Total CVEs

138

Critical

9

Important

124

Exploited

6

Publicly Disclosed

1

All CVEs this month 138

CVE Title Severity CVSS Product Exploited Disclosed Diffed
CVE-2023-33127 .NET and Visual Studio Elevation of Privilege Vulnerability Important 8.1 .NET and Visual Studio - - -
CVE-2023-21756 Windows Win32k Elevation of Privilege Vulnerability Important 7.8 Microsoft Graphics Component - - -
CVE-2023-33148 Microsoft Office Elevation of Privilege Vulnerability Important 7.8 Microsoft Office - - -
CVE-2023-33149 Microsoft Office Graphics Remote Code Execution Vulnerability Important 7.8 Microsoft Graphics Component - - -
CVE-2023-33150 Microsoft Office Security Feature Bypass Vulnerability Important 9.6 Microsoft Office - - -
CVE-2023-33151 Microsoft Outlook Spoofing Vulnerability Important 6.5 Microsoft Office Outlook - - -
CVE-2023-33152 Microsoft ActiveX Remote Code Execution Vulnerability Important 7.8 Microsoft Office Access - - -
CVE-2023-33153 Microsoft Outlook Remote Code Execution Vulnerability Important 8.8 Microsoft Office Outlook - - -
CVE-2023-33165 Microsoft SharePoint Server Security Feature Bypass Vulnerability Important 7.5 Microsoft Office SharePoint - - -
CVE-2023-33166 Remote Procedure Call Runtime Denial of Service Vulnerability Important 7.5 Windows Remote Procedure Call - - -
CVE-2023-33167 Remote Procedure Call Runtime Denial of Service Vulnerability Important 7.5 Windows Remote Procedure Call - - -
CVE-2023-33168 Remote Procedure Call Runtime Denial of Service Vulnerability Important 7.5 Windows Remote Procedure Call - - -
CVE-2023-33169 Remote Procedure Call Runtime Denial of Service Vulnerability Important 7.5 Windows Remote Procedure Call - - -
CVE-2023-33172 Remote Procedure Call Runtime Denial of Service Vulnerability Important 7.5 Windows Remote Procedure Call - - -
CVE-2023-33173 Remote Procedure Call Runtime Denial of Service Vulnerability Important 7.5 Windows Remote Procedure Call - - -
CVE-2023-33174 Windows Cryptographic Information Disclosure Vulnerability Important 5.5 Windows Cryptographic Services - - -
CVE-2023-32033 Microsoft Failover Cluster Remote Code Execution Vulnerability Important 7.2 Windows Cluster Server - - -
CVE-2023-32034 Remote Procedure Call Runtime Denial of Service Vulnerability Important 7.5 Windows Remote Procedure Call - - -
CVE-2023-32035 Remote Procedure Call Runtime Denial of Service Vulnerability Important 7.5 Windows Remote Procedure Call - - -
CVE-2023-32037 Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability Important 6.5 Windows Layer 2 Tunneling Protocol - - -
CVE-2023-32038 Microsoft ODBC Driver Remote Code Execution Vulnerability Important 8.8 Windows ODBC Driver - - -
CVE-2023-32039 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Important 5.5 Microsoft Printer Drivers - - -
CVE-2023-32040 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Important 5.5 Microsoft Printer Drivers - - -
CVE-2023-32041 Windows Update Orchestrator Service Information Disclosure Vulnerability Important 5.5 Windows Update Orchestrator Service - - -
CVE-2023-32042 OLE Automation Information Disclosure Vulnerability Important 7.5 Windows OLE - - -
CVE-2023-32043 Windows Remote Desktop Security Feature Bypass Vulnerability Important 6.8 Windows Remote Desktop - - -
CVE-2023-32044 Microsoft Message Queuing Denial of Service Vulnerability Important 7.5 Windows Message Queuing - - -
CVE-2023-32045 Microsoft Message Queuing Denial of Service Vulnerability Important 7.5 Windows Message Queuing - - -
CVE-2023-32046 Windows MSHTML Platform Elevation of Privilege Vulnerability Important 7.8 Windows MSHTML Platform Yes - -
CVE-2023-32047 Paint 3D Remote Code Execution Vulnerability Important 7.8 Paint 3D - - -
CVE-2023-32050 Windows Installer Elevation of Privilege Vulnerability Important 7 Windows Installer - - -
CVE-2023-32051 Raw Image Extension Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2023-35313 Windows Online Certificate Status Protocol (OCSP) SnapIn Remote Code Execution Vulnerability Important 7.8 Windows Online Certificate Status Protocol (OCSP) SnapIn - - -
CVE-2023-35314 Remote Procedure Call Runtime Denial of Service Vulnerability Important 6.5 Windows Remote Procedure Call - - -
CVE-2023-35315 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability Critical 8.8 Windows Layer-2 Bridge Network Driver - - -
CVE-2023-35316 Remote Procedure Call Runtime Information Disclosure Vulnerability Important 6.5 Windows Remote Procedure Call - - -
CVE-2023-35317 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability Important 7.8 Windows Server Update Service - - -
CVE-2023-35318 Remote Procedure Call Runtime Denial of Service Vulnerability Important 6.5 Windows Remote Procedure Call - - -
CVE-2023-35319 Remote Procedure Call Runtime Denial of Service Vulnerability Important 6.5 Windows Remote Procedure Call - - -
CVE-2023-35320 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability Important 7.8 Windows Connected User Experiences and Telemetry - - -
CVE-2023-35321 Windows Deployment Services Denial of Service Vulnerability Important 6.5 Windows Deployment Services - - -
CVE-2023-35322 Windows Deployment Services Remote Code Execution Vulnerability Important 8.8 Windows Deployment Services - - -
CVE-2023-35323 Windows OLE Remote Code Execution Vulnerability Important 7.8 Windows Online Certificate Status Protocol (OCSP) SnapIn - - -
CVE-2023-35324 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Important 5.5 Microsoft Printer Drivers - - -
CVE-2023-35325 Windows Print Spooler Information Disclosure Vulnerability Important 7.5 Windows Print Spooler Components - - -
CVE-2023-35326 Windows CDP User Components Information Disclosure Vulnerability Important 5.5 Windows CDP User Components - - -
CVE-2023-35328 Windows Transaction Manager Elevation of Privilege Vulnerability Important 7.8 Windows Transaction Manager - - -
CVE-2023-35329 Windows Authentication Denial of Service Vulnerability Important 6.5 Windows Authentication Methods - - -
CVE-2023-35330 Windows Extended Negotiation Denial of Service Vulnerability Important 7.5 Windows SPNEGO Extended Negotiation - - -
CVE-2023-35331 Windows Local Security Authority (LSA) Denial of Service Vulnerability Important 6.5 Windows Local Security Authority (LSA) - - -
CVE-2023-35332 Windows Remote Desktop Protocol Security Feature Bypass Important 6.8 Windows Remote Desktop - - -
CVE-2023-35333 MediaWiki PandocUpload Extension Remote Code Execution Vulnerability Important 7.5 Microsoft Media-Wiki Extensions - - -
CVE-2023-35336 Windows MSHTML Platform Security Feature Bypass Vulnerability Important 5.4 Windows MSHTML Platform - - -
CVE-2023-35337 Win32k Elevation of Privilege Vulnerability Important 7.8 Windows Win32K - - -
CVE-2023-35338 Windows Peer Name Resolution Protocol Denial of Service Vulnerability Important 7.5 Windows Peer Name Resolution Protocol - - -
CVE-2023-35339 Windows CryptoAPI Denial of Service Vulnerability Important 7.5 Windows CryptoAPI - - -
CVE-2023-35340 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability Important 7.8 Windows CNG Key Isolation Service - - -
CVE-2023-35341 Microsoft DirectMusic Information Disclosure Vulnerability Important 5.5 Windows Media - - -
CVE-2023-35342 Windows Image Acquisition Elevation of Privilege Vulnerability Important 7.8 Windows Image Acquisition - - -
CVE-2023-35343 Windows Geolocation Service Remote Code Execution Vulnerability Important 7.8 Windows Geolocation Service - - -
CVE-2023-35344 Windows DNS Server Remote Code Execution Vulnerability Important 6.6 Role: DNS Server - - -
CVE-2023-35345 Windows DNS Server Remote Code Execution Vulnerability Important 6.6 Role: DNS Server - - -
CVE-2023-35346 Windows DNS Server Remote Code Execution Vulnerability Important 6.6 Role: DNS Server - - -
CVE-2023-35347 Microsoft Install Service Elevation of Privilege Vulnerability Important 7.1 Windows App Store - - -
CVE-2023-35348 Active Directory Federation Service Security Feature Bypass Vulnerability Important 6.5 Azure Active Directory - - -
CVE-2023-35350 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability Important 7.2 Windows Active Directory Certificate Services - - -
CVE-2023-35351 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability Important 6.6 Windows Active Directory Certificate Services - - -
CVE-2023-35352 Windows Remote Desktop Security Feature Bypass Vulnerability Critical 7.5 Windows Remote Desktop - - -
CVE-2023-35353 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability Important 7.8 Windows Connected User Experiences and Telemetry - - -
CVE-2023-35356 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2023-35357 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2023-35358 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2023-35360 Windows Kernel Elevation of Privilege Vulnerability Important 7 Windows NT OS Kernel - - -
CVE-2023-35361 Windows Kernel Elevation of Privilege Vulnerability Important 7 Windows NT OS Kernel - - -
CVE-2023-35362 Windows Clip Service Elevation of Privilege Vulnerability Important 7.8 Windows Clip Service - - -
CVE-2023-35363 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2023-35364 Windows Kernel Elevation of Privilege Vulnerability Important 8.8 Windows NT OS Kernel - - -
CVE-2023-35365 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Critical 9.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2023-35366 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Critical 9.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2023-35367 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Critical 9.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2023-36872 VP9 Video Extensions Information Disclosure Vulnerability Important 5.5 Microsoft Windows Codecs Library - - -
CVE-2023-36874 Windows Error Reporting Service Elevation of Privilege Vulnerability Important 7.8 Windows Error Reporting Yes - -
CVE-2023-36884 Windows Search Remote Code Execution Vulnerability Important 7.5 Microsoft Windows Search Component Yes Yes -
CVE-2023-36888 Microsoft Edge for Android (Chromium-based) Tampering Vulnerability Important 6.3 Microsoft Edge (Chromium-based) - - -
CVE-2023-36883 Microsoft Edge for iOS Spoofing Vulnerability Moderate 4.3 Microsoft Edge (Chromium-based) - - -
CVE-2023-36887 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Important 7.8 Microsoft Edge (Chromium-based) - - -
CVE-2023-38173 Microsoft Edge for Android Spoofing Vulnerability Moderate 4.3 Microsoft Edge (Chromium-based) - - -
CVE-2023-35392 Microsoft Edge (Chromium-based) Spoofing Vulnerability Low 4.7 Microsoft Edge (Chromium-based) - - -
CVE-2023-38187 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Moderate 6.5 Microsoft Edge (Chromium-based) - - -
CVE-2023-21526 Windows Netlogon Information Disclosure Vulnerability Important 7.4 Windows Netlogon - - -
ADV230001 Guidance on Microsoft Signed Drivers Being Used Maliciously None - Windows Certificates Yes - -
CVE-2023-29347 Windows Admin Center Spoofing Vulnerability Important 6.8 Windows Admin Center - - -
CVE-2023-33154 Windows Partition Management Driver Elevation of Privilege Vulnerability Important 9.8 Windows Partition Management Driver - - -
CVE-2023-33155 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Important 7.8 Windows Cloud Files Mini Filter Driver - - -
CVE-2023-33156 Microsoft Defender Elevation of Privilege Vulnerability Important 7 Windows Defender - - -
CVE-2023-33157 Microsoft SharePoint Remote Code Execution Vulnerability Critical 8.8 Microsoft Office SharePoint - - -
CVE-2023-33158 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2023-33159 Microsoft SharePoint Server Spoofing Vulnerability Important 8.8 Microsoft Office SharePoint - - -
CVE-2023-33160 Microsoft SharePoint Server Remote Code Execution Vulnerability Critical 8.8 Microsoft Office SharePoint - - -
CVE-2023-33161 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2023-33162 Microsoft Excel Information Disclosure Vulnerability Important 5.5 Microsoft Office Excel - - -
CVE-2023-33163 Windows Network Load Balancing Remote Code Execution Vulnerability Important 7.5 Windows Network Load Balancing - - -
