Patch Tuesday Archive
Patch Tuesday April 2023
Total CVEs
101
Critical
7
Important
91
Exploited
1
Publicly Disclosed
0
All CVEs this month 101
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2023-24914 | Win32k Elevation of Privilege Vulnerability | Important | 7 |
Windows Win32K | - | - | - |
| CVE-2023-23384 | Microsoft SQL Server Remote Code Execution Vulnerability | Important | 7.3 |
SQL Server | - | - | - |
| CVE-2023-21769 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-21729 | Remote Procedure Call Runtime Information Disclosure Vulnerability | Important | 5.3 |
Windows RPC API | - | - | - |
| CVE-2023-21727 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows RPC API | - | - | - |
| CVE-2023-23375 | Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-24912 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2023-24860 | Microsoft Defender Denial of Service Vulnerability | Important | 7.5 |
Microsoft Defender for Endpoint | - | - | - |
| CVE-2023-24931 | Windows Secure Channel Denial of Service Vulnerability | Important | 7.5 |
Windows Secure Channel | - | - | - |
| CVE-2023-28216 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Important | 7 |
Windows ALPC | - | - | - |
| CVE-2023-28217 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Important | 7.5 |
Windows Network Address Translation (NAT) | - | - | - |
| CVE-2023-28218 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2023-28221 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Important | 7 |
Windows Error Reporting | - | - | - |
| CVE-2023-28222 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.1 |
Windows Kernel | - | - | - |
| CVE-2023-24926 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-24885 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-24927 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-24886 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-24928 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-24929 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-24887 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-28285 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2023-28287 | Microsoft Publisher Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Publisher | - | - | - |
| CVE-2023-28288 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 8.1 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-28291 | Raw Image Extension Remote Code Execution Vulnerability | Critical | 7.8 |
Windows Raw Image Extension | - | - | - |
| CVE-2023-28292 | Raw Image Extension Remote Code Execution Vulnerability | Important | 7.8 |
Windows Raw Image Extension | - | - | - |
| CVE-2023-28295 | Microsoft Publisher Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Publisher | - | - | - |
| CVE-2023-28297 | Windows Remote Procedure Call Service (RPCSS) Elevation of Privilege Vulnerability | Important | 8.8 |
Windows RPC API | - | - | - |
| CVE-2023-28298 | Windows Kernel Denial of Service Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2023-28300 | Azure Service Connector Security Feature Bypass Vulnerability | Important | 7.5 |
Azure Service Connector | - | - | - |
| CVE-2023-28305 | Windows DNS Server Remote Code Execution Vulnerability | Important | 6.6 |
Microsoft Windows DNS | - | - | - |
| CVE-2023-28309 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2023-28313 | Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability | Important | 6.1 |
Dynamics 365 Customer Voice | - | - | - |
| CVE-2023-28223 | Windows Domain Name Service Remote Code Execution Vulnerability | Important | 6.6 |
Microsoft Windows DNS | - | - | - |
| CVE-2023-28314 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 6.1 |
Microsoft Dynamics | - | - | - |
| CVE-2023-24893 | Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2023-24935 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 6.1 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-28301 | Microsoft Edge (Chromium-based) Tampering Vulnerability | Low | 3.7 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-29334 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Moderate | 4.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-21554 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Message Queuing | - | - | Yes |
