Patch Tuesday Archive
Patch Tuesday August 2023
Total CVEs
80
Critical
6
Important
68
Exploited
2
Publicly Disclosed
2
All CVEs this month 80
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2023-36787 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Moderate | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-21709 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Important | 9.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-35368 | Microsoft Exchange Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-35359 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-36865 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2023-36866 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2023-36873 | .NET Framework Spoofing Vulnerability | Important | 5.9 |
.NET Framework | - | - | - |
| CVE-2023-36876 | Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability | Important | 7.1 |
Reliability Analysis Metrics Calculation Engine | - | - | - |
| CVE-2023-36882 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2023-36889 | Windows Group Policy Security Feature Bypass Vulnerability | Important | 5.5 |
Windows Group Policy | - | - | - |
| CVE-2023-36898 | Tablet Windows User Interface Application Core Remote Code Execution Vulnerability | Important | 7.8 |
Tablet Windows User Interface | - | - | - |
| CVE-2023-36899 | ASP.NET Elevation of Privilege Vulnerability | Important | 8.8 |
ASP.NET | - | - | - |
| CVE-2023-36900 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2023-36903 | Windows System Assessment Tool Elevation of Privilege Vulnerability | Important | 9.8 |
Windows System Assessment Tool | - | - | - |
| CVE-2023-36904 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Cloud Files Mini Filter Driver | - | - | - |
| CVE-2023-36905 | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | Important | 7.5 |
Windows Wireless Wide Area Network Service | - | - | - |
| CVE-2023-36906 | Windows Cryptographic Services Information Disclosure Vulnerability | Important | 7.5 |
Windows Cryptographic Services | - | - | - |
| CVE-2023-36907 | Windows Cryptographic Services Information Disclosure Vulnerability | Important | 7.5 |
Windows Cryptographic Services | - | - | - |
| CVE-2023-36908 | Windows Hyper-V Information Disclosure Vulnerability | Important | 6.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2023-36909 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 6.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-36910 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Message Queuing | - | - | - |
| CVE-2023-36911 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Message Queuing | - | - | - |
| CVE-2023-36912 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-36913 | Microsoft Message Queuing Information Disclosure Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-36914 | Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | Important | 5.5 |
Windows Smart Card | - | - | - |
| CVE-2023-35376 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 6.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-38254 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 6.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-35377 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 6.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-35378 | Windows Projected File System Elevation of Privilege Vulnerability | Important | 7 |
Windows Projected File System | - | - | - |
| CVE-2023-35379 | Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Reliability Analysis Metrics Calculation Engine | - | - | - |
| CVE-2023-35380 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-35381 | Windows Fax Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Fax and Scan Service | - | - | - |
| CVE-2023-35382 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-35383 | Microsoft Message Queuing Information Disclosure Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-35384 | Windows HTML Platforms Security Feature Bypass Vulnerability | Important | 6.5 |
Windows HTML Platform | - | - | - |
| CVE-2023-35385 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Message Queuing | - | - | - |
| CVE-2023-35386 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-35387 | Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability | Important | 8.8 |
Windows Bluetooth A2DP driver | - | - | - |
| CVE-2023-35389 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | Important | 6.5 |
Microsoft Dynamics | - | - | - |
| CVE-2023-35393 | Azure Apache Hive Spoofing Vulnerability | Important | 4.5 |
Azure HDInsights | - | - | - |
| CVE-2023-35394 | Azure HDInsight Jupyter Notebook Spoofing Vulnerability | Important | 4.6 |
Azure HDInsights | - | - | - |
| CVE-2023-38188 | Azure Apache Hadoop Spoofing Vulnerability | Important | 4.5 |
Azure HDInsights | - | - | - |
| CVE-2023-38186 | Windows Mobile Device Management Elevation of Privilege Vulnerability | Important | 9.8 |
Windows Mobile Device Management | - | - | - |
| CVE-2023-38185 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-38184 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 7.5 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2023-38175 | Microsoft Windows Defender Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Defender | - | - | - |
