Patch Tuesday Archive
Patch Tuesday March 2023
Total CVEs
77
Critical
7
Important
66
Exploited
2
Publicly Disclosed
2
All CVEs this month 77
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2023-28303 | Windows Snipping Tool Information Disclosure Vulnerability | Low | 3.3 |
Apps | - | Yes | - |
| CVE-2023-23383 | Service Fabric Explorer Spoofing Vulnerability | Important | 4.7 |
Service Fabric | - | - | - |
| CVE-2023-23385 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability | Important | 7 |
Windows Point-to-Point Protocol over Ethernet (PPPoE) | - | - | - |
| CVE-2023-23388 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft Bluetooth Driver | - | - | - |
| CVE-2023-23389 | Microsoft Defender Elevation of Privilege Vulnerability | Important | 6.3 |
Windows Defender | - | - | - |
| CVE-2023-23391 | Office for Android Spoofing Vulnerability | Important | 5.5 |
Office for Android | - | - | - |
| CVE-2023-23392 | HTTP Protocol Stack Remote Code Execution Vulnerability | Critical | 9.8 |
Windows HTTP Protocol Stack | - | - | - |
| CVE-2023-23393 | Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability | Important | 7 |
Windows Central Resource Manager | - | - | - |
| CVE-2023-23394 | Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | Important | 5.5 |
Client Server Run-time Subsystem (CSRSS) | - | - | - |
| CVE-2023-23395 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 3.1 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-23396 | Microsoft Excel Denial of Service Vulnerability | Important | 6.5 |
Microsoft Office Excel | - | - | - |
| CVE-2023-23397 | Microsoft Outlook Elevation of Privilege Vulnerability | Critical | 9.8 |
Microsoft Office Outlook | Yes | - | - |
| CVE-2023-23398 | Microsoft Excel Spoofing Vulnerability | Important | 7.1 |
Microsoft Office Excel | - | - | - |
| CVE-2023-23399 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2023-23403 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-24856 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Important | 7.5 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24919 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2023-24879 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2023-24920 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2023-24921 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2023-24922 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Dynamics | - | - | - |
| CVE-2023-24923 | Microsoft OneDrive for Android Information Disclosure Vulnerability | Important | 5.5 |
Microsoft OneDrive | - | - | - |
| CVE-2023-24882 | Microsoft OneDrive for Android Information Disclosure Vulnerability | Important | 5.5 |
Microsoft OneDrive | - | - | - |
| CVE-2023-24930 | Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft OneDrive | - | - | - |
| CVE-2023-24891 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2023-21708 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Remote Procedure Call | - | - | - |
| CVE-2023-23400 | Windows DNS Server Remote Code Execution Vulnerability | Important | 7.2 |
Role: DNS Server | - | - | - |
| CVE-2023-23401 | Windows Media Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2023-23402 | Windows Media Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2023-23404 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Remote Access Service Point-to-Point Tunneling Protocol | - | - | - |
| CVE-2023-23405 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.1 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2023-23406 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-23407 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | Important | 7.1 |
Windows Point-to-Point Protocol over Ethernet (PPPoE) | - | - | - |
| CVE-2023-23408 | Azure Apache Ambari Spoofing Vulnerability | Important | 4.5 |
Azure | - | - | - |
| CVE-2023-23409 | Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | Important | 5.5 |
Client Server Run-time Subsystem (CSRSS) | - | - | - |
| CVE-2023-23410 | Windows HTTP.sys Elevation of Privilege Vulnerability | Important | 7.8 |
Windows HTTP.sys | - | - | - |
| CVE-2023-23411 | Windows Hyper-V Denial of Service Vulnerability | Critical | 6.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2023-23412 | Windows Accounts Picture Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Accounts Control | - | - | - |
| CVE-2023-23413 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-23414 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | Important | 7.1 |
Windows Point-to-Point Protocol over Ethernet (PPPoE) | - | - | - |
| CVE-2023-23415 | Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability | Critical | 9.8 |
Internet Control Message Protocol (ICMP) | - | - | - |
| CVE-2023-23416 | Windows Cryptographic Services Remote Code Execution Vulnerability | Critical | 7.8 |
Windows Cryptographic Services | - | - | - |
| CVE-2023-23417 | Windows Partition Management Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Partition Management Driver | - | - | - |
