Total CVEs

66

Critical

3

Important

57

Exploited

3

Publicly Disclosed

4

All CVEs this month 66

CVE Title Severity CVSS Product Exploited Disclosed Diffed
CVE-2023-36413 Microsoft Office Security Feature Bypass Vulnerability Important 6.5 Microsoft Office - Yes -
CVE-2023-36036 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Important 7.8 Windows Cloud Files Mini Filter Driver Yes - -
CVE-2023-38177 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 6.8 Microsoft Office SharePoint - - -
CVE-2023-36439 Microsoft Exchange Server Remote Code Execution Vulnerability Important 8 Microsoft Exchange Server - - -
CVE-2023-36428 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability Important 5.5 Windows Authentication Methods - - -
CVE-2023-36427 Windows Hyper-V Elevation of Privilege Vulnerability Important 7 Windows Hyper-V - - -
CVE-2023-36425 Windows Distributed File System (DFS) Remote Code Execution Vulnerability Important 8 Windows Distributed File System (DFS) - - -
CVE-2023-36424 Windows Common Log File System Driver Elevation of Privilege Vulnerability Important 7.8 Windows Common Log File System Driver - - -
CVE-2023-36423 Microsoft Remote Registry Service Remote Code Execution Vulnerability Important 8.8 Microsoft Remote Registry Service - - -
CVE-2023-38151 Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability Important 8.8 Azure - - -
CVE-2023-36437 Azure DevOps Server Remote Code Execution Vulnerability Important 8.8 Azure DevOps - - -
CVE-2023-36410 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Important 5.4 Microsoft Dynamics - - -
CVE-2023-36052 Azure CLI REST Command Information Disclosure Vulnerability Critical 8.6 Azure - - -
CVE-2023-36043 Open Management Infrastructure Information Disclosure Vulnerability Important 6.5 Open Management Infrastructure - - -
CVE-2023-36034 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Moderate 7.3 Microsoft Edge (Chromium-based) - - -
CVE-2023-36024 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Important 7.1 Microsoft Edge (Chromium-based) - - -
CVE-2023-36017 Windows Scripting Engine Memory Corruption Vulnerability Important 8.8 Windows Scripting - - -
CVE-2023-36027 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Important 6.3 Microsoft Edge (Chromium-based) - - -
CVE-2023-36007 Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability Important 4.1 Microsoft Dynamics - - -
CVE-2023-36008 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Moderate 6.6 Microsoft Edge (Chromium-based) - - -
CVE-2023-36026 Microsoft Edge (Chromium-based) Spoofing Vulnerability Moderate 4.3 Microsoft Edge (Chromium-based) - - -
CVE-2023-36705 Windows Installer Elevation of Privilege Vulnerability Important 7.8 Windows Installer - - -
CVE-2023-36558 ASP.NET Core Security Feature Bypass Vulnerability Important 5.5 ASP.NET - - -
CVE-2023-36560 ASP.NET Security Feature Bypass Vulnerability Important 8.8 ASP.NET - - -
CVE-2023-36408 Windows Hyper-V Elevation of Privilege Vulnerability Important 7.8 Windows Hyper-V - - -
CVE-2023-36407 Windows Hyper-V Elevation of Privilege Vulnerability Important 7.8 Windows Hyper-V - - -
CVE-2023-36406 Windows Hyper-V Information Disclosure Vulnerability Important 5.5 Windows Hyper-V - - -
CVE-2023-36405 Windows Kernel Elevation of Privilege Vulnerability Important 7 Windows Kernel - - -
CVE-2023-36404 Windows Kernel Information Disclosure Vulnerability Important 5.5 Windows Kernel - - -
CVE-2023-36403 Windows Kernel Elevation of Privilege Vulnerability Important 7 Windows Kernel - - -
CVE-2023-36402 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Important 8.8 Microsoft WDAC OLE DB provider for SQL - - -
CVE-2023-36401 Microsoft Remote Registry Service Remote Code Execution Vulnerability Important 7.2 Microsoft Remote Registry Service - - -
CVE-2023-36400 Windows HMAC Key Derivation Elevation of Privilege Vulnerability Critical 8.8 Windows HMAC Key Derivation - - -
CVE-2023-36399 Windows Storage Elevation of Privilege Vulnerability Important 7.1 Windows Storage - - -
CVE-2023-36398 Windows NTFS Information Disclosure Vulnerability Important 6.5 Windows NTFS - - -
CVE-2023-36397 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Critical 9.8 Windows Internet Connection Sharing (ICS) - - -
CVE-2023-36396 Windows Compressed Folder Remote Code Execution Vulnerability Important 7.8 Windows Compressed Folder - - -
CVE-2023-36395 Windows Deployment Services Denial of Service Vulnerability Important 7.5 Windows Deployment Services - - -
CVE-2023-36394 Windows Search Service Elevation of Privilege Vulnerability Important 7 Microsoft Windows Search Component - - -
CVE-2023-36393 Windows User Interface Application Core Remote Code Execution Vulnerability Important 7.8 Tablet Windows User Interface - - -
CVE-2023-36392 DHCP Server Service Denial of Service Vulnerability Important 7.5 Windows DHCP Server - - -
CVE-2023-36046 Windows Authentication Denial of Service Vulnerability Important 7.1 Windows Authentication Methods - - -
CVE-2023-36047 Windows Authentication Elevation of Privilege Vulnerability Important 7.8 Windows Authentication Methods - - -
CVE-2023-36049 .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability Important 9.8 .NET Framework - - -
CVE-2023-36050 Microsoft Exchange Server Spoofing Vulnerability Important 8 Microsoft Exchange Server - - -
CVE-2023-36039 Microsoft Exchange Server Spoofing Vulnerability Important 8 Microsoft Exchange Server - - -
CVE-2023-36041 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2023-36042 Visual Studio Denial of Service Vulnerability Important 5.5 Visual Studio - - -
CVE-2023-36045 Microsoft Office Graphics Remote Code Execution Vulnerability Important 7.8 Microsoft Office - - -
CVE-2023-36037 Microsoft Excel Security Feature Bypass Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2023-36038 ASP.NET Core Denial of Service Vulnerability Important 7.5 ASP.NET - Yes -
CVE-2023-36035 Microsoft Exchange Server Spoofing Vulnerability Important 8 Microsoft Exchange Server - - -
CVE-2023-36029 Microsoft Edge (Chromium-based) Spoofing Vulnerability Moderate 4.3 Microsoft Edge (Chromium-based) - - -
CVE-2023-36030 Microsoft Dynamics 365 Sales Spoofing Vulnerability Important 6.1 Microsoft Dynamics 365 Sales - - -
CVE-2023-36031 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Important 5.4 Microsoft Dynamics - - -
CVE-2023-36033 Windows DWM Core Library Elevation of Privilege Vulnerability Important 7.8 Windows DWM Core Library Yes Yes Yes
CVE-2023-36021 Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability Important 8 Azure - - -
CVE-2023-36022 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Moderate 6.6 Microsoft Edge (Chromium-based) - - -
CVE-2023-36028 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability Important 9.8 Windows Protected EAP (PEAP) - - -
CVE-2023-36025 Windows SmartScreen Security Feature Bypass Vulnerability Important 8.8 Windows SmartScreen Yes Yes -
CVE-2023-36422 Microsoft Windows Defender Elevation of Privilege Vulnerability Important 7.8 Windows Defender - - -
CVE-2023-36016 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Important 3.4 Microsoft Dynamics - - -
CVE-2023-36018 Visual Studio Code Jupyter Extension Spoofing Vulnerability Important 9.8 Visual Studio Code - - -
CVE-2023-36014 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Moderate 7.3 Microsoft Edge (Chromium-based) - - -
CVE-2023-36013 PowerShell Information Disclosure Vulnerability Important 6.5 Microsoft PowerShell - - -
CVE-2023-36719 Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability Important 7.8 Microsoft Windows Speech - - -

