By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
softwareprosoftwarepro
  • Home
  • A/B Testing Tools
    • Accounting Software
    • Ad Serving & Retargeting Platforms
    • All-in-One Marketing Platforms
    • Applicant Tracking Systems (ATS)
    • Business Intelligence (BI) Tools
    • Cloud Storage Systems
    • Collaboration Tools
    • Content Management(CMS)
    • Corporate Learning Management
  • Agile
    • AI
    • Big Data
    • Cloud
    • Database
    • Devops
    • Integration
    • IoT
    • Java
    • Guest Posting
  • Customer Relationship (CRM)
    • Email Marketing Software
    • Fraud Detection Software
    • Help Desk Software
    • HR Management Software
    • Integration Platform as a Software
    • Marketing Automation Software
    • Network Performance Monitoring
    • Payroll Software
  • Project Management Software
    • SEO Software
    • Social Media Management Tools
    • Talent Intelligence Tools Solutions
    • Talent Management
    • Web Analytics Tools
    • Web and Video Conferencing
    • Workforce Analytics Software
    • Workforce Management Software
  • Accessibility Testing Tools
    • Agile Development Software
    • Augmented Development Platforms
    • Automation Testing Tools
    • Batch Management Software
    • Beta Testing Software
    • Bug Tracking Software
  • More
    • Microservices
    • Open Source
    • Performance
    • Security
    • Web Dev
    • Automotive
    • Business
    • Consumer & Gadgets
    • Electronics & Semiconductors
    • Energy & Green Tech
    • Engineering
    • Hardware
    • Hi Tech & Innovation
    • Internet
    • Machine learning & AI
Search
  • Consumer & Gadgets
  • Electronics & Semiconductors
  • Energy & Green Tech
  • Engineering
  • Hardware
  • Hi Tech & Innovation
  • Internet
  • Machine learning & AI
© 2022 Softwareproz.com/knowledge resources for software developers. All Rights Reserved.
Reading: Microsoft’s latest Patch Tuesday is here – fixes numerous flaws, some ‘critical’
Share
Notification Show More
Latest News
This $399 AMD-based one-eyed PC is one of the wackiest designs I’ve seen in 25 years
Audio Digital Home Gaming Home Cinema Mobile Computing
10 Things to Know When Using SHACL With GraphDB
Agile AI Big Data Cloud Database Devops Integration IoT Java Microservices Open Source Performance Security Web Dev
Top 5 Data Streaming Trends for 2023
Agile AI Big Data Cloud Database Devops Integration IoT Java Microservices Open Source Performance Security Web Dev
How to create custom images with Podman
Amazon Analyst Insights Android Apple Ecommerce
How to clone a GitHub repository: A quick tutorial
Amazon Analyst Insights Android Apple Ecommerce
Aa
softwareprosoftwarepro
Aa
Search
  • Home
  • A/B Testing Tools
    • Accounting Software
    • Ad Serving & Retargeting Platforms
    • All-in-One Marketing Platforms
    • Applicant Tracking Systems (ATS)
    • Business Intelligence (BI) Tools
    • Cloud Storage Systems
    • Collaboration Tools
    • Content Management(CMS)
    • Corporate Learning Management
  • Agile
    • AI
    • Big Data
    • Cloud
    • Database
    • Devops
    • Integration
    • IoT
    • Java
    • Guest Posting
  • Customer Relationship (CRM)
    • Email Marketing Software
    • Fraud Detection Software
    • Help Desk Software
    • HR Management Software
    • Integration Platform as a Software
    • Marketing Automation Software
    • Network Performance Monitoring
    • Payroll Software
  • Project Management Software
    • SEO Software
    • Social Media Management Tools
    • Talent Intelligence Tools Solutions
    • Talent Management
    • Web Analytics Tools
    • Web and Video Conferencing
    • Workforce Analytics Software
    • Workforce Management Software
  • Accessibility Testing Tools
    • Agile Development Software
    • Augmented Development Platforms
    • Automation Testing Tools
    • Batch Management Software
    • Beta Testing Software
    • Bug Tracking Software
  • More
    • Microservices
    • Open Source
    • Performance
    • Security
    • Web Dev
    • Automotive
    • Business
    • Consumer & Gadgets
    • Electronics & Semiconductors
    • Energy & Green Tech
    • Engineering
    • Hardware
    • Hi Tech & Innovation
    • Internet
    • Machine learning & AI
Follow US
  • Consumer & Gadgets
  • Electronics & Semiconductors
  • Energy & Green Tech
  • Engineering
  • Hardware
  • Hi Tech & Innovation
  • Internet
  • Machine learning & AI
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
softwarepro > Blog > Audio > Microsoft’s latest Patch Tuesday is here – fixes numerous flaws, some ‘critical’
AudioDigital HomeGamingHome CinemaMobile Computing

Microsoft’s latest Patch Tuesday is here – fixes numerous flaws, some ‘critical’

Last updated: 2023/03/15 at 1:00 PM
Share
SHARE

Microsoft has just released its cumulative security update for March 2023, casually known as Patch Tuesday. 

In this month’s fix, the company addressed a total of 83 flaws, including nine critical vulnerabilities and two zero-day flaws that are being actively exploited in the wild.

Breaking the patch down, Microsoft said it addressed 21 elevation of privilege issues, 2 security feature bypass flaws, 27 remote code execution vulnerabilities, 4 denial of service flaws, 10 spoofing flaws, and one Microsoft Edge / Chromium flaw.

Fixing zero-days

But perhaps the most important fixes are two zero-day vulnerabilities: flaws that were previously undisclosed and abused without victims knowing how to address them.

This month’s zero-days include CVE-2023-23397, an elevation of privilege vulnerability found in Outlook, and CVE-2023-24880 -a security feature bypass vulnerability found in Windows SmartScreen.

With the Outlook file, threat actors were creating emails that forced the target endpoint to connect to a remote URL and transmit the Windows account’s Net-NTLMv2 hash.

“External attackers could send specially crafted emails that will cause a connection from the victim to an external UNC location of attackers’ control,” Microsoft explained.

“This will leak the Net-NTLMv2 hash of the victim to the attacker who can then relay this to another service and authenticate as the victim.” The company added, saying that a known threat actor STRONTIUM was abusing this flaw.

Read more

> The first Microsoft Patch Tuesday of 2023 includes some rather important fixes

> Microsoft’s latest Patch Tuesday broke some VMs, but there’s a fix

> These are the best malware removal tools at the moment

The second zero-day, found in Windows SmartScreen, allowed hackers to bypass the Windows Mark of the Web warning. When a file is downloaded from the internet, it gets a “mark of the web” signaling that it might potentially be malicious.

“An attacker can craft a malicious file that would evade Mark of the Web (MOTW) defenses, resulting in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging,” Microsoft said.

Check out the best web browsers right now

You Might Also Like

This $399 AMD-based one-eyed PC is one of the wackiest designs I’ve seen in 25 years

Framework’s DIY laptop shames Apple and Microsoft with its upgradable CPU and makes me excited for the future

Insta360 teases new challenger for DJI’s class-leading smartphone gimbal

A new Python info-stealing malware is using Unicode to stay undetected

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share this Article
Facebook Twitter Copy Link Print
Share
Previous Article Propeller advance paves way for quiet, efficient electric aviation
Next Article Fitbit gives away some of its best Premium features for free – and it’s about time
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow
banner banner
Create an Amazing Newspaper
Discover thousands of options, easy to customize layouts, one-click to import demo and much more.
Learn More

Latest News

This $399 AMD-based one-eyed PC is one of the wackiest designs I’ve seen in 25 years
Audio Digital Home Gaming Home Cinema Mobile Computing
10 Things to Know When Using SHACL With GraphDB
Agile AI Big Data Cloud Database Devops Integration IoT Java Microservices Open Source Performance Security Web Dev
Top 5 Data Streaming Trends for 2023
Agile AI Big Data Cloud Database Devops Integration IoT Java Microservices Open Source Performance Security Web Dev
How to create custom images with Podman
Amazon Analyst Insights Android Apple Ecommerce
//

We influence 20 million users and is the number one business and technology news network on the planet

Quick Link

  • Audio
  • Digital Home
  • Emerging Technology
  • Enterprise Application
  • Gaming
  • Mobile and Wireless
  • Networking
  • Operating System
  • Photography Video Capture

Blog Categories

  • Environment
  • Health
  • science
  • Technology
  • Amazon
  • Analyst Insights
  • Android
  • Apple
  • Ecommerce

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!
softwareprosoftwarepro
Follow US

© 2022 Software Pro News Network. Software Pro Design Company. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Register Lost your password?