Patch Tuesday Archive
Patch Tuesday February 2023
Total CVEs
78
Critical
8
Important
67
Exploited
3
Publicly Disclosed
0
All CVEs this month 78
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2023-21553 | Azure DevOps Server Remote Code Execution Vulnerability | Important | 7.5 |
Azure DevOps | - | - | - |
| CVE-2023-21777 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | Important | 8.7 |
Azure App Service | - | - | - |
| CVE-2023-21778 | Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability | Important | 8 |
Microsoft Dynamics | - | - | - |
| CVE-2023-21684 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-21529 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-21794 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 4.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-21806 | Power BI Report Server Spoofing Vulnerability | Important | 8.2 |
Power BI | - | - | - |
| CVE-2023-21807 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 6.5 |
Microsoft Dynamics | - | - | - |
| CVE-2023-21704 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-21705 | Microsoft SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
SQL Server | - | - | - |
| CVE-2023-21706 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-21707 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-21718 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-21528 | Microsoft SQL Server Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-21809 | Microsoft Defender for Endpoint Security Feature Bypass Vulnerability | Important | 7.8 |
Microsoft Defender for Endpoint | - | - | - |
| CVE-2023-21566 | Visual Studio Elevation of Privilege Vulnerability | Important | 7.8 |
Visual Studio | - | - | - |
| CVE-2023-21567 | Visual Studio Denial of Service Vulnerability | Important | 5.6 |
Visual Studio | - | - | - |
| CVE-2023-21568 | Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability | Important | 7.3 |
SQL Server | - | - | - |
| CVE-2023-21570 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2023-21571 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2023-21572 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 6.5 |
Microsoft Dynamics | - | - | - |
| CVE-2023-21573 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2023-23374 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Moderate | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-23378 | Print 3D Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-23379 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Defender for IoT | - | - | - |
| CVE-2023-23382 | Azure Machine Learning Compute Instance Information Disclosure Vulnerability | Important | 6.5 |
Azure Machine Learning | - | - | - |
| CVE-2023-21701 | Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability | Important | 7.5 |
Windows Protected EAP (PEAP) | - | - | - |
| CVE-2023-21720 | Microsoft Edge (Chromium-based) Tampering Vulnerability | Low | 5.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-21797 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Windows ODBC Driver | - | - | - |
| CVE-2023-21798 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Windows ODBC Driver | - | - | - |
| CVE-2023-21799 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2023-21800 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Installer | - | - | - |
| CVE-2023-21801 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-21802 | Windows Media Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2023-21803 | Windows iSCSI Discovery Service Remote Code Execution Vulnerability | Critical | 9.8 |
Windows iSCSI | - | - | - |
| CVE-2023-21804 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2023-21805 | Windows MSHTML Platform Remote Code Execution Vulnerability | Important | 7.8 |
Windows MSHTML Platform | - | - | - |
| CVE-2023-21808 | .NET and Visual Studio Remote Code Execution Vulnerability | Critical | 7.8 |
.NET and Visual Studio | - | - | - |
| CVE-2023-21811 | Windows iSCSI Service Denial of Service Vulnerability | Important | 7.5 |
Windows iSCSI | - | - | - |
| CVE-2023-21812 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2023-21813 | Windows Secure Channel Denial of Service Vulnerability | Important | 7.5 |
Windows Cryptographic Services | - | - | - |
| CVE-2023-21815 | Visual Studio Remote Code Execution Vulnerability | Critical | 7.8 |
Visual Studio | - | - | - |
| CVE-2023-21816 | Windows Active Directory Domain Services API Denial of Service Vulnerability | Important | 7.5 |
Windows Active Directory | - | - | - |
| CVE-2023-21817 | Windows Kerberos Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kerberos | - | - | - |
| CVE-2023-21818 | Windows Secure Channel Denial of Service Vulnerability | Important | 7.5 |
Windows SChannel | - | - | - |
| CVE-2023-21819 | Windows Secure Channel Denial of Service Vulnerability | Important | 7.5 |
Windows Cryptographic Services | - | - | - |
| CVE-2023-21820 | Windows Distributed File System (DFS) Remote Code Execution Vulnerability | Important | 7.4 |
Windows Distributed File System (DFS) | - | - | - |