Threat Categories 6

Threat Category CVEs Critical
Remote Code Execution 19 1
Elevation of Privilege 18 1
Spoofing 11 -
Information Disclosure 7 1
Security Feature Bypass 6 -
Denial of Service 5 -

Affected Products 39

Product CVEs Exploited
Microsoft Edge (Chromium-based) 8 -
Microsoft Dynamics 4 -
Microsoft Exchange Server 4 -
Windows Hyper-V 4 -
ASP.NET 3 -
Azure 3 -
Windows Authentication Methods 3 -
Windows Kernel 3 -
Microsoft Office 2 -
Microsoft Office Excel 2 -
Microsoft Remote Registry Service 2 -
.NET Framework 1 -
Azure DevOps 1 -
Microsoft Dynamics 365 Sales 1 -
Microsoft Office SharePoint 1 -
Microsoft PowerShell 1 -
Microsoft WDAC OLE DB provider for SQL 1 -
Microsoft Windows Search Component 1 -
Microsoft Windows Speech 1 -
Open Management Infrastructure 1 -
Tablet Windows User Interface 1 -
Visual Studio 1 -
Visual Studio Code 1 -
Windows Cloud Files Mini Filter Driver 1 1
Windows Common Log File System Driver 1 -
Windows Compressed Folder 1 -
Windows DHCP Server 1 -
Windows DWM Core Library 1 1
Windows Defender 1 -
Windows Deployment Services 1 -
Windows Distributed File System (DFS) 1 -
Windows HMAC Key Derivation 1 -
Windows Installer 1 -
Windows Internet Connection Sharing (ICS) 1 -
Windows NTFS 1 -
Windows Protected EAP (PEAP) 1 -
Windows Scripting 1 -
Windows SmartScreen 1 1
Windows Storage 1 -