{"id":1745,"date":"2023-08-09T06:43:45","date_gmt":"2023-08-09T06:43:45","guid":{"rendered":"https:\/\/cert-mu.govmu.org\/cert-mu\/?page_id=1745"},"modified":"2023-08-09T07:03:01","modified_gmt":"2023-08-09T07:03:01","slug":"multiple-microsoft-zero-day-vulnerabilities-exploited-in-the-wild","status":"publish","type":"page","link":"https:\/\/cert-mu.govmu.org\/cert-mu\/?page_id=1745","title":{"rendered":"Multiple Microsoft Zero-Day Vulnerabilities Exploited in the Wild"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"1745\" class=\"elementor elementor-1745\" data-elementor-post-type=\"page\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-166eefda ct-section-stretched elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"166eefda\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t\t<div class=\"elementor-background-overlay\"><\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-314d1d\" data-id=\"314d1d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-514ff558 elementor-hidden-tablet elementor-hidden-phone\" data-id=\"514ff558\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4e3e8fb elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4e3e8fb\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-93566b9\" data-id=\"93566b9\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d08b013 elementor-widget elementor-widget-heading\" data-id=\"d08b013\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Multiple Microsoft Zero-Day Vulnerabilities Exploited in the Wild<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7d0347e elementor-widget elementor-widget-text-editor\" data-id=\"7d0347e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>CERT-MU Vulnerability Note VN-2023-07<\/strong><br \/><br \/><strong>Date of Issue: 12.07.2023<\/strong><br \/><br \/><strong>Severity Rating: High<\/strong><br \/><br \/><strong>Affected Products:<\/strong><br \/>\uf0b7 Microsoft Windows Server 2016<br \/>\uf0b7 Microsoft Windows Server 2019<br \/>\uf0b7 Microsoft Windows 10 1809 for x64-based Systems<br \/>\uf0b7 Microsoft Windows 10 1809 for 32-bit Systems<br \/>\uf0b7 Microsoft Windows 10 1809 for ARM64-based Systems<br \/>\uf0b7 Microsoft Windows 10 1607 for 32-bit Systems<br \/>\uf0b7 Microsoft Windows 10 1607 for x64-based Systems<br \/>\uf0b7 Microsoft Windows Server (Server Core installation) 2019<br \/>\uf0b7 Microsoft Windows Server (Server Core installation) 2016<br \/>\uf0b7 Microsoft Windows Server 2022<br \/>\uf0b7 Microsoft Windows Server (Server Core installation) 2022<br \/>\uf0b7 Microsoft Windows 10 21H2 for 32-bit Systems<br \/>\uf0b7 Microsoft Windows 10 21H2 for ARM64-based Systems<br \/>\uf0b7 Microsoft Windows 10 21H2 for x64-based Systems<br \/>\uf0b7 Microsoft Windows 11 22H2 for ARM64-based Systems<br \/>\uf0b7 Microsoft Windows 11 22H2 for x64-based Systems<br \/>\uf0b7 Microsoft Windows 10 22H2 for 32-bit Systems<br \/>\uf0b7 Microsoft Windows 10 22H2 for ARM64-based Systems<br \/>\uf0b7 Microsoft Windows 10 22H2 for x64-based Systems<br \/>\uf0b7 Microsoft Windows 11 21H2 for ARM64-based Systems<br \/>\uf0b7 Microsoft Windows 11 21H2 for x64-based Systems<br \/>\uf0b7 Microsoft Outlook 2016 x32<br \/>\uf0b7 Microsoft Outlook 2016 x64<br \/><br \/><strong>Description<\/strong><br \/>Microsoft Windows could allow a remote attacker to bypass security restrictions, caused by a<br \/>flaw in the SmartScreen component. By persuading a victim to click on a specially crafted URL,<br \/>an attacker could exploit this vulnerability to bypass the Open File \u2013 Security Warning prompt.<br \/><br \/>Microsoft Windows and Microsoft Office could allow a remote attacker to execute arbitrary code<br \/>on the system. By persuading a victim to open a specially crafted file, an attacker could exploit<br \/>this vulnerability to execute arbitrary code on the system.<br \/><br \/><strong>Solution<\/strong><br \/>Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft<br \/>Security Update Guide to search for available patches.<br \/><br \/><strong>CVE Information<\/strong><br \/>\uf0b7\u00a0<a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2023-32049\">CVE-2023-32049 CVSS:8.8<\/a><br \/>\uf0b7\u00a0<a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2023-35311\">CVE-2023-35311 CVSS:8.8<\/a><br \/>\uf0b7\u00a0<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-36884\">CVE-2023-36884 CVSS:8.3<\/a><br \/>\uf0b7\u00a0<a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2023-36874\">CVE-2023-36874 CVSS:7.8<\/a><br \/>\uf0b7\u00a0<a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2023-32046\">CVE-2023-32046 CVSS:7.8<\/a><br \/><br \/><strong>References<\/strong><br \/>\uf0b7\u00a0<a href=\"https:\/\/www.tenable.com\/cve\/CVE-2023-32049\">https:\/\/www.tenable.com\/cve\/CVE-2023-32049<\/a><br \/>\uf0b7\u00a0<a href=\"https:\/\/www.tenable.com\/cve\/CVE-2023-35311\">https:\/\/www.tenable.com\/cve\/CVE-2023-35311<\/a><br \/>\uf0b7\u00a0<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-36874\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-36874<\/a><br \/>\uf0b7\u00a0<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-32046\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-32046<\/a><br \/><br \/><strong>Report Cyber Incidents<\/strong><br \/>Report cyber security incident on the Mauritian Cybercrime Online Reporting System (MAUCORS \u2013<br \/>http:\/\/maucors.govmu.org\/)<br \/><br \/><strong>Contact Information<\/strong><br \/>Computer Emergency Response Team of Mauritius (CERT-MU)<br \/>Ministry of Information Technology, Communication and Innovation<br \/>Tel: (+230) 4602600<br \/>Hotline No: (+230) 800 2378<br \/>Gen. Info. : contact@cert.govmu.org<br \/>Incident: incident@cert.govmu.org<br \/>Website: http:\/\/cert-mu.govmu.org<br \/>MAUCORS: http:\/\/maucors.govmu.org<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Multiple Microsoft Zero-Day Vulnerabilities Exploited in the Wild CERT-MU Vulnerability Note VN-2023-07 Date of Issue: 12.07.2023 Severity Rating: High Affected Products:\uf0b7 Microsoft Windows Server 2016\uf0b7 Microsoft Windows Server 2019\uf0b7 Microsoft Windows 10 1809 for x64-based Systems\uf0b7 Microsoft Windows 10 1809 for 32-bit Systems\uf0b7 Microsoft Windows 10 1809 for ARM64-based Systems\uf0b7 Microsoft Windows 10 1607 for 32-bit Systems\uf0b7 Microsoft Windows 10 1607 for x64-based Systems\uf0b7 Microsoft Windows Server (Server Core installation) 2019\uf0b7 Microsoft Windows Server (Server Core installation) 2016\uf0b7 Microsoft Windows Server 2022\uf0b7 Microsoft Windows Server (Server Core installation) 2022\uf0b7 Microsoft Windows 10 21H2 for 32-bit Systems\uf0b7 Microsoft Windows 10 21H2\u2026<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1745","page","type-page","status-publish","hentry"],"blocksy_meta":{"page_title_panel":"","has_hero_section":"disabled","bc159c5af2a03de5c75561ba297140d8":"","hero_section":"type-1","hero_elements":[{"id":"custom_title","enabled":true,"heading_tag":"h1","title":"Home"},{"id":"custom_description","enabled":true,"description_visibility":{"desktop":true,"tablet":true,"mobile":false}},{"id":"custom_meta","enabled":false,"meta_elements":[{"id":"author","enabled":true,"label":"By","has_author_avatar":"yes","avatar_size":25},{"id":"post_date","enabled":true,"label":"On","date_format_source":"default","date_format":"M j, Y"},{"id":"comments","enabled":true}],"page_meta_elements":{"joined":true,"articles_count":true,"comments":true}},{"id":"breadcrumbs","enabled":false}],"df3eb590217e0ce26e832da2c07e7ca6":"","hero_alignment1":"left","hero_alignment2":"center","hero_vertical_alignment":"center","19d24a625abe62e6d16b259439e9cba0":"","hero_structure":"narrow","a3dd00aea12a8c52bdc0775015a386ce":"","page_title_bg_type":"featured_image","custom_hero_background":{"attachment_id":null},"parallax":{"desktop":false,"tablet":false,"mobile":false},"007fc1b0d7d7ea0d9823538a36652bf9":"","hero_height":"250px","pageTitleFont":{"family":"Default","variation":"Default","size":{"desktop":"32px","tablet":"30px","mobile":"25px"},"line-height":"CT_CSS_SKIP_RULE","letter-spacing":"CT_CSS_SKIP_RULE","text-transform":"CT_CSS_SKIP_RULE","text-decoration":"CT_CSS_SKIP_RULE"},"pageTitleFontColor":{"default":{"color":"CT_CSS_SKIP_RULEDEFAULT"}},"pageMetaFont":{"family":"Default","variation":"n6","size":"12px","line-height":"1.3","letter-spacing":"CT_CSS_SKIP_RULE","text-transform":"uppercase","text-decoration":"CT_CSS_SKIP_RULE"},"pageMetaFontColor":{"default":{"color":"CT_CSS_SKIP_RULEDEFAULT"},"hover":{"color":"CT_CSS_SKIP_RULEDEFAULT"}},"pageExcerptFont":{"family":"Default","variation":"Default","size":"CT_CSS_SKIP_RULE","line-height":"CT_CSS_SKIP_RULE","letter-spacing":"CT_CSS_SKIP_RULE","text-transform":"CT_CSS_SKIP_RULE","text-decoration":"CT_CSS_SKIP_RULE"},"pageExcerptColor":{"default":{"color":"CT_CSS_SKIP_RULEDEFAULT"}},"breadcrumbsFont":{"family":"Default","variation":"n6","size":"12px","line-height":"CT_CSS_SKIP_RULE","letter-spacing":"CT_CSS_SKIP_RULE","text-transform":"uppercase","text-decoration":"CT_CSS_SKIP_RULE"},"breadcrumbsFontColor":{"default":{"color":"CT_CSS_SKIP_RULEDEFAULT"},"initial":{"color":"CT_CSS_SKIP_RULEDEFAULT"},"hover":{"color":"CT_CSS_SKIP_RULEDEFAULT"}},"pageTitleOverlay":{"default":{"color":"rgba(41, 51, 60, 0.2)"}},"pageTitleBackground":{"background_type":"color","background_pattern":"type-1","background_image":{"attachment_id":null,"x":0,"y":0},"background_repeat":"no-repeat","background_size":"auto","background_attachment":"scroll","patternColor":{"default":{"color":"#e5e7ea"}},"backgroundColor":{"default":{"color":"#EDEFF2"}}},"806cf646dc975203c3ef573b498d2a6c":"","page_structure_type":"default","content_style":"inherit","vertical_spacing_source":"custom","content_area_spacing":"none","background":{"background_type":"color","background_pattern":"type-1","background_image":{"attachment_id":null,"x":0,"y":0},"background_repeat":"no-repeat","background_size":"auto","background_attachment":"scroll","patternColor":{"default":{"color":"#e5e7ea"}},"backgroundColor":{"default":{"color":"CT_CSS_SKIP_RULE"}}},"content_background":{"background_type":"color","background_pattern":"type-1","background_image":{"attachment_id":null,"x":0,"y":0},"background_repeat":"no-repeat","background_size":"auto","background_attachment":"scroll","patternColor":{"default":{"color":"#e5e7ea"}},"backgroundColor":{"default":{"color":"#ffffff"}}},"content_boxed_spacing":{"desktop":"40px","tablet":"35px","mobile":"20px"},"content_boxed_radius":{"top":"3px","bottom":"3px","left":"3px","right":"3px","linked":true},"content_boxed_shadow":{"blur":18,"spread":-6,"v_offset":12,"h_offset":0,"inset":false,"enable":true,"color":{"color":"rgba(34, 56, 101, 0.04)"}},"19c6ff9349ac0932d7247f0e755658ea":"","disable_featured_image":"no","disable_header":"no","disable_footer":"no","styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[]}},"_links":{"self":[{"href":"https:\/\/cert-mu.govmu.org\/cert-mu\/index.php?rest_route=\/wp\/v2\/pages\/1745","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cert-mu.govmu.org\/cert-mu\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/cert-mu.govmu.org\/cert-mu\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/cert-mu.govmu.org\/cert-mu\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cert-mu.govmu.org\/cert-mu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1745"}],"version-history":[{"count":4,"href":"https:\/\/cert-mu.govmu.org\/cert-mu\/index.php?rest_route=\/wp\/v2\/pages\/1745\/revisions"}],"predecessor-version":[{"id":1779,"href":"https:\/\/cert-mu.govmu.org\/cert-mu\/index.php?rest_route=\/wp\/v2\/pages\/1745\/revisions\/1779"}],"wp:attachment":[{"href":"https:\/\/cert-mu.govmu.org\/cert-mu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1745"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}