| CVE-2023-23418 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2023-23419 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2023-23420 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-23421 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-23422 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-23423 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-24857 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Important | 6.5 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24858 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Important | 7.5 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24859 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Important | 7.5 |
Windows Internet Key Exchange (IKE) Protocol | - | - | - |
| CVE-2023-24861 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7 |
Windows Win32K | - | - | - |
| CVE-2023-24862 | Windows Secure Channel Denial of Service Vulnerability | Important | 5.5 |
Windows Secure Channel | - | - | - |
| CVE-2023-24863 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Important | 6.5 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24864 | Microsoft PostScript and PCL6 Class Printer Driver Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24865 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-24866 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Important | 6.5 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24906 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Important | 6.5 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24867 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24907 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24868 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24908 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.1 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2023-24869 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.1 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2023-24909 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24910 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2023-24870 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Important | 6.5 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24911 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Important | 4.3 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24871 | Windows Bluetooth Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Bluetooth Service | - | - | - |
| CVE-2023-24872 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24913 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24876 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-24880 | Windows SmartScreen Security Feature Bypass Vulnerability | Moderate | 4.4 |
Windows SmartScreen | Yes | Yes | - |
| CVE-2023-24890 | Microsoft OneDrive for iOS Security Feature Bypass Vulnerability | Important | 6.5 |
Microsoft OneDrive | - | - | - |
| CVE-2023-24892 | Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability | Important | 8.2 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-28286 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Moderate | 6.1 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-28261 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Low | 5.7 |
Microsoft Edge (Chromium-based) | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 26 | 5 |
| Elevation of Privilege | 19 | 1 |
| Information Disclosure | 15 | - |
| Spoofing | 11 | - |
| Denial of Service | 4 | 1 |
| Security Feature Bypass | 2 | - |
Affected Products 37
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft PostScript Printer Driver | 18 | - |
| Microsoft Dynamics | 6 | - |
| Microsoft OneDrive | 4 | - |
| Windows Kernel | 4 | - |
| Microsoft Edge (Chromium-based) | 3 | - |
| Microsoft Office Excel | 3 | - |
| Windows Point-to-Point Protocol over Ethernet (PPPoE) | 3 | - |
| Windows Remote Procedure Call Runtime | 3 | - |
| Client Server Run-time Subsystem (CSRSS) | 2 | - |
| Microsoft Printer Drivers | 2 | - |
| Microsoft Windows Codecs Library | 2 | - |
| Windows Resilient File System (ReFS) | 2 | - |
| Apps | 1 | - |
| Azure | 1 | - |
| Internet Control Message Protocol (ICMP) | 1 | - |
| Microsoft Bluetooth Driver | 1 | - |
| Microsoft Graphics Component | 1 | - |
| Microsoft Office Outlook | 1 | 1 |
| Microsoft Office SharePoint | 1 | - |
| Office for Android | 1 | - |
| Remote Access Service Point-to-Point Tunneling Protocol | 1 | - |
| Role: DNS Server | 1 | - |
| Role: Windows Hyper-V | 1 | - |
| Service Fabric | 1 | - |
| Windows Accounts Control | 1 | - |
| Windows Bluetooth Service | 1 | - |
| Windows Central Resource Manager | 1 | - |
| Windows Cryptographic Services | 1 | - |
| Windows Defender | 1 | - |
| Windows HTTP Protocol Stack | 1 | - |
| Windows HTTP.sys | 1 | - |
| Windows Internet Key Exchange (IKE) Protocol | 1 | - |
| Windows Partition Management Driver | 1 | - |
| Windows Remote Procedure Call | 1 | - |
| Windows Secure Channel | 1 | - |
| Windows SmartScreen | 1 | 1 |
| Windows Win32K | 1 | - |