Microsoft addressed 104 vulnerabilities in this October 2023 release, including 12 rated as Critical and 45 Remote Code Execution vulnerabilities.

  • Three of the CVEs included in this month’s release are also being exploited in the wild.
CVE/AdvisoryTitleTagMicrosoft Severity RatingBase ScoreMicrosoft ImpactExploitedPublicly Disclosed
CVE-2023-35349Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingCritical9.8Remote Code ExecutionNoNo
CVE-2023-36902Windows Runtime Remote Code Execution VulnerabilityWindows Client/Server Runtime SubsystemImportant7Remote Code ExecutionNoNo
CVE-2023-38171Microsoft QUIC Denial of Service VulnerabilityMicrosoft QUICImportant7.5Denial of ServiceNoNo
CVE-2023-36737Azure Network Watcher VM Agent Elevation of Privilege VulnerabilityAzureImportant7.8Elevation of PrivilegeNoNo
CVE-2023-41763Skype for Business Elevation of Privilege VulnerabilitySkype for BusinessImportant5.3Elevation of PrivilegeYesYes
CVE-2023-41765Layer 2 Tunneling Protocol Remote Code Execution VulnerabilityWindows Layer 2 Tunneling ProtocolCritical8.1Remote Code ExecutionNoNo
CVE-2023-41766Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege VulnerabilityClient Server Run-time Subsystem (CSRSS)Important7.8Elevation of PrivilegeNoNo
CVE-2023-41767Layer 2 Tunneling Protocol Remote Code Execution VulnerabilityWindows Layer 2 Tunneling ProtocolCritical8.1Remote Code ExecutionNoNo
CVE-2023-41768Layer 2 Tunneling Protocol Remote Code Execution VulnerabilityWindows Layer 2 Tunneling ProtocolCritical8.1Remote Code ExecutionNoNo
CVE-2023-41769Layer 2 Tunneling Protocol Remote Code Execution VulnerabilityWindows Layer 2 Tunneling ProtocolCritical8.1Remote Code ExecutionNoNo
CVE-2023-41770Layer 2 Tunneling Protocol Remote Code Execution VulnerabilityWindows Layer 2 Tunneling ProtocolCritical8.1Remote Code ExecutionNoNo
CVE-2023-41771Layer 2 Tunneling Protocol Remote Code Execution VulnerabilityWindows Layer 2 Tunneling ProtocolCritical8.1Remote Code ExecutionNoNo
CVE-2023-41772Win32k Elevation of Privilege VulnerabilityWindows Win32KImportant7.8Elevation of PrivilegeNoNo
CVE-2023-41773Layer 2 Tunneling Protocol Remote Code Execution VulnerabilityWindows Layer 2 Tunneling ProtocolCritical8.1Remote Code ExecutionNoNo
CVE-2023-41774Layer 2 Tunneling Protocol Remote Code Execution VulnerabilityWindows Layer 2 Tunneling ProtocolCritical8.1Remote Code ExecutionNoNo
CVE-2023-36732Win32k Elevation of Privilege VulnerabilityWindows Win32KImportant7.8Elevation of PrivilegeNoNo
CVE-2023-36731Win32k Elevation of Privilege VulnerabilityWindows Win32KImportant7.8Elevation of PrivilegeNoNo
CVE-2023-36730Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilitySQL ServerImportant7.8Remote Code ExecutionNoNo
CVE-2023-36729Named Pipe File System Elevation of Privilege VulnerabilityWindows Named Pipe File SystemImportant7.8Elevation of PrivilegeNoNo
CVE-2023-36728Microsoft SQL Server Denial of Service VulnerabilitySQL ServerImportant5.5Denial of ServiceNoNo
CVE-2023-36726Windows Internet Key Exchange (IKE) Extension Elevation of Privilege  VulnerabilityWindows IKE ExtensionImportant7.8Elevation of PrivilegeNoNo
CVE-2023-36725Windows Kernel Elevation of Privilege VulnerabilityWindows NT OS KernelImportant7.8Elevation of PrivilegeNoNo
CVE-2023-36724Windows Power Management Service Information Disclosure VulnerabilityWindows Power Management ServiceImportant5.5Information DisclosureNoNo
CVE-2023-36723Windows Container Manager Service Elevation of Privilege VulnerabilityWindows Container Manager ServiceImportant7.8Elevation of PrivilegeNoNo
CVE-2023-36722Active Directory Domain Services Information Disclosure VulnerabilityActive Directory Domain ServicesImportant4.4Information DisclosureNoNo
CVE-2023-36721Windows Error Reporting Service Elevation of Privilege VulnerabilityWindows Error ReportingImportant7Elevation of PrivilegeNoNo
