Microsoft December 2023 Security Updates

Discussion in 'Software' started by NICK ADSL UK, Dec 12, 2023.

Thread Status:
Not open for further replies.
  1. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    December 2023 Security Updates
    This release consists of the following 36 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?
    Windows Media CVE-2023-21740
    Microsoft Edge (Chromium-based) CVE-2023-35618
    Microsoft Office Outlook CVE-2023-35619
    Microsoft Dynamics CVE-2023-35621
    Microsoft Windows DNS CVE-2023-35622
    Azure Connected Machine Agent CVE-2023-35624
    Azure Machine Learning CVE-2023-35625
    Windows MSHTML Platform CVE-2023-35628
    Windows USB Mass Storage Class Driver CVE-2023-35629
    Windows Internet Connection Sharing (ICS) CVE-2023-35630
    Windows Win32K CVE-2023-35631
    Windows Internet Connection Sharing (ICS) CVE-2023-35632
    Windows Kernel CVE-2023-35633
    Microsoft Bluetooth Driver CVE-2023-35634
    Windows Kernel CVE-2023-35635
    Microsoft Office Outlook CVE-2023-35636
    Windows DHCP Server CVE-2023-35638
    Windows ODBC Driver CVE-2023-35639
    Windows Internet Connection Sharing (ICS) CVE-2023-35641
    Windows Internet Connection Sharing (ICS) CVE-2023-35642
    Windows DHCP Server CVE-2023-35643
    Windows Kernel-Mode Drivers CVE-2023-35644
    XAML Diagnostics CVE-2023-36003
    Windows DPAPI (Data Protection Application Programming Interface) CVE-2023-36004
    Windows Telephony Server CVE-2023-36005
    Microsoft WDAC OLE DB provider for SQL CVE-2023-36006
    Microsoft Office Word CVE-2023-36009
    Windows Defender CVE-2023-36010
    Windows Win32K CVE-2023-36011
    Windows DHCP Server CVE-2023-36012
    Microsoft Power Platform Connector CVE-2023-36019
    Microsoft Dynamics CVE-2023-36020
    Windows Local Security Authority Subsystem Service (LSASS) CVE-2023-36391
    Windows Cloud Files Mini Filter Driver CVE-2023-36696
    Microsoft Edge (Chromium-based) CVE-2023-36880
    Microsoft Edge (Chromium-based) CVE-2023-38174
    We are republishing 6 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    Chrome Microsoft Edge (Chromium-based) CVE-2023-6508
    Chrome Microsoft Edge (Chromium-based) CVE-2023-6509
    Chrome Microsoft Edge (Chromium-based) CVE-2023-6510
    Chrome Microsoft Edge (Chromium-based) CVE-2023-6511
    Chrome Microsoft Edge (Chromium-based) CVE-2023-6512
    AMD Chipsets CVE-2023-20588 Yes No No
    Security Update Guide Blog Posts
    Date Blog Post
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide
    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows 7, Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5033369 Windows 11, version 21H2
    5033371 Windows 10, version 1809, Windows Server 2019
    5033372 Windows 10, version 21H2, Windows 10, version 22H2
    5033375 Windows 11, version 22H2, Windows 11, version 23H2
    5033422 Windows Server 2008 (Monthly Rollup)
    5033424 Windows Server 2008 R2 (Security-only update)
    5033427 Windows Server 2008 (Security-only update)
    5033433 Windows Server 2008 R2 (Monthly Rollup)
    Released: Dec 12, 2023
    December 2023 Security Updates - Release Notes - Security Update Guide - Microsoft
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds