“Of the 33 vulnerabilities patched this month, 11 vulnerabilities are rated as Exploitation More Likely according to Microsoft. Nearly three-quarters of these flaws are elevation of privilege vulnerabilities, followed by remote code execution flaws at 18.2%. Typically, remote execution flaws get the most attention due to their impact, but elevation of privilege vulnerabilities are extremely valuable to attackers as they are often leveraged by advanced persistent threat (APT) actors and by determined cybercriminals seeking to elevate privileges as part of post-compromise activity.
“CVE-2023-35636 is an information disclosure vulnerability in Microsoft Outlook. An attacker could exploit this flaw by convincing a potential victim to open a specially crafted file that could be delivered via email or hosted on a malicious website. What makes this one stand out is that exploitation of this flaw would lead to the disclosure of NTLM hashes, which could be leveraged as part of an NTLM relay attackIt is reminiscent of CVE-2023-23397, an elevation of privilege vulnerability in Microsoft Outlook that was exploited in the wild as a zero day and patched in the March 2023 Patch Tuesday release. However, unlike CVE-2023-23397, CVE-2023-35636 is not exploitable via Microsoft’s Preview Pane, which lowers the severity of this flaw.
“CVE-2023-36696 is an elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver. An attacker could exploit this vulnerability as part of post-compromise to elevate privileges to SYSTEM. It’s the sixth elevation of privilege vulnerability discovered in this driver in 2023. Last month, Microsoft patched CVE-2023-36036, a separate elevation of privilege flaw in the same driver that was exploited in the wild as a zero day.
“For 2023, Microsoft patched 909 CVEs, a slight decline of 0.87% from 2022, which saw Microsoft patch 917 CVEs. Severity wise, the majority of vulnerabilities in 2023 were rated as important, accounting for 90% of all CVEs patched, followed by critical at 9.6%. In 2023, Microsoft released patches for 23 zero-day vulnerabilities. Of the 23 zero-day vulnerabilities patched this year, over half (52.2%) were elevation of privilege flaws.” – Satnam Narang, Senior Staff Research Engineer, Tenable
More Stories
Aditya Birla Fashion Ranked India’s 1 and World’s 3 Most Sustainable Retail Company
Mumbai, Jan 19: Aditya Birla Fashion continues to solidify its position as a global leader in sustainable business practices. In...
RR Kabel announces the winners of Kabel Star Season 4 Celebrates four years of the scholarship program worth INR4 Crore
New Delhi, Jan 19: RR Kabel, one of India’s leading consumer electrical and wire and cable manufacturers, announced the national winners of the Kabel Star Scholarship Program 2025,...
Excelsoft and ASEAMETRICS Partner with the Civil Service Commission of the Philippines to Deliver CSC Civil Service Digital Examination (CSC DeX)
Mysore, Jan 19: Excelsoft Technologies Limited(“Excelsoft Technologies”), in partnership with its Philippine partner ASEAMETRICS, will deliver the Civil Service Commission of the Philippines’ Civil Service Digital Examination (CSC DeX) beginning in 2026, supporting the Commission’s nationwide shift to secure, technology-enabled assessments.The partnership...
Professional Housekeepers Association and Karnataka Pest Management Association Sign MoU at ‘Housekeeping Synergy 3.0’
Bengaluru, Jan 19: In a significant step towards strengthening industry collaboration and enhancing hygiene standards, the Professional Housekeepers Association (PHA)...
Celebrate Republic Day with a Desi Brunch at Novotel Hyderabad Convention Centre
Honour the spirit of India’s Republic Day with a vibrant and indulgent Republic Day Brunch at Food Exchange, Novotel Hyderabad...
FIGSI Announces New Leadership for 2026 – 2028 Term
Bangalore, Jan 19: The Federation of Indian Granite and Stone Industry (FIGSI) has announced its newly elected office bearers for...
