{"id":2191,"date":"2023-12-12T23:14:00","date_gmt":"2023-12-12T23:14:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update"},"modified":"2023-12-12T23:14:00","modified_gmt":"2023-12-12T23:14:00","slug":"microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/12\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update\/","title":{"rendered":"Microsoft Gives Admins a Reprieve With Lighter-Than-Usual Patch Update"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltb23521e57efb667b\/6578d6177266f1040a626746\/partchtuesday_Below_the_Sky_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In what&#8217;s sure to be a refreshing break for IT and security teams, Microsoft&#8217;s monthly security update for December 2023 contained fewer vulnerabilities for them to address than in recent months.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The update included fixes for a total of 36 vulnerabilities, four of which Microsoft identified as being of critical severity, one as moderate, and the rest as important or medium-severity threats. Eleven of the bugs in the December update \u2014 or more than a third \u2014 are issues that threat actors are more likely to exploit. That&#8217;s a description that Microsoft reserves for bugs that that are likely to be an <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/exploitability-index\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">attractive target for attackers<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and one they could consistently exploit.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The patches that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Dec\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Microsoft released today<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> include one for a vulnerability in an AMD chipset (<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2023-20588\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">CVE-2023-20588<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">) for which a proof-of-concept is publicly available. But for only the second time this year, the December security update contained no actively exploited flaws \u2014 something that usually requires an immediate response.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Early Holiday Gift?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;December&#8217;s Patch Tuesday may seem like an early seasonal gift to security teams with a small number of patches and none reported as exploited in the wild,&#8221; said Kev Breen, senior director of threat research at Immersive Labs. &#8220;But this doesn\u2019t mean anyone should rest easy with a glass of mulled wine.&#8221; He pointed to the relatively highly number of CVEs that Microsoft identified as more likely to be exploited as one reason for diligence, especially given how quickly attackers take advantage of new flaws these days.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Notably, the patch update contains fixes for 10 privilege escalation vulnerabilities, a category of bugs that consistently ranks lower in severity than remote code execution bugs, but which are almost equally dangerous, Breen said. &#8220;Almost every security breach will contain a privilege escalation phase that enables the attacker to gain system-level permissions and disable security tools or deploy other attacks and tools,&#8221; he said.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Bugs to Prioritize in the December Batch<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a break from the usual, security researchers had slightly different takes on what they perceived as the most significant bugs in the latest batch. But one flaw that most agreed is a high-priority issue is <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2023-35628\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">CVE-2023-35628<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a remote code execution bug in the Windows MSHTML platform. Microsoft gave the bug a severity rating of 8.1 out of 10 on the CVSS scale and identified it as an issue that threat actors are more likely to abuse.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Unlike usual cases where viewing the email in the Preview Pane causes the problem, the issue happens earlier this time,&#8221; says Saeed Abbasi, manager of vulnerability and threat research at Qualys. &#8220;The problem occurs as soon as Outlook downloads and handles the email, even before it shows up in the Preview Pane.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He predicts that ransomware gangs will try to take advantage of the flow. &#8220;But exploiting it successfully demands sophisticated memory-shaping techniques, posing a substantial challenge,&#8221; Abbasi adds.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Also heightening the severity of the bug is the fact that MSHTML is a core component of Windows for rendering HTML and other browser-based content. The component is not just a part of browsers but also in applications like Microsoft Office, Outlook, Teams, and Skype, Breen said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Jason Kikta, CISO at Automox, highlighted <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2023-35618\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">CVE-2023-35618<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, an elevation of privilege bug in Microsoft&#8217;s Chromium-based Edge browser, as an issue that organizations need to mitigate on a priority basis. &#8220;This vulnerability is rated as moderate severity, but it&#8217;s not to be ignored,&#8221; Kikta said. &#8220;It could potentially lead to a browser sandbox escape, transforming the normally safe browsing environment of Microsoft Edge into a potential risk.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Microsoft itself gave the bug a CVSS severity rating of 9.6 out of a maximum possible 10. At the same time, the company also assessed the flaw as only a medium-severity vulnerability issue because of the amount of user interaction and required preconditions for an attacker to be able to exploit it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Two out of the seven remote code execution vulnerabilities in the December 2023 update affect the Internet Connection Sharing (ICS) feature in Windows. Both vulnerabilities \u2014 <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2023-35641\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">CVE-2023-35641<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2023-35630\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">CVE-2023-35630<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 have an identical CVSS score of 8.8, though Microsoft identified only the former as a vulnerability that attackers are more likely to target.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;These vulnerabilities share similar characteristics, including an adjacent attack vector, low complexity, low privilege requirements, and no user interaction needed,&#8221; said Mike Walters, president and co-founder of Action1. &#8220;The scope of these attacks is confined to systems on the same network segment as the attacker, meaning they cannot be conducted across multiple networks, such as a WAN.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Two other vulnerabilities that security researchers said were worthy of attention are <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2023-35636\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">CVE-2023-35636<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, an information disclosure flaw in Outlook, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2023-36696\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">CVE-2023-36696<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, an elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Abbasi says CVE-2023-35636 is interesting because it doesn&#8217;t cause problems when a user previews emails. But if misused, it can expose NTLM hashes that hackers could use to pretend to be other users and get deeper into a company&#8217;s network, he adds.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Slight Year-Over-Year Decline<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Satnam Narang, senior staff research engineer at Tenable, described the Mini Filter Drive vulnerability as something that an attacker could exploit post-compromise to elevate privileges. The bug is the sixth such vulnerability that Microsoft has disclosed in this driver, he said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;For 2023, Microsoft patched 909 CVEs, a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.tenable.com\/blog\/microsoft-patch-tuesday-2023-year-in-review\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">slight decline of 0.87% from 2022<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which saw Microsoft patch 917 CVEs,&#8221; Narang said. Of these, 23 were zero-day vulnerabilities that attackers were actively exploiting at the time Microsoft disclosed and issued a patch for them. Over half of the zero-days were elevation of privilege vulnerabilities, he said.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In what&#8217;s sure to be a refreshing break for IT<\/p>\n","protected":false},"author":12,"featured_media":2192,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2191","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?fit=1000%2C667&ssl=1",1000,667,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?fit=1000%2C667&ssl=1",1000,667,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?fit=1000%2C667&ssl=1",1000,667,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?fit=1000%2C667&ssl=1",1000,667,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update.jpg?fit=1000%2C667&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2191","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2191"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2191\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2192"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2191"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2191"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2191"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}