Microsoft's December 2023 Patch Tuesday is a light one: 33 patches, only four of which are deemed critical.
Among the flaws for which exploitation is more likely is CVE-2023-35628, a RCE flaw in Windows MSHTML Platform.
CVE-2023-35636, a flaw in Microsoft Outlook, may allow an attacker to grab NTLM hashes.
The vulnerability has been addressed by Microsoft by making newly created custom connectors that use OAuth 2.0 to authenticate automatically have a per connector redirect URI. But admins must close the hole completely by updating existing custom OAuth 2.0 connectors to do the same before February 17th, 2024, Microsoft urged.
Microsoft has also fixed CVE-2023-20588, a flaw in certain AMD processor models that could result in loss of confidentiality, and CVE-2023-36696, an elevation of privilege vulnerability in the Windows Cloud Files Mini Filter driver.
This Cyber News was published on www.helpnetsecurity.com. Publication date: Tue, 12 Dec 2023 20:43:05 +0000