Patch Tuesday Archive
Patch Tuesday May 2023
Total CVEs
40
Critical
6
Important
33
Exploited
2
Publicly Disclosed
2
All CVEs this month 40
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2023-24932 | Secure Boot Security Feature Bypass Vulnerability | Important | 6.7 |
Windows Secure Boot | Yes | Yes | - |
| CVE-2023-28251 | Windows Driver Revocation List Security Feature Bypass Vulnerability | Important | 5.5 |
Windows Secure Boot | - | - | - |
| CVE-2023-28283 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2023-24898 | Windows SMB Denial of Service Vulnerability | Important | 7.5 |
Windows SMB | - | - | - |
| CVE-2023-24899 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Graphics Component | - | - | - |
| CVE-2023-24939 | Server for NFS Denial of Service Vulnerability | Important | 7.5 |
Windows NFS Portmapper | - | - | - |
| CVE-2023-24900 | Windows NTLM Security Support Provider Information Disclosure Vulnerability | Important | 5.9 |
Windows NTLM | - | - | - |
| CVE-2023-24940 | Windows Pragmatic General Multicast (PGM) Denial of Service Vulnerability | Important | 7.5 |
Windows PGM | - | - | - |
| CVE-2023-24901 | Windows NFS Portmapper Information Disclosure Vulnerability | Important | 7.5 |
Windows NFS Portmapper | - | - | - |
| CVE-2023-24941 | Windows Network File System Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Network File System | - | - | - |
| CVE-2023-24902 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2023-24942 | Remote Procedure Call Runtime Denial of Service Vulnerability | Important | 7.5 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2023-24903 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Secure Socket Tunneling Protocol (SSTP) | - | - | - |
| CVE-2023-24943 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows PGM | - | - | - |
| CVE-2023-24905 | Remote Desktop Client Remote Code Execution Vulnerability | Important | 7.8 |
Remote Desktop Client | - | - | - |
| CVE-2023-24944 | Windows Bluetooth Driver Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Bluetooth Driver | - | - | - |
| CVE-2023-24945 | Windows iSCSI Target Service Information Disclosure Vulnerability | Important | 5.5 |
Windows iSCSI Target Service | - | - | - |
| CVE-2023-24946 | Windows Backup Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Backup Engine | - | - | - |
| CVE-2023-24947 | Windows Bluetooth Driver Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Bluetooth Driver | - | - | - |
| CVE-2023-24948 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | Important | 7.4 |
Microsoft Bluetooth Driver | - | - | - |
| CVE-2023-24949 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-24950 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 6.5 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-24953 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2023-24954 | Microsoft SharePoint Server Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-24955 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Critical | 7.2 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-29324 | Windows MSHTML Platform Security Feature Bypass Vulnerability | Important | 6.5 |
Windows MSHTML Platform | - | - | - |
| CVE-2023-29335 | Microsoft Word Security Feature Bypass Vulnerability | Important | 7.5 |
Microsoft Office Word | - | - | - |
| CVE-2023-29336 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | Yes | - | - |
| CVE-2023-29338 | Visual Studio Code Spoofing Vulnerability | Important | 6.6 |
Visual Studio Code | - | - | - |
| CVE-2023-29340 | AV1 Video Extension Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2023-29341 | AV1 Video Extension Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2023-29343 | SysInternals Sysmon for Windows Elevation of Privilege Vulnerability | Important | 7.8 |
SysInternals | - | - | - |
| CVE-2023-29354 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Moderate | 4.7 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-29350 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 7.5 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-28290 | Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability | Important | 5.3 |
Windows RDP Client | - | - | - |
| CVE-2023-24881 | Microsoft Teams Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Teams | - | - | - |
| CVE-2023-24904 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.1 |
Windows Installer | - | - | - |
| CVE-2023-29325 | Windows OLE Remote Code Execution Vulnerability | Critical | 7.5 |
Windows OLE | - | Yes | - |
| CVE-2023-29333 | Microsoft Access Denial of Service Vulnerability | Important | 3.3 |
Microsoft Office Access | - | - | - |
| CVE-2023-29344 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 12 | 6 |
| Elevation of Privilege | 9 | - |
| Information Disclosure | 7 | - |
| Denial of Service | 5 | - |
| Security Feature Bypass | 5 | - |
| Spoofing | 2 | - |
Affected Products 30
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Bluetooth Driver | 3 | - |
| Microsoft Office SharePoint | 3 | - |
| Microsoft Edge (Chromium-based) | 2 | - |
| Microsoft Windows Codecs Library | 2 | - |
| Windows NFS Portmapper | 2 | - |
| Windows PGM | 2 | - |
| Windows Secure Boot | 2 | 1 |
| Windows Win32K | 2 | 1 |
| Microsoft Graphics Component | 1 | - |
| Microsoft Office | 1 | - |
| Microsoft Office Access | 1 | - |
| Microsoft Office Excel | 1 | - |
| Microsoft Office Word | 1 | - |
| Microsoft Teams | 1 | - |
| Remote Desktop Client | 1 | - |
| SysInternals | 1 | - |
| Visual Studio Code | 1 | - |
| Windows Backup Engine | 1 | - |
| Windows Installer | 1 | - |
| Windows Kernel | 1 | - |
| Windows LDAP - Lightweight Directory Access Protocol | 1 | - |
| Windows MSHTML Platform | 1 | - |
| Windows NTLM | 1 | - |
| Windows Network File System | 1 | - |
| Windows OLE | 1 | - |
| Windows RDP Client | 1 | - |
| Windows Remote Procedure Call Runtime | 1 | - |
| Windows SMB | 1 | - |
| Windows Secure Socket Tunneling Protocol (SSTP) | 1 | - |
| Windows iSCSI Target Service | 1 | - |