CVE-2023-36720Windows Mixed Reality Developer Tools Denial of Service VulnerabilityWindows Mixed Reality Developer ToolsImportant7.5Denial of ServiceNoNo
CVE-2023-36718Microsoft Virtual Trusted Platform Module Remote Code Execution VulnerabilityWindows Virtual Trusted Platform ModuleCritical7.8Remote Code ExecutionNoNo
CVE-2023-36717Windows Virtual Trusted Platform Module Denial of Service VulnerabilityWindows TPMImportant6.5Denial of ServiceNoNo
CVE-2023-36713Windows Common Log File System Driver Information Disclosure VulnerabilityWindows Common Log File System DriverImportant5.5Information DisclosureNoNo
CVE-2023-36712Windows Kernel Elevation of Privilege VulnerabilityWindows KernelImportant7.8Elevation of PrivilegeNoNo
CVE-2023-36711Windows Runtime C++ Template Library Elevation of Privilege VulnerabilityWindows Runtime C++ Template LibraryImportant7.8Elevation of PrivilegeNoNo
CVE-2023-36710Windows Media Foundation Core Remote Code Execution VulnerabilityMicrosoft Windows Media FoundationImportant7.8Remote Code ExecutionNoNo
CVE-2023-36709Microsoft AllJoyn API Denial of Service VulnerabilityWindows AllJoyn APIImportant7.5Denial of ServiceNoNo
CVE-2023-36707Windows Deployment Services Denial of Service VulnerabilityWindows Deployment ServicesImportant6.5Denial of ServiceNoNo
CVE-2023-36706Windows Deployment Services Information Disclosure VulnerabilityWindows Deployment ServicesImportant6.5Information DisclosureNoNo
CVE-2023-36704Windows Setup Files Cleanup Remote Code Execution VulnerabilityWindows Setup Files CleanupImportant7.8Remote Code ExecutionNoNo
CVE-2023-36703DHCP Server Service Denial of Service VulnerabilityWindows DHCP ServerImportant7.5Denial of ServiceNoNo
CVE-2023-36702Microsoft DirectMusic Remote Code Execution VulnerabilityWindows Microsoft DirectMusicImportant7.8Remote Code ExecutionNoNo
CVE-2023-36701Microsoft Resilient File System (ReFS) Elevation of Privilege VulnerabilityWindows Resilient File System (ReFS)Important7.8Elevation of PrivilegeNoNo
CVE-2023-36698Windows Kernel Security Feature Bypass VulnerabilityWindows KernelImportant3.6Security Feature BypassNoNo
CVE-2023-36697Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingCritical6.8Remote Code ExecutionNoNo
CVE-2023-36606Microsoft Message Queuing Denial of Service VulnerabilityWindows Message QueuingImportant7.5Denial of ServiceNoNo
CVE-2023-36605Windows Named Pipe Filesystem Elevation of Privilege VulnerabilityWindows Named Pipe File SystemImportant7.4Elevation of PrivilegeNoNo
CVE-2023-36603Windows TCP/IP Denial of Service VulnerabilityWindows TCP/IPImportant7.5Denial of ServiceNoNo
CVE-2023-36602Windows TCP/IP Denial of Service VulnerabilityWindows TCP/IPImportant7.5Denial of ServiceNoNo
CVE-2023-36598Microsoft WDAC ODBC Driver Remote Code Execution VulnerabilitySQL ServerImportant7.8Remote Code ExecutionNoNo
CVE-2023-36596Remote Procedure Call Information Disclosure VulnerabilityWindows Remote Procedure CallImportant6.5Information DisclosureNoNo
CVE-2023-36594Windows Graphics Component Elevation of Privilege VulnerabilityMicrosoft Graphics ComponentImportant7.8Elevation of PrivilegeNoNo
CVE-2023-36593Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.8Remote Code ExecutionNoNo
CVE-2023-36592Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36591Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36590Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36589Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36585Active Template Library Denial of Service VulnerabilityWindows Active Template LibraryImportant7.5Denial of ServiceNoNo
CVE-2023-36584Windows Mark of the Web Security Feature Bypass VulnerabilityWindows Mark of the Web (MOTW)Important5.4Security Feature BypassNoNo
CVE-2023-36583Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36582Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36581Microsoft Message Queuing Denial of Service VulnerabilityWindows Message QueuingImportant7.5Denial of ServiceNoNo
CVE-