| CVE-2023-24924 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-24883 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-24925 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-24884 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-28219 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-28220 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-28224 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | Important | 7.1 |
Windows Point-to-Point Protocol over Ethernet (PPPoE) | - | - | - |
| CVE-2023-28225 | Windows NTLM Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTLM | - | - | - |
| CVE-2023-28226 | Windows Enroll Engine Security Feature Bypass Vulnerability | Important | 5.3 |
Windows Enroll Engine | - | - | - |
| CVE-2023-28227 | Windows Bluetooth Driver Remote Code Execution Vulnerability | Important | 7.5 |
Microsoft Bluetooth Driver | - | - | - |
| CVE-2023-28228 | Windows Spoofing Vulnerability | Important | 5.5 |
Windows RDP Client | - | - | - |
| CVE-2023-28229 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | Important | 7 |
Windows CNG Key Isolation Service | - | - | Yes |
| CVE-2023-28231 | DHCP Server Service Remote Code Execution Vulnerability | Critical | 8.8 |
Windows DHCP Server | - | - | - |
| CVE-2023-28232 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | Critical | 7.5 |
Windows Point-to-Point Tunneling Protocol | - | - | - |
| CVE-2023-28233 | Windows Secure Channel Denial of Service Vulnerability | Important | 7.5 |
Windows Secure Channel | - | - | - |
| CVE-2023-28234 | Windows Secure Channel Denial of Service Vulnerability | Important | 7.5 |
Windows Transport Security Layer (TLS) | - | - | - |
| CVE-2023-28235 | Windows Lock Screen Security Feature Bypass Vulnerability | Important | 6.8 |
Windows Lock Screen | - | - | - |
| CVE-2023-28236 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows ALPC | - | - | - |
| CVE-2023-28237 | Windows Kernel Remote Code Execution Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-28238 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | Important | 7.5 |
Windows Internet Key Exchange (IKE) Protocol | - | - | - |
| CVE-2023-28240 | Windows Network Load Balancing Remote Code Execution Vulnerability | Important | 8.8 |
Windows Network Load Balancing | - | - | - |
| CVE-2023-28241 | Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability | Important | 7.5 |
Windows Secure Socket Tunneling Protocol (SSTP) | - | - | - |
| CVE-2023-28266 | Windows Common Log File System Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows Common Log File System Driver | - | - | - |
| CVE-2023-28243 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft PostScript Printer Driver | - | - | - |
| CVE-2023-28267 | Remote Desktop Protocol Client Information Disclosure Vulnerability | Important | 6.5 |
Windows RDP Client | - | - | - |
| CVE-2023-28244 | Windows Kerberos Elevation of Privilege Vulnerability | Important | 8.1 |
Windows Kerberos | - | - | - |
| CVE-2023-28268 | Netlogon RPC Elevation of Privilege Vulnerability | Important | 8.1 |
Windows Netlogon | - | - | - |
| CVE-2023-28246 | Windows Registry Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Registry | - | - | - |
| CVE-2023-28270 | Windows Lock Screen Security Feature Bypass Vulnerability | Important | 6.8 |
Windows Lock Screen | - | - | - |
| CVE-2023-28247 | Windows Network File System Information Disclosure Vulnerability | Important | 7.5 |
Windows Network File System | - | - | - |
| CVE-2023-28248 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-28271 | Windows Kernel Memory Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2023-28272 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-28250 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows PGM | - | - | - |
| CVE-2023-28273 | Windows Clip Service Elevation of Privilege Vulnerability | Important | 7 |
Windows Clip Service | - | - | - |
| CVE-2023-28274 | Windows Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2023-28252 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | Yes | - | Yes |
| CVE-2023-28275 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2023-28253 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2023-28276 | Windows Group Policy Security Feature Bypass Vulnerability | Important | 4.4 |
Windows Group Policy | - | - | - |
| CVE-2023-28254 | Windows DNS Server Remote Code Execution Vulnerability | Important | 7.2 |
Microsoft Windows DNS | - | - | - |
| CVE-2023-28277 | Windows DNS Server Information Disclosure Vulnerability | Important | 4.9 |
Microsoft Windows DNS | - | - | - |
