Patch Tuesday Archive
Patch Tuesday October 2023
Total CVEs
105
Critical
12
Important
91
Exploited
2
Publicly Disclosed
2
All CVEs this month 105
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2023-35349 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Message Queuing | - | - | - |
| CVE-2023-36902 | Windows Runtime Remote Code Execution Vulnerability | Important | 7 |
Windows Client/Server Runtime Subsystem | - | - | - |
| CVE-2023-38171 | Microsoft QUIC Denial of Service Vulnerability | Important | 7.5 |
Microsoft QUIC | - | - | - |
| CVE-2023-36737 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | Important | 7.8 |
Azure | - | - | - |
| CVE-2023-36786 | Skype for Business Remote Code Execution Vulnerability | Important | 7.2 |
Skype for Business | - | - | - |
| CVE-2023-36789 | Skype for Business Remote Code Execution Vulnerability | Important | 7.2 |
Skype for Business | - | - | - |
| CVE-2023-41763 | Skype for Business Elevation of Privilege Vulnerability | Important | 5.3 |
Skype for Business | Yes | Yes | - |
| CVE-2023-41765 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-41766 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | Important | 7.8 |
Client Server Run-time Subsystem (CSRSS) | - | - | - |
| CVE-2023-41770 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-41768 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-41767 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-41771 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-41769 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-41772 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2023-41773 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-41774 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-36732 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2023-36731 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2023-36730 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-36729 | Named Pipe File System Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Named Pipe File System | - | - | - |
| CVE-2023-36728 | Microsoft SQL Server Denial of Service Vulnerability | Important | 5.5 |
SQL Server | - | - | - |
| CVE-2023-36726 | Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability | Important | 7.8 |
Windows IKE Extension | - | - | - |
| CVE-2023-36725 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NT OS Kernel | - | - | - |
| CVE-2023-36724 | Windows Power Management Service Information Disclosure Vulnerability | Important | 5.5 |
Windows Power Management Service | - | - | - |
| CVE-2023-36723 | Windows Container Manager Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Container Manager Service | - | - | - |
| CVE-2023-36722 | Active Directory Domain Services Information Disclosure Vulnerability | Important | 4.4 |
Active Directory Domain Services | - | - | - |
| CVE-2023-36721 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Important | 7 |
Windows Error Reporting | - | - | - |
| CVE-2023-36720 | Windows Mixed Reality Developer Tools Denial of Service Vulnerability | Important | 7.5 |
Windows Mixed Reality Developer Tools | - | - | - |
| CVE-2023-36718 | Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability | Critical | 7.8 |
Windows Virtual Trusted Platform Module | - | - | - |
| CVE-2023-36717 | Windows Virtual Trusted Platform Module Denial of Service Vulnerability | Important | 6.5 |
Windows TPM | - | - | - |
| CVE-2023-36713 | Windows Common Log File System Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows Common Log File System Driver | - | - | - |
| CVE-2023-36712 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2023-36711 | Windows Runtime C++ Template Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Runtime C++ Template Library | - | - | - |
| CVE-2023-36710 | Windows Media Foundation Core Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Media Foundation | - | - | - |
| CVE-2023-36709 | Microsoft AllJoyn API Denial of Service Vulnerability | Important | 7.5 |
Windows AllJoyn API | - | - | - |
| CVE-2023-36707 | Windows Deployment Services Denial of Service Vulnerability | Important | 7.5 |
Windows Deployment Services | - | - | - |
| CVE-2023-36706 | Windows Deployment Services Information Disclosure Vulnerability | Important | 6.5 |
Windows Deployment Services | - | - | - |
| CVE-2023-36704 | Windows Setup Files Cleanup Remote Code Execution Vulnerability | Important | 7.8 |
