Patch Tuesday Archive
Patch Tuesday June 2023
Total CVEs
78
Critical
6
Important
68
Exploited
0
Publicly Disclosed
0
All CVEs this month 78
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2023-28310 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-24896 | Dynamics 365 Finance Spoofing Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2023-29345 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Low | 6.1 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-29353 | Sysinternals Process Monitor for Windows Denial of Service Vulnerability | Low | 5.5 |
SysInternals | - | - | - |
| CVE-2023-24897 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | Critical | 7.8 |
.NET and Visual Studio | - | - | - |
| CVE-2023-24895 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | Important | 7.8 |
.NET and Visual Studio | - | - | - |
| CVE-2023-24936 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | Moderate | 7.5 |
.NET and Visual Studio | - | - | - |
| CVE-2023-29326 | .NET Framework Remote Code Execution Vulnerability | Important | 7.8 |
.NET Framework | - | - | - |
| CVE-2023-21569 | Azure DevOps Server Spoofing Vulnerability | Important | 5.5 |
Azure DevOps | - | - | - |
| CVE-2023-21565 | Azure DevOps Server Spoofing Vulnerability | Important | 7.1 |
Azure DevOps | - | - | - |
| CVE-2023-32024 | Microsoft Power Apps Spoofing Vulnerability | Important | 3 |
Microsoft Power Apps | - | - | - |
| CVE-2023-32029 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2023-32031 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-33137 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2023-33139 | Visual Studio Information Disclosure Vulnerability | Important | 5.5 |
Visual Studio | - | - | - |
| CVE-2023-33143 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Moderate | 7.5 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-33146 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2023-29356 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-32025 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-32026 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-32027 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-29349 | Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-32028 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-24937 | Windows CryptoAPI Denial of Service Vulnerability | Important | 6.5 |
Windows CryptoAPI | - | - | - |
| CVE-2023-24938 | Windows CryptoAPI Denial of Service Vulnerability | Important | 6.5 |
Windows CryptoAPI | - | - | - |
| CVE-2023-29331 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET Core | - | - | - |
| CVE-2023-29346 | NTFS Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2023-29351 | Windows Group Policy Elevation of Privilege Vulnerability | Important | 8.1 |
Windows Group Policy | - | - | - |
| CVE-2023-29352 | Windows Remote Desktop Security Feature Bypass Vulnerability | Important | 6.5 |
Remote Desktop Client | - | - | - |
| CVE-2023-29337 | NuGet Client Remote Code Execution Vulnerability | Important | 7.1 |
NuGet Client | - | - | - |
| CVE-2023-29355 | DHCP Server Service Information Disclosure Vulnerability | Important | 5.3 |
Windows DHCP Server | - | - | - |
| CVE-2023-29357 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Critical | 9.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-29358 | Windows GDI Elevation of Privilege Vulnerability | Important | 7.8 |
Windows GDI | - | - | - |
| CVE-2023-29359 | GDI Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2023-29360 | Microsoft Streaming Service Elevation of Privilege Vulnerability | Important | 8.4 |
Microsoft Streaming Service | - | - | Yes |
| CVE-2023-29361 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 7 |
Windows Cloud Files Mini Filter Driver | - | - | - |
| CVE-2023-29362 | Remote Desktop Client Remote Code Execution Vulnerability | Important | 8.8 |
Remote Desktop Client | - | - | - |
| CVE-2023-29363 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows PGM | - | - | - |
| CVE-2023-29364 | Windows Authentication Elevation of Privilege Vulnerability | Important | 7 |
Windows Authentication Methods | - | - | - |
| CVE-2023-29365 | Windows Media Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2023-29366 | Windows Geolocation Service Remote Code Execution Vulnerability | Important | 7.8 |
Windows Geolocation Service | - | - | - |
| CVE-2023-29367 | iSCSI Target WMI Provider Remote Code Execution Vulnerability | Important | 7.8 |
Windows OLE | - | - | - |
| CVE-2023-29368 | Windows Filtering Platform Elevation of Privilege Vulnerability | Important | 7 |
Windows Filtering | - | - | - |
| CVE-2023-29369 | Remote Procedure Call Runtime Denial of Service Vulnerability | Important | 6.5 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2023-29370 | Windows Media Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2023-29371 | Windows GDI Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2023-29372 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2023-29373 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Windows ODBC Driver | - | - | - |
| CVE-2023-32008 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | Important | 7.8 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2023-32009 | Windows Collaborative Translation Framework Elevation of Privilege Vulnerability | Important | 8.8 |