| CVE-2023-38172 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-38170 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2023-38169 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | Important | 8.8 |
SQL Server | - | - | - |
| CVE-2023-38167 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | Important | 7.2 |
Dynamics Business Central Control | - | - | - |
| ADV230003 | Microsoft Office Defense in Depth Update | Moderate | - | Microsoft Office | Yes | Yes | - |
| CVE-2023-38157 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Moderate | 6.5 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-35371 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2023-35372 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2023-29330 | Microsoft Teams Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Teams | - | - | - |
| CVE-2023-29328 | Microsoft Teams Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Teams | - | - | - |
| CVE-2023-36877 | Azure Apache Oozie Spoofing Vulnerability | Important | 4.5 |
Azure HDInsights | - | - | - |
| CVE-2023-36881 | Azure Apache Ambari Spoofing Vulnerability | Important | 4.5 |
Azure HDInsights | - | - | - |
| CVE-2023-36869 | Azure DevOps Server Spoofing Vulnerability | Important | 6.3 |
Azure DevOps | - | - | - |
| CVE-2023-36890 | Microsoft SharePoint Server Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-36891 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-36892 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-36893 | Microsoft Outlook Spoofing Vulnerability | Important | 6.5 |
Microsoft Office Outlook | - | - | - |
| CVE-2023-36894 | Microsoft SharePoint Server Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Office SharePoint | - | - | - |
| CVE-2023-36895 | Microsoft Outlook Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Office Outlook | - | - | - |
| CVE-2023-36896 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2023-36897 | Visual Studio Tools for Office Runtime Spoofing Vulnerability | Important | 6.5 |
Microsoft Office | - | - | - |
| CVE-2023-35388 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-35390 | .NET and Visual Studio Remote Code Execution Vulnerability | Important | 7.8 |
.NET Core | - | - | - |
| CVE-2023-35391 | ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability | Important | 7.5 |
ASP.NET and Visual Studio | - | - | - |
| CVE-2023-38182 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-38181 | Microsoft Exchange Server Spoofing Vulnerability | Important | 8.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-38180 | .NET and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
ASP.NET | Yes | - | - |
| CVE-2023-38178 | .NET Core and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET Core | - | - | - |
| CVE-2023-38176 | Azure Arc-Enabled Servers Elevation of Privilege Vulnerability | Important | 7 |
Azure Arc | - | - | - |
| CVE-2023-38154 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| ADV230004 | Memory Integrity System Readiness Scan Tool Defense in Depth Update | Moderate | - | Memory Integrity System Readiness Scan Tool | - | Yes | - |
| CVE-2023-36769 | Microsoft OneNote Spoofing Vulnerability | Moderate | 5.4 |
Microsoft Office OneNote | - | - | - |
| CVE-2023-36741 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 7.5 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-38158 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Low | 3.1 |
Microsoft Edge (Chromium-based) | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 23 | 6 |
| Elevation of Privilege | 20 | - |
| Spoofing | 13 | - |
| Information Disclosure | 10 | - |
| Denial of Service | 8 | - |
| Security Feature Bypass | 4 | - |
| Defense in Depth | 2 | - |
Affected Products 42
| Product | CVEs | Exploited |
|---|---|---|
| Windows Message Queuing | 11 | - |
| Microsoft Exchange Server | 6 | - |
| Azure HDInsights | 5 | - |
| Windows Kernel | 5 | - |
| Microsoft Edge (Chromium-based) | 4 | - |
| Microsoft Office SharePoint | 4 | - |
| Microsoft Office Visio | 3 | - |
| .NET Core | 2 | - |
| ASP.NET | 2 | 1 |
| Microsoft Office | 2 | 1 |
| Microsoft Office Excel | 2 | - |
| Microsoft Office Outlook | 2 | - |
| Microsoft Teams | 2 | - |
| Windows Cryptographic Services | 2 | - |
| .NET Framework | 1 | - |
| ASP.NET and Visual Studio | 1 | - |
| Azure Arc | 1 | - |
| Azure DevOps | 1 | - |
| Dynamics Business Central Control | 1 | - |
| Memory Integrity System Readiness Scan Tool | 1 | - |
| Microsoft Dynamics | 1 | - |
| Microsoft Office OneNote | 1 | - |
| Microsoft WDAC OLE DB provider for SQL | 1 | - |
| Microsoft Windows Codecs Library | 1 | - |
| Reliability Analysis Metrics Calculation Engine | 1 | - |
| Role: Windows Hyper-V | 1 | - |
| SQL Server | 1 | - |
| Tablet Windows User Interface | 1 | - |
| Windows Bluetooth A2DP driver | 1 | - |
| Windows Cloud Files Mini Filter Driver | 1 | - |
| Windows Common Log File System Driver | 1 | - |
| Windows Defender | 1 | - |
| Windows Fax and Scan Service | 1 | - |
| Windows Group Policy | 1 | - |
| Windows HTML Platform | 1 | - |
| Windows LDAP - Lightweight Directory Access Protocol | 1 | - |
| Windows Mobile Device Management | 1 | - |
| Windows Projected File System | 1 | - |
| Windows Reliability Analysis Metrics Calculation Engine | 1 | - |
| Windows Smart Card | 1 | - |
| Windows System Assessment Tool | 1 | - |
| Windows Wireless Wide Area Network Service | 1 | - |