| CVE-2023-21822 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2023-21823 | Windows Graphics Component Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | Yes | - | - |
| CVE-2023-21685 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2023-21686 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2023-21687 | HTTP.sys Information Disclosure Vulnerability | Important | 5.5 |
Windows HTTP.sys | - | - | - |
| CVE-2023-21688 | NT OS Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows ALPC | - | - | - |
| CVE-2023-21689 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Protected EAP (PEAP) | - | - | - |
| CVE-2023-21690 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Protected EAP (PEAP) | - | - | - |
| CVE-2023-21691 | Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability | Important | 7.5 |
Windows Protected EAP (PEAP) | - | - | - |
| CVE-2023-21692 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Protected EAP (PEAP) | - | - | - |
| CVE-2023-21693 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Important | 5.7 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-21694 | Windows Fax Service Remote Code Execution Vulnerability | Important | 6.8 |
Windows Fax and Scan Service | - | - | - |
| CVE-2023-21695 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Protected EAP (PEAP) | - | - | - |
| CVE-2023-21697 | Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | Important | 5.5 |
Internet Storage Name Service | - | - | - |
| CVE-2023-21699 | Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | Important | 5.3 |
Internet Storage Name Service | - | - | - |
| CVE-2023-21700 | Windows iSCSI Discovery Service Denial of Service Vulnerability | Important | 7.5 |
Windows iSCSI | - | - | - |
| CVE-2023-21702 | Windows iSCSI Service Denial of Service Vulnerability | Important | 7.5 |
Windows iSCSI | - | - | - |
| CVE-2023-21703 | Azure Data Box Gateway Remote Code Execution Vulnerability | Important | 7.2 |
Azure Data Box Gateway | - | - | - |
| CVE-2023-21710 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 7.2 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-21713 | Microsoft SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
SQL Server | - | - | - |
| CVE-2023-21714 | Microsoft Office Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office | - | - | - |
| CVE-2023-21715 | Microsoft Publisher Security Features Bypass Vulnerability | Important | 7.3 |
Microsoft Office Publisher | Yes | - | - |
| CVE-2023-21716 | Microsoft Word Remote Code Execution Vulnerability | Critical | 9.8 |
Microsoft Office Word | - | - | - |
| CVE-2023-21717 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-21722 | .NET Framework Denial of Service Vulnerability | Important | 5 |
.NET Framework | - | - | - |
| CVE-2023-21564 | Azure DevOps Server Cross-Site Scripting Vulnerability | Important | 7.1 |
Azure DevOps | - | - | - |
| CVE-2023-23376 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | Yes | - | - |
| CVE-2023-23377 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-23381 | Visual Studio Remote Code Execution Vulnerability | Critical | 7.8 |
Visual Studio | - | - | - |
| CVE-2023-23390 | 3D Builder Remote Code Execution Vulnerability | Important | 7.8 |
3D Builder | - | - | - |
| CVE-2023-21721 | Microsoft OneNote Elevation of Privilege Vulnerability | Important | 6.5 |
Microsoft Office OneNote | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 37 | 8 |
| Elevation of Privilege | 13 | - |
| Denial of Service | 10 | - |
| Spoofing | 8 | - |
| Information Disclosure | 7 | - |
| Security Feature Bypass | 2 | - |
| Tampering | 1 | - |
Affected Products 40
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Dynamics | 6 | - |
| SQL Server | 6 | - |
| Windows Protected EAP (PEAP) | 6 | - |
| Microsoft Exchange Server | 4 | - |
| Visual Studio | 4 | - |
| Windows iSCSI | 4 | - |
| 3D Builder | 3 | - |
| Microsoft Edge (Chromium-based) | 3 | - |
| Microsoft PostScript Printer Driver | 3 | - |
| Microsoft WDAC OLE DB provider for SQL | 3 | - |
| Azure DevOps | 2 | - |
| Internet Storage Name Service | 2 | - |
| Microsoft Graphics Component | 2 | 1 |
| Windows Common Log File System Driver | 2 | 1 |
| Windows Cryptographic Services | 2 | - |
| Windows ODBC Driver | 2 | - |
| .NET Framework | 1 | - |
| .NET and Visual Studio | 1 | - |
| Azure App Service | 1 | - |
| Azure Data Box Gateway | 1 | - |
| Azure Machine Learning | 1 | - |
| Microsoft Defender for Endpoint | 1 | - |
| Microsoft Defender for IoT | 1 | - |
| Microsoft Office | 1 | - |
| Microsoft Office OneNote | 1 | - |
| Microsoft Office Publisher | 1 | 1 |
| Microsoft Office SharePoint | 1 | - |
| Microsoft Office Word | 1 | - |
| Microsoft Windows Codecs Library | 1 | - |
| Power BI | 1 | - |
| Windows ALPC | 1 | - |
| Windows Active Directory | 1 | - |
| Windows Distributed File System (DFS) | 1 | - |
| Windows Fax and Scan Service | 1 | - |
| Windows HTTP.sys | 1 | - |
| Windows Installer | 1 | - |
| Windows Kerberos | 1 | - |
| Windows MSHTML Platform | 1 | - |
| Windows SChannel | 1 | - |
| Windows Win32K | 1 | - |