Windows Setup Files Cleanup | - | - | - |
| CVE-2023-36703 | DHCP Server Service Denial of Service Vulnerability | Important | 7.5 |
Windows DHCP Server | - | - | - |
| CVE-2023-36702 | Microsoft DirectMusic Remote Code Execution Vulnerability | Important | 7.8 |
Windows Microsoft DirectMusic | - | - | - |
| CVE-2023-36701 | Microsoft Resilient File System (ReFS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2023-36698 | Windows Kernel Security Feature Bypass Vulnerability | Important | 4.4 |
Windows Kernel | - | - | - |
| CVE-2023-36697 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Critical | 8 |
Windows Message Queuing | - | - | - |
| CVE-2023-36606 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-36605 | Windows Named Pipe Filesystem Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Named Pipe File System | - | - | - |
| CVE-2023-36603 | Windows TCP/IP Denial of Service Vulnerability | Important | 7.5 |
Windows TCP/IP | - | - | - |
| CVE-2023-36602 | Windows TCP/IP Denial of Service Vulnerability | Important | 7.5 |
Windows TCP/IP | - | - | - |
| CVE-2023-36598 | Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft WDAC ODBC Driver | - | - | - |
| CVE-2023-36596 | Remote Procedure Call Information Disclosure Vulnerability | Important | 7.5 |
Windows Remote Procedure Call | - | - | - |
| CVE-2023-36594 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2023-36593 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36592 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36591 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36590 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36589 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36585 | Windows upnphost.dll Denial of Service Vulnerability | Important | 7.5 |
Windows UPnP Device Host | - | - | - |
| CVE-2023-36584 | Windows Mark of the Web Security Feature Bypass Vulnerability | Important | 5.4 |
Windows Mark of the Web (MOTW) | - | - | - |
| CVE-2023-36583 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36582 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36581 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-36579 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-36578 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36577 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft WDAC OLE DB provider for SQL | - | - | - |
| CVE-2023-36576 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2023-36575 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36574 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36573 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36572 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36571 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36570 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 7.3 |
Windows Message Queuing | - | - | - |
| CVE-2023-36569 | Microsoft Office Elevation of Privilege Vulnerability | Important | 8.4 |
Microsoft Office | - | - | - |
| CVE-2023-36568 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Office | - | - | - |
| CVE-2023-36567 | Windows Deployment Services Information Disclosure Vulnerability | Important | 7.5 |
Windows Deployment Services | - | - | - |
| CVE-2023-36564 | Windows Search Security Feature Bypass Vulnerability | Important | 6.5 |
Microsoft Windows Search Component | - | - | - |
| CVE-2023-36563 | Microsoft WordPad Information Disclosure Vulnerability | Important | 5.5 |
Microsoft WordPad | Yes | Yes | - |
| CVE-2023-36561 | Azure DevOps Server Elevation of Privilege Vulnerability | Important | 7.3 |
Azure DevOps | - | - | - |
| CVE-2023-36557 | PrintHTML API Remote Code Execution Vulnerability | Important | 7.8 |
Windows HTML Platform | - | - | - |
| CVE-2023-36438 | Windows TCP/IP Information Disclosure Vulnerability | Important | 7.5 |
Windows TCP/IP | - | - | - |
| CVE-2023-36435 | Microsoft QUIC Denial of Service Vulnerability | Important | 7.5 |
Microsoft QUIC | - | - | - |
| CVE-2023-36434 | Windows IIS Server Elevation of Privilege Vulnerability | Important | 9.8 |
Windows IIS | - | - | - |
| CVE-2023-36433 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Dynamics | - | - | - |
| CVE-2023-36431 | Microsoft Message Queuing Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2023-36429 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Dynamics | - | - | - |
