| Microsoft Exchange Server | 5 | - |
| Windows Layer 2 Tunneling Protocol | 5 | - |
| Microsoft Edge (Chromium-based) | 4 | - |
| Microsoft Office Visio | 4 | - |
| Microsoft Graphics Component | 3 | - |
| Microsoft Office SharePoint | 3 | - |
| Windows IKE Extension | 3 | - |
| Windows Print Spooler Components | 3 | - |
| Microsoft Office | 2 | - |
| Windows Kernel | 2 | - |
| Windows LDAP - Lightweight Directory Access Protocol | 2 | - |
| Windows Overlay Filter | 2 | - |
| Windows Point-to-Point Tunneling Protocol | 2 | - |
| Windows Secure Socket Tunneling Protocol (SSTP) | 2 | - |
| .NET Core | 1 | - |
| Azure Service Fabric Container | 1 | - |
| Microsoft Bluetooth Driver | 1 | - |
| Microsoft Local Security Authority Server (lsasrv) | 1 | - |
| Microsoft WDAC OLE DB provider for SQL | 1 | - |
| Visual Studio Code | 1 | - |
| Windows ALPC | 1 | 1 |
| Windows Ancillary Function Driver for WinSock | 1 | - |
| Windows Authentication Methods | 1 | - |
| Windows Backup Engine | 1 | - |
| Windows Bind Filter Driver | 1 | - |
| Windows BitLocker | 1 | - |
| Windows Boot Manager | 1 | - |
| Windows Credential Manager | 1 | - |
| Windows DWM Core Library | 1 | - |
| Windows Error Reporting | 1 | - |
| Windows Event Tracing | 1 | - |
| Windows Installer | 1 | - |
| Windows Internet Key Exchange (IKE) Protocol | 1 | - |
| Windows Local Security Authority (LSA) | 1 | - |
| Windows Local Session Manager (LSM) | 1 | - |
| Windows Malicious Software Removal Tool | 1 | - |
| Windows Management Instrumentation | 1 | - |
| Windows Message Queuing | 1 | - |
| Windows NTLM | 1 | - |
| Windows ODBC Driver | 1 | - |
| Windows RPC API | 1 | - |
| Windows Remote Access Service L2TP Driver | 1 | - |
| Windows SMB | 1 | - |
| Windows Smart Card | 1 | - |
| Windows Task Scheduler | 1 | - |
| Windows iSCSI | 1 | - |