Total CVEs

38

Critical

4

Important

30

Exploited

0

Publicly Disclosed

0

All CVEs this month 38

CVE Title Severity CVSS Product Exploited Disclosed Diffed
CVE-2023-36696 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Important 7.8 Windows Cloud Files Mini Filter Driver - - -
CVE-2023-36020 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Important 5.4 Microsoft Dynamics - - -
CVE-2023-36009 Microsoft Word Information Disclosure Vulnerability Important 5.5 Microsoft Office Word - - -
CVE-2023-36011 Win32k Elevation of Privilege Vulnerability Important 7.8 Windows Win32K - - -
CVE-2023-35618 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Moderate 9.6 Microsoft Edge (Chromium-based) - - -
CVE-2023-35625 Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability Important 4.7 Azure Machine Learning - - -
CVE-2023-21740 Windows Media Remote Code Execution Vulnerability Important 7.8 Windows Media - - -
CVE-2023-38174 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Low 4.3 Microsoft Edge (Chromium-based) - - -
CVE-2023-36391 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability Important 7.8 Windows Local Security Authority Subsystem Service (LSASS) - - -
CVE-2023-36019 Microsoft Power Platform Connector Spoofing Vulnerability Critical 7.4 Microsoft Power Platform Connector - - -
CVE-2023-36010 Microsoft Defender Denial of Service Vulnerability Important 7.5 Windows Defender - - -
CVE-2023-36012 DHCP Server Service Information Disclosure Vulnerability Important 5.3 Windows DHCP Server - - -
CVE-2023-36003 XAML Diagnostics Elevation of Privilege Vulnerability Important 7.3 XAML Diagnostics - - -
CVE-2023-36004 Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability Important 7.5 Windows DPAPI (Data Protection Application Programming Interface) - - -
CVE-2023-36005 Windows Telephony Server Elevation of Privilege Vulnerability Important 8.1 Windows Telephony Server - - -
CVE-2023-36006 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Important 8.8 Microsoft WDAC OLE DB provider for SQL - - -
CVE-2023-35638 DHCP Server Service Denial of Service Vulnerability Important 7.5 Windows DHCP Server - - -
CVE-2023-35639 Microsoft ODBC Driver Remote Code Execution Vulnerability Important 8.8 Windows ODBC Driver - - -
CVE-2023-35641 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability Critical 8.8 Windows Internet Connection Sharing (ICS) - - -
CVE-2023-35642 Internet Connection Sharing (ICS) Denial of Service Vulnerability Important 6.5 Windows Internet Connection Sharing (ICS) - - -
CVE-2023-35643 DHCP Server Service Information Disclosure Vulnerability Important 7.5 Windows DHCP Server - - -
CVE-2023-35644 Windows Sysmain Service Elevation of Privilege Important 7.8 Windows Kernel-Mode Drivers - - -
CVE-2023-35628 Windows MSHTML Platform Remote Code Execution Vulnerability Critical 8.1 Windows MSHTML Platform - - -
CVE-2023-35629 Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability Important 6.8 Windows USB Mass Storage Class Driver - - -
CVE-2023-35630 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability Critical 8.8 Windows Internet Connection Sharing (ICS) - - -
CVE-2023-35631 Win32k Elevation of Privilege Vulnerability Important 7.8 Windows Win32K - - -
CVE-2023-35632 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7.8 Windows Internet Connection Sharing (ICS) - - -
CVE-2023-35633 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2023-35634 Windows Bluetooth Driver Remote Code Execution Vulnerability Important 8.8 Microsoft Bluetooth Driver - - -
CVE-2023-35635 Windows Kernel Denial of Service Vulnerability Important 5.5 Windows Kernel - - -
CVE-2023-35636 Microsoft Outlook Information Disclosure Vulnerability Important 6.5 Microsoft Office Outlook - - -
CVE-2023-35619 Microsoft Outlook for Mac Spoofing Vulnerability Important 5.3 Microsoft Office Outlook - - -
CVE-2023-35621 Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability Important 7.5 Microsoft Dynamics - - -
CVE-2023-35622 Windows DNS Spoofing Vulnerability Important 7.5 Microsoft Windows DNS - - -
CVE-2023-35624 Azure Connected Machine Agent Elevation of Privilege Vulnerability Important 7.3 Azure Connected Machine Agent - - -
CVE-2023-36880 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Low 4.8 Microsoft Edge (Chromium-based) - - -
CVE-2023-21751 Azure DevOps Server Spoofing Vulnerability Important 6.5 Azure DevOps - - -
CVE-2023-36878 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability Low 4.3 Microsoft Edge (Chromium-based) - - -

Threat Categories 6

Threat Category CVEs Critical
Elevation of Privilege 11 -
Remote Code Execution 8 3
Information Disclosure 7 -
Spoofing 6 1
Denial of Service 5 -
Security Feature Bypass 1 -

Affected Products 26

Product CVEs Exploited
Microsoft Edge (Chromium-based) 4 -
Windows Internet Connection Sharing (ICS) 4 -
Windows DHCP Server 3 -
Microsoft Dynamics 2 -
Microsoft Office Outlook 2 -
Windows Kernel 2 -
Windows Win32K 2 -
Azure Connected Machine Agent 1 -
Azure DevOps 1 -
Azure Machine Learning 1 -
Microsoft Bluetooth Driver 1 -
Microsoft Office Word 1 -
Microsoft Power Platform Connector 1 -
Microsoft WDAC OLE DB provider for SQL 1 -
Microsoft Windows DNS 1 -
Windows Cloud Files Mini Filter Driver 1 -
Windows DPAPI (Data Protection Application Programming Interface) 1 -
Windows Defender 1 -
Windows Kernel-Mode Drivers 1 -
Windows Local Security Authority Subsystem Service (LSASS) 1 -
Windows MSHTML Platform 1 -
Windows Media 1 -
Windows ODBC Driver 1 -
Windows Telephony Server 1 -
Windows USB Mass Storage Class Driver 1 -
XAML Diagnostics 1 -