| CVE-2023-36420 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-36419 | Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability | Important | 9.8 |
Azure | - | - | - |
| CVE-2023-36417 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-36415 | Azure Identity SDK Remote Code Execution Vulnerability | Important | 8.8 |
Azure SDK | - | - | - |
| CVE-2023-36414 | Azure Identity SDK Remote Code Execution Vulnerability | Important | 8.8 |
Azure SDK | - | - | - |
| CVE-2023-36559 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 4.2 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-38166 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Layer 2 Tunneling Protocol | - | - | - |
| CVE-2023-38159 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Graphics Component | - | - | - |
| CVE-2023-36785 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2023-36780 | Skype for Business Remote Code Execution Vulnerability | Important | 7.2 |
Skype for Business | - | - | - |
| CVE-2023-36778 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8 |
Microsoft Exchange Server | - | - | - |
| CVE-2023-36776 | Win32k Elevation of Privilege Vulnerability | Important | 7 |
Windows Win32K | - | - | - |
| CVE-2023-36790 | Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows RDP | - | - | - |
| CVE-2023-36743 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2023-36566 | Microsoft Common Data Model SDK Denial of Service Vulnerability | Important | 6.5 |
Microsoft Common Data Model SDK | - | - | - |
| CVE-2023-36565 | Microsoft Office Graphics Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Office | - | - | - |
| CVE-2023-36436 | Windows MSHTML Platform Remote Code Execution Vulnerability | Important | 7.8 |
Windows HTML Platform | - | - | - |
| CVE-2023-36418 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | Important | 7.8 |
Azure Real Time Operating System | - | - | - |
| CVE-2023-36416 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 6.1 |
Microsoft Dynamics | - | - | - |
| CVE-2023-36409 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Moderate | 6.5 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2023-29348 | Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability | Important | 7.5 |
Windows RDP | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 45 | 12 |
| Elevation of Privilege | 26 | - |
| Denial of Service | 16 | - |
| Information Disclosure | 13 | - |
| Security Feature Bypass | 3 | - |
| Spoofing | 2 | - |
Affected Products 49
| Product | CVEs | Exploited |
|---|---|---|
| Windows Message Queuing | 20 | - |
| Windows Layer 2 Tunneling Protocol | 9 | - |
| SQL Server | 5 | - |
| Windows Win32K | 5 | - |
| Skype for Business | 4 | 1 |
| Microsoft Dynamics | 3 | - |
| Microsoft Office | 3 | - |
| Windows Deployment Services | 3 | - |
| Windows Kernel | 3 | - |
| Windows TCP/IP | 3 | - |
| Azure | 2 | - |
| Azure SDK | 2 | - |
| Microsoft Edge (Chromium-based) | 2 | - |
| Microsoft Graphics Component | 2 | - |
| Microsoft QUIC | 2 | - |
| Windows HTML Platform | 2 | - |
| Windows Named Pipe File System | 2 | - |
| Windows RDP | 2 | - |
| Active Directory Domain Services | 1 | - |
| Azure DevOps | 1 | - |
| Azure Real Time Operating System | 1 | - |
| Client Server Run-time Subsystem (CSRSS) | 1 | - |
| Microsoft Common Data Model SDK | 1 | - |
| Microsoft Exchange Server | 1 | - |
| Microsoft WDAC ODBC Driver | 1 | - |
| Microsoft WDAC OLE DB provider for SQL | 1 | - |
| Microsoft Windows Media Foundation | 1 | - |
| Microsoft Windows Search Component | 1 | - |
| Microsoft WordPad | 1 | 1 |
| Windows AllJoyn API | 1 | - |
| Windows Client/Server Runtime Subsystem | 1 | - |
| Windows Common Log File System Driver | 1 | - |
| Windows Container Manager Service | 1 | - |
| Windows DHCP Server | 1 | - |
| Windows Error Reporting | 1 | - |
| Windows IIS | 1 | - |
| Windows IKE Extension | 1 | - |
| Windows Mark of the Web (MOTW) | 1 | - |
| Windows Microsoft DirectMusic | 1 | - |
| Windows Mixed Reality Developer Tools | 1 | - |
| Windows NT OS Kernel | 1 | - |
| Windows Power Management Service | 1 | - |
| Windows Remote Procedure Call | 1 | - |
| Windows Resilient File System (ReFS) | 1 | - |
| Windows Runtime C++ Template Library | 1 | - |
| Windows Setup Files Cleanup | 1 | - |
| Windows TPM | 1 | - |
| Windows UPnP Device Host | 1 | - |
| Windows Virtual Trusted Platform Module | 1 | - |