| CVE-2023-28255 | Windows DNS Server Remote Code Execution Vulnerability | Important | 6.6 |
Microsoft Windows DNS | - | - | - |
| CVE-2023-28278 | Windows DNS Server Remote Code Execution Vulnerability | Important | 6.6 |
Microsoft Windows DNS | - | - | - |
| CVE-2023-28256 | Windows DNS Server Remote Code Execution Vulnerability | Important | 6.6 |
Microsoft Windows DNS | - | - | - |
| CVE-2023-28260 | .NET DLL Hijacking Remote Code Execution Vulnerability | Important | 7.8 |
.NET Core | - | - | - |
| CVE-2023-28262 | Visual Studio Elevation of Privilege Vulnerability | Important | 7.8 |
Visual Studio | - | - | - |
| CVE-2023-28263 | Visual Studio Information Disclosure Vulnerability | Important | 5.5 |
Visual Studio | - | - | - |
| CVE-2023-28293 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-28296 | Visual Studio Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio | - | - | - |
| CVE-2023-28299 | Visual Studio Spoofing Vulnerability | Important | 5.5 |
Visual Studio | - | - | - |
| CVE-2023-28302 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 7.5 |
Windows Active Directory | - | - | - |
| CVE-2023-28304 | Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-28306 | Windows DNS Server Remote Code Execution Vulnerability | Important | 6.6 |
Microsoft Windows DNS | - | - | - |
| CVE-2023-28307 | Windows DNS Server Remote Code Execution Vulnerability | Important | 6.6 |
Microsoft Windows DNS | - | - | - |
| CVE-2023-28308 | Windows DNS Server Remote Code Execution Vulnerability | Important | 6.6 |
Microsoft Windows DNS | - | - | - |
| CVE-2023-28311 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2023-28312 | Azure Machine Learning Information Disclosure Vulnerability | Important | 6.5 |
Azure Machine Learning | - | - | - |
| CVE-2023-28269 | Windows Boot Manager Security Feature Bypass Vulnerability | Important | 6.8 |
Windows Boot Manager | - | - | - |
| CVE-2023-28249 | Windows Boot Manager Security Feature Bypass Vulnerability | Important | 6.8 |
Windows Boot Manager | - | - | - |
| CVE-2023-24934 | Microsoft Defender Security Feature Bypass Vulnerability | Important | 5.5 |
Windows Defender | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 45 | 7 |
| Elevation of Privilege | 20 | - |
| Information Disclosure | 10 | - |
| Denial of Service | 9 | - |
| Security Feature Bypass | 8 | - |
| Spoofing | 8 | - |
| Tampering | 1 | - |
Affected Products 54
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Printer Drivers | 11 | - |
| Microsoft Windows DNS | 10 | - |
| Windows Kernel | 8 | - |
| Visual Studio | 4 | - |
| Microsoft Edge (Chromium-based) | 3 | - |
| SQL Server | 3 | - |
| Windows RPC API | 3 | - |
| Microsoft Dynamics | 2 | - |
| Microsoft Office Publisher | 2 | - |
| Windows ALPC | 2 | - |
| Windows Boot Manager | 2 | - |
| Windows Common Log File System Driver | 2 | 1 |
| Windows Layer 2 Tunneling Protocol | 2 | - |
| Windows Lock Screen | 2 | - |
| Windows Message Queuing | 2 | - |
| Windows RDP Client | 2 | - |
| Windows Raw Image Extension | 2 | - |
| Windows Secure Channel | 2 | - |
| Windows Win32K | 2 | - |
| .NET Core | 1 | - |
| Azure Machine Learning | 1 | - |
| Azure Service Connector | 1 | - |
| Dynamics 365 Customer Voice | 1 | - |
| Microsoft Bluetooth Driver | 1 | - |
| Microsoft Defender for Endpoint | 1 | - |
| Microsoft Graphics Component | 1 | - |
| Microsoft Office | 1 | - |
| Microsoft Office SharePoint | 1 | - |
| Microsoft Office Word | 1 | - |
| Microsoft PostScript Printer Driver | 1 | - |
| Microsoft WDAC OLE DB provider for SQL | 1 | - |
| Visual Studio Code | 1 | - |
| Windows Active Directory | 1 | - |
| Windows Ancillary Function Driver for WinSock | 1 | - |
| Windows CNG Key Isolation Service | 1 | - |
| Windows Clip Service | 1 | - |
| Windows DHCP Server | 1 | - |
| Windows Defender | 1 | - |
| Windows Enroll Engine | 1 | - |
| Windows Error Reporting | 1 | - |
| Windows Group Policy | 1 | - |
| Windows Internet Key Exchange (IKE) Protocol | 1 | - |
| Windows Kerberos | 1 | - |
| Windows NTLM | 1 | - |
| Windows Netlogon | 1 | - |
| Windows Network Address Translation (NAT) | 1 | - |
| Windows Network File System | 1 | - |
| Windows Network Load Balancing | 1 | - |
| Windows PGM | 1 | - |
| Windows Point-to-Point Protocol over Ethernet (PPPoE) | 1 | - |
| Windows Point-to-Point Tunneling Protocol | 1 | - |
| Windows Registry | 1 | - |
| Windows Secure Socket Tunneling Protocol (SSTP) | 1 | - |
| Windows Transport Security Layer (TLS) | 1 | - |