CVE-2023-33164 Remote Procedure Call Runtime Denial of Service Vulnerability Important 6.5 Windows Remote Procedure Call - - -
CVE-2023-33170 ASP.NET and Visual Studio Security Feature Bypass Vulnerability Important 8.1 ASP.NET and Visual Studio - - -
CVE-2023-33171 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Important 6.1 Microsoft Dynamics - - -
CVE-2023-32052 Microsoft Power Apps (online) Spoofing Vulnerability Important 5.4 Microsoft Power Apps - - -
CVE-2023-32053 Windows Installer Elevation of Privilege Vulnerability Important 7.8 Windows Installer - - -
CVE-2023-32054 Volume Shadow Copy Elevation of Privilege Vulnerability Important 7.3 Windows Volume Shadow Copy - - -
CVE-2023-32055 Active Template Library Elevation of Privilege Vulnerability Important 6.7 Windows Active Template Library - - -
CVE-2023-32056 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability Important 9.8 Windows Server Update Service - - -
CVE-2023-32057 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Critical 9.8 Windows Message Queuing - - -
CVE-2023-32083 Microsoft Failover Cluster Information Disclosure Vulnerability Important 4.9 Windows Failover Cluster - - -
CVE-2023-32084 HTTP.sys Denial of Service Vulnerability Important 7.5 Windows HTTP.sys - - -
CVE-2023-32085 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Important 5.5 Microsoft Printer Drivers - - -
CVE-2023-35296 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Important 6.5 Microsoft Printer Drivers - - -
CVE-2023-35297 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Critical 8.1 Windows PGM - - -
CVE-2023-35298 HTTP.sys Denial of Service Vulnerability Important 7.5 Windows HTTP.sys - - -
CVE-2023-35299 Windows Common Log File System Driver Elevation of Privilege Vulnerability Important 7.8 Windows Common Log File System Driver - - -
CVE-2023-35300 Remote Procedure Call Runtime Remote Code Execution Vulnerability Important 8.8 Windows Remote Procedure Call - - -
CVE-2023-35302 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability Important 8.8 Microsoft Printer Drivers - - -
CVE-2023-35303 USB Audio Class System Driver Remote Code Execution Vulnerability Important 8.8 Microsoft Windows Codecs Library - - -
CVE-2023-35304 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2023-35305 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2023-35306 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Important 5.5 Microsoft Printer Drivers - - -
CVE-2023-35308 Windows MSHTML Platform Security Feature Bypass Vulnerability Important 6.5 Windows MSHTML Platform - - -
CVE-2023-35309 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Important 7.5 Windows Message Queuing - - -
CVE-2023-35310 Windows DNS Server Remote Code Execution Vulnerability Important 6.6 Role: DNS Server - - -
CVE-2023-35311 Microsoft Outlook Security Feature Bypass Vulnerability Important 8.8 Microsoft Office Outlook Yes - -
CVE-2023-35312 Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability Important 7.8 Windows VOLSNAP.SYS - - -
CVE-2023-35335 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Important 8.2 Microsoft Dynamics - - -
CVE-2023-32049 Windows SmartScreen Security Feature Bypass Vulnerability Important 8.8 Windows SmartScreen Yes - -
ADV230002 Microsoft Guidance for Addressing Security Feature Bypass in Trend Micro EFI Modules Important - Windows EFI Partition - - -
CVE-2023-35374 Paint 3D Remote Code Execution Vulnerability Important 7.8 Paint 3D - - -
CVE-2023-35373 Mono Authenticode Validation Spoofing Vulnerability Important 5.3 Mono Authenticode - - -
CVE-2023-36867 Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability Important 7.8 Visual Studio Code - - -
CVE-2023-36868 Azure Service Fabric on Windows Information Disclosure Vulnerability Important 6.5 Service Fabric - - -
CVE-2023-33134 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 8.8 Microsoft Office SharePoint - - -
CVE-2023-36871 Azure Active Directory Security Feature Bypass Vulnerability Important 6.5 Azure Active Directory - - -