Windows Collaborative Translation Framework | - | - | - |
| CVE-2023-32010 | Windows Bus Filter Driver Elevation of Privilege Vulnerability | Important | 7 |
Windows Bus Filter Driver | - | - | - |
| CVE-2023-32011 | Windows iSCSI Discovery Service Denial of Service Vulnerability | Important | 7.5 |
Windows iSCSI | - | - | - |
| CVE-2023-32012 | Windows Container Manager Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Container Manager Service | - | - | - |
| CVE-2023-32013 | Windows Hyper-V Denial of Service Vulnerability | Critical | 5.3 |
Windows Hyper-V | - | - | - |
| CVE-2023-32014 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows PGM | - | - | - |
| CVE-2023-32015 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows PGM | - | - | - |
| CVE-2023-32016 | Windows Installer Information Disclosure Vulnerability | Important | 5.5 |
Windows Installer | - | - | - |
| CVE-2023-32017 | Microsoft PostScript Printer Driver Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Printer Drivers | - | - | - |
| CVE-2023-32018 | Windows Hello Remote Code Execution Vulnerability | Important | 7.8 |
Windows Hello | - | - | - |
| CVE-2023-32019 | Windows Kernel Information Disclosure Vulnerability | Important | 4.7 |
Windows Kernel | - | - | - |
| CVE-2023-32020 | Windows DNS Spoofing Vulnerability | Important | 5.6 |
Role: DNS Server | - | - | - |
| CVE-2023-32021 | Windows SMB Witness Service Security Feature Bypass Vulnerability | Important | 7.1 |
Windows SMB | - | - | - |
| CVE-2023-32022 | Windows Server Service Security Feature Bypass Vulnerability | Important | 7.6 |
Windows Server Service | - | - | - |
| CVE-2023-32030 | .NET and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET and Visual Studio | - | - | - |
| CVE-2023-32032 | .NET and Visual Studio Elevation of Privilege Vulnerability | Important | 6.5 |
.NET and Visual Studio | - | - | - |
| CVE-2023-33126 | .NET and Visual Studio Remote Code Execution Vulnerability | Important | 7.3 |
.NET and Visual Studio | - | - | - |
| CVE-2023-33128 | .NET and Visual Studio Remote Code Execution Vulnerability | Important | 7.3 |
.NET and Visual Studio | - | - | - |
| CVE-2023-33129 | Microsoft SharePoint Denial of Service Vulnerability | Important | 6.5 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-33130 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 7.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-33131 | Microsoft Outlook Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office Outlook | - | - | - |
| CVE-2023-33132 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 6.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-33133 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2023-33135 | .NET and Visual Studio Elevation of Privilege Vulnerability | Important | 7.3 |
.NET and Visual Studio | - | - | - |
| CVE-2023-33140 | Microsoft OneNote Spoofing Vulnerability | Important | 6.5 |
Microsoft Office OneNote | - | - | - |
| CVE-2023-33141 | Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability | Important | 7.5 |
ASP.NET | - | - | - |
| CVE-2023-33142 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Important | 6.5 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-33144 | Visual Studio Code Spoofing Vulnerability | Important | 6.6 |
Visual Studio Code | - | - | - |
| CVE-2023-33145 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Edge (Chromium-based) | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 32 | 4 |
| Elevation of Privilege | 18 | 1 |
| Denial of Service | 10 | 1 |
| Spoofing | 9 | - |
| Information Disclosure | 5 | - |
| Security Feature Bypass | 4 | - |
Affected Products 50
| Product | CVEs | Exploited |
|---|---|---|
| .NET and Visual Studio | 8 | - |
| SQL Server | 6 | - |
| Microsoft Office SharePoint | 5 | - |
| Microsoft Edge (Chromium-based) | 3 | - |
| Microsoft Office Excel | 3 | - |
| Windows PGM | 3 | - |
| Azure DevOps | 2 | - |
| Microsoft Exchange Server | 2 | - |
| Microsoft Windows Codecs Library | 2 | - |
| Remote Desktop Client | 2 | - |
| Windows CryptoAPI | 2 | - |
| Windows Win32K | 2 | - |
| .NET Core | 1 | - |
| .NET Framework | 1 | - |
| ASP.NET | 1 | - |
| Microsoft Dynamics | 1 | - |
| Microsoft Office | 1 | - |
| Microsoft Office OneNote | 1 | - |
| Microsoft Office Outlook | 1 | - |
| Microsoft Power Apps | 1 | - |
| Microsoft Printer Drivers | 1 | - |
| Microsoft Streaming Service | 1 | - |
| Microsoft WDAC OLE DB provider for SQL | 1 | - |
| NuGet Client | 1 | - |
| Role: DNS Server | 1 | - |
| SysInternals | 1 | - |
| Visual Studio | 1 | - |
| Visual Studio Code | 1 | - |
| Windows Authentication Methods | 1 | - |
| Windows Bus Filter Driver | 1 | - |
| Windows Cloud Files Mini Filter Driver | 1 | - |
| Windows Collaborative Translation Framework | 1 | - |
| Windows Container Manager Service | 1 | - |
| Windows DHCP Server | 1 | - |
| Windows Filtering | 1 | - |
| Windows GDI | 1 | - |
| Windows Geolocation Service | 1 | - |
| Windows Group Policy | 1 | - |
| Windows Hello | 1 | - |
| Windows Hyper-V | 1 | - |
| Windows Installer | 1 | - |
| Windows Kernel | 1 | - |
| Windows NTFS | 1 | - |
| Windows ODBC Driver | 1 | - |
| Windows OLE | 1 | - |
| Windows Remote Procedure Call Runtime | 1 | - |
| Windows Resilient File System (ReFS) | 1 | - |
| Windows SMB | 1 | - |
| Windows Server Service | 1 | - |
| Windows iSCSI | 1 | - |