The Windows October 2023 security updates fix three 0-day vulnerabilities
#1
Information 
Quote:The Windows Security Updates for October 2023 are now available. It is a big update for a number of reasons. First, because several Windows products have reached end of support. Second, because the update for Windows 11 includes new features, including Windows Copilot and the new Windows Backup app, that will be available to users of the operating system.

Our overview focuses on the security patches that Microsoft released for Windows. It is a monthly analysis of the Microsoft Patch Day that begins with an executive summary. A list of Windows products follows that lists how each version is affected by this month's security updates.

The guide lists other security and non security updates, links to official support websites and resources, and includes links to direct downloads and other download options.

You may check out the overview for September 2023 here.

Microsoft Windows Security Updates: October 2023

[Image: windows-updates-october-2023.png]

Here is a link to an Excel spreadsheet that lists information about the released security updates on the October 2023 Microsoft Patch Day. Activate the following link to download an archive file that contains the spreadsheet: windows-security-updates-october-2023

Executive Summary
  • Windows 11 version 21H2 is no longer supported. Upgrades to Windows 11 version 22H2 are available.
  • Windows Server 2012 and 2012 R2 have reached end of support today. Microsoft won't release security updates for these Server versions anymore, unless organizations purchase Extended Security Updates subscriptions or migrate their servers to Azure. Microsoft guarantees three years of additional security updates in this year.
  • Microsoft fixed 103 unique vulnerabilities in Microsoft products as well as two vulnerabilities in non-Microsoft products on this Patch Tuesday.
  • Windows clients have no known issues according to Microsoft.
  • Windows Server clients 2008, 2008 R2 and 2022 affected by known issues.
Each supported version of Windows and their critical vulnerabilities are listed below.
  • Windows 10 version 22H2: 73 vulnerabilities, 12 critical and 61 important.
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-38166
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41765
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41767
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41768
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41769
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41770
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41771
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41773
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41774
    • Microsoft Message Queuing Remote Code Execution Vulnerability -- CVE-2023-35349
    • Microsoft Message Queuing Remote Code Execution Vulnerability -- CVE-2023-36697
    • Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability -- CVE-2023-36718
  • Windows 11 version 21H2:  75 vulnerabilities, 12 critical and 63 important
    • same as Windows 10 version 22H2
  • Windows 11 version 22H2:  75 vulnerabilities, 12 critical and 63 important
    • same as Windows 10 version 22H2
Windows Server products
  • Windows Server 2008 R2 (extended support only): 56 vulnerabilities: 11 critical and 45 important
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-38166
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41765
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41767
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41768
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41769
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41770
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41771
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41773
    • Layer 2 Tunneling Protocol Remote Code Execution Vulnerability -- CVE-2023-41774
    • Microsoft Message Queuing Remote Code Execution Vulnerability -- CVE-2023-35349
    • Microsoft Message Queuing Remote Code Execution Vulnerability -- CVE-2023-36697
  • Windows Server 2012 R2: 61 vulnerabilities: 11 critical and 50 important
    • Same critical vulnerabilities as Server 2008 R2.
  • Windows Server 2016: 70 vulnerabilities: 12 critical and 58 important
    • Same critical vulnerabilities as Server 2008 R2, plus
    • Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability -- CVE-2023-36718
  • Windows Server 2019: 78 vulnerabilities: 12 critical and 66 important
    • Same critical vulnerabilities as Server 2016
  •  Windows Server 2022: 79 vulnerabilities: 12 critical and 67 important.
    • Same critical vulnerabilities as Server 2016
The three 0-day vulnerabilities are:
  • CVE-2023-36563 -- Microsoft WordPad Information Disclosure Vulnerability
  • CVE-2023-41763 -- Skype for Business Elevation of Privilege Vulnerability
  • CVE-2023-44487 -- MITRE: CVE-2023-44487 HTTP/2 Rapid Reset Attack
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Elon Musk brings new competition for You...
X TV, a new streamin...Nicholas — 09:51
Malwarebytes 5.1.10.127
Malwarebytes 5.1.1...harlan4096 — 06:44
Mozilla Thunderbird 130.0
Mozilla Thunderbir...harlan4096 — 06:43
Free Download Manager 6.24.1.5847
Changes in 6.24.1....harlan4096 — 06:42
Sandboxie-Plus 1.14.7
Sandboxie-Plus 1.1...harlan4096 — 06:41

[-]
Birthdays
Today's Birthdays
avatar (34)emyzowa
avatar (45)JustinPrede
Upcoming Birthdays
avatar (37)fapedDow
avatar (47)pohudidere
avatar (39)obudyg
avatar (47)rarinsWax
avatar (24)DianaBrown
avatar (37)eqiduseb
avatar (46)schedZoorb
avatar (40)bgreorasjunior4824
avatar (44)ThomasLYDAY
avatar (39)upakoExapy
avatar (49)diplomasync
avatar (48)Myronjax
avatar (48)skepwHug
avatar (37)RicardoGoase
avatar (41)Edwardgef
avatar (42)Denpokhew
avatar (34)azidony
avatar (39)maskbSleew

[-]
Online Staff
There are no staff members currently online.

>