Threat Categories 8

Threat Category CVEs Critical
Remote Code Execution 38 8
Elevation of Privilege 34 -
Denial of Service 22 -
Information Disclosure 19 -
Security Feature Bypass 13 1
Spoofing 10 -
Defense in Depth 1 -
Tampering 1 -

Affected Products 73

Product CVEs Exploited
Windows Remote Procedure Call 14 -
Microsoft Printer Drivers 7 -
Microsoft Edge (Chromium-based) 6 -
Windows Kernel 6 -
Microsoft Office SharePoint 5 -
Role: DNS Server 4 -
Windows Message Queuing 4 -
Microsoft Office Excel 3 -
Microsoft Office Outlook 3 1
Microsoft Windows Codecs Library 3 -
Windows MSHTML Platform 3 1
Windows NT OS Kernel 3 -
Windows Remote Desktop 3 -
Windows Routing and Remote Access Service (RRAS) 3 -
Azure Active Directory 2 -
Microsoft Dynamics 2 -
Microsoft Graphics Component 2 -
Microsoft Office 2 -
Paint 3D 2 -
Windows Active Directory Certificate Services 2 -
Windows Connected User Experiences and Telemetry 2 -
Windows Deployment Services 2 -
Windows HTTP.sys 2 -
Windows Installer 2 -
Windows Online Certificate Status Protocol (OCSP) SnapIn 2 -
Windows Server Update Service 2 -
.NET and Visual Studio 1 -
ASP.NET and Visual Studio 1 -
Microsoft Media-Wiki Extensions 1 -
Microsoft Office Access 1 -
Microsoft Power Apps 1 -
Microsoft Windows Search Component 1 1
Mono Authenticode 1 -
Service Fabric 1 -
Visual Studio Code 1 -
Windows Active Template Library 1 -
Windows Admin Center 1 -
Windows App Store 1 -
Windows Authentication Methods 1 -
Windows CDP User Components 1 -
Windows CNG Key Isolation Service 1 -
Windows Certificates 1 1
Windows Clip Service 1 -
Windows Cloud Files Mini Filter Driver 1 -
Windows Cluster Server 1 -
Windows Common Log File System Driver 1 -
Windows CryptoAPI 1 -
Windows Cryptographic Services 1 -
Windows Defender 1 -
Windows EFI Partition 1 -
Windows Error Reporting 1 1
Windows Failover Cluster 1 -
Windows Geolocation Service 1 -
Windows Image Acquisition 1 -
Windows Layer 2 Tunneling Protocol 1 -
Windows Layer-2 Bridge Network Driver 1 -
Windows Local Security Authority (LSA) 1 -
Windows Media 1 -
Windows Netlogon 1 -
Windows Network Load Balancing 1 -
Windows ODBC Driver 1 -
Windows OLE 1 -
Windows PGM 1 -
Windows Partition Management Driver 1 -
Windows Peer Name Resolution Protocol 1 -
Windows Print Spooler Components 1 -
Windows SPNEGO Extended Negotiation 1 -
Windows SmartScreen 1 1
Windows Transaction Manager 1 -
Windows Update Orchestrator Service 1 -
Windows VOLSNAP.SYS 1 -
Windows Volume Shadow Copy 1 -
Windows Win32K 1 -