Microsoft ended the year with a relatively light patch-load, issuing updates for 34 vulnerabilities including one zero-day first reported back in August.
Microsoft addressed the vulnerability in its Patch Tuesday update round, as the latest Windows versions enable mitigation and protection.
Elsewhere, there were only four critical vulnerabilities listed by Microsoft this month.
CVE-2023-35628 is a Windows MSHTML Platform remote code execution vulnerability with a CVSS score of 8.1.
CVE-2023-35641 and CVE-2023-35630 are two critical RCE bugs in Internet Connection Sharing, both of which have a CVSS score of 8.8.
Finally, CVE-2023-36019 is a critical flaw in the Microsoft Power Platform.
It enables an attacker to deceive a user by making a malicious link or file look like a legitimate one.
It's also low in complexity and does not require system privileges, which is why its CVSS score is 9.6..
This Cyber News was published on www.infosecurity-magazine.com. Publication date: Wed, 13 Dec 2023 10:30:19 +0000