Almost 100 fixes released

computing

(Image credit: Microsoft)

The first Patch Tuesday of 2023 is here, with Microsoft putting in quite the effort to start the year on a high note. 

In total, the Redmond software giant unveiled fixes for 98 security flaws, including generally known vulnerabilities, as well as those being abused in the wild. 

Almost a dozen (11) have been rated “critical” as they allow threat actors to remotely execute malicious code.

Fixes to Microsoft Exchange servers

The flaw that hackers are currently exploiting is CVE-2023-21674, a Windows advanced local procedure call (ALPC) elevation of privilege vulnerability that allows threat actors to gain SYSTEM privileges. This one has a severity score of 8.8.

Another vulnerability with an 8.8 severity score is CVE-2023-21549, a Windows SMB Witness Service elevation of privilege vulnerability that allows attackers to execute RPC functions usually reserved for privileged accounts. 

“To exploit this vulnerability, an attacker could execute a specially crafted malicious script which executes an RPC call to an RPC host,” the security alert reads. 

The list of fixed vulnerabilities is quite long, but a few other notable mentions include CVE-2023-21743, a Microsoft SharePoint Server security feature bypass vulnerability that allows threat actors to bypass the expected user access as an unauthenticated user, CVE-2023-21762 and CVE-2023-21745 (spoofing vulnerabilities in Microsoft Exchange servers), and CVE-2023-21763 and CVE-2023-21764 (elevation of privilege flaws in Exchange servers).

Read more

> Microsoft’s latest Patch Tuesday broke some VMs, but there’s a fix
> Another Patch Tuesday launch has broken another key Microsoft tool
> Here are the best endpoint protection tools around (opens in new tab)

It’s also worth mentioning that these are the last security updates to ever hit Windows 7 and Windows 8.1. The former has reached the end of its three-year- pay-extra-to-get-extended-security-updates period, while Windows 8.1 simply won’t be getting any, regardless if firms are ready to pay or not. 

“As a reminder, Windows 8.1 will reach end of support on January 10, 2023 [2023-01-10], at which point technical assistance and software updates will no longer be provided,” Microsoft said. “Microsoft will not be offering an Extended Security Update (ESU) program for Windows 8.1. Continuing to use Windows 8.1 after January 10, 2023 may increase an organization’s exposure to security (opens in new tab) risks or impact its ability to meet compliance obligations.”

    Via: The Register (opens in new tab)

    Are you a pro? Subscribe to our newsletter

    Sign up to theTechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    By submitting your information you agree to the Terms & Conditions (opens in new tab) and Privacy Policy (opens in new tab) and are aged 16 or over.

    Sead Fadilpašić

    Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

    TECH NEWS RELATED

    9 Best Ways To Retrieve A Downloaded Movie On Your Laptop

    Watching movies online can be a hassle; Especially when there is a lot of buffering. This is one of the biggest reasons for people to download their movies and watch them offline. However, I found this specific query in a forum where people were asking to recover a downloaded movie ...

    View more: 9 Best Ways To Retrieve A Downloaded Movie On Your Laptop

    How To Snip Screen On Your Laptop?

    Taking a screenshot is not a complicated process. All of us are familiar with at least one way to do it. However, there are several ways to capture your screen for a frame. We made this article to show you all the different ways you can grab your screens. If ...

    View more: How To Snip Screen On Your Laptop?

    How To Connect AirPods To A Laptop?

    The Apple AirPods are, undoubtedly, some of the best earpieces available on the electronics market. With three generations of different AirPods models, these sleek, ivory earphones are quite popular. Apart from the appearance and quality, AirPods are known for being versatile. Irrespective of what the host device is, AirPods can ...

    View more: How To Connect AirPods To A Laptop?

    7 Best Ways To Fix DistributedCOM Error In Windows

    If you open the Event Viewer utility often, you may notice a DistributedCOM Error on Windows. Let’s know what this DistributedCOM Error Windows error is, how it’s caused, and how you can fix it. Contents show 1 What Is the DistributedCOM Error Windows 10 and 11? 2 What is the ...

    View more: 7 Best Ways To Fix DistributedCOM Error In Windows

    12 Easy Fixes For Webcam Not Working In Windows

    Cameras are becoming quite common for PCs. We use meetings on Zoom, Microsoft Teams, Skype, and other options. The operating system might not be at fault if your camera isn’t working. You can use the given solutions to solve the Webcam Not Working Windows issue quickly. We have covered ...

    View more: 12 Easy Fixes For Webcam Not Working In Windows

    Windows 10 Sound Not Working: 18 Quick And Easy Methods

    Is  Windows 10 Sound Not Working on your PC? This is a common issue faced by many Windows users.  If you are one among them, you are in the right place. This article gives you 11 solutions to fix the no-sound issues in Windows 10.  Contents show 1 Reasons For ...

    View more: Windows 10 Sound Not Working: 18 Quick And Easy Methods

    Fix CAA20004 Microsoft Teams Sign in Error

    Microsoft Teams have a bundle of excellent and attractive features that provides you with easy communication among friends, even classes and offices were conducted online. There’s a lot going on in MS Teams, for example, you can chat via messages and video calls, and at the same time share files ...

    View more: Fix CAA20004 Microsoft Teams Sign in Error

    How To Fix This Update Is Not Applicable To Your Computer Error: 11 Quick Fixes

    Windows standalone updates packages are useful when your Windows updater is not working or you want to install a certain update manually. However, running these updated packages, sometimes, shows the error message “This update is not applicable to your computer” or “This update is not applicable to your computer”. ...

    View more: How To Fix This Update Is Not Applicable To Your Computer Error: 11 Quick Fixes

    Windows Dual Boot Menu Not Showing: 6 Easy Ways To Fix

    12 Best Fixes: Windows 10 Start Menu Search Not Working

    How to customize and publish a Microsoft Bookings page?

    Chic-Fil-A’s Training Program Apparently Features a Familiar Fallout Face

    Microsoft Teams Status not updating or changing

    Don’t Buy a Foldable Until Samsung Brings This Prototype to Life

    Windows Encryption Not Working? 6 Best Ways To Fix

    How to get Apple Calendar on Windows PC

    Windows Update Error 0x80073701: 9 Best Ways To Fix

    Best Ways To Fix Slow Internet During VPN On Windows 11

    6 Solutions To Fix Wmpnetwk High CPU Usage In Windows

    Save Time in Microsoft PowerPoint by Making Your Own Theme

    OTHER TECH NEWS

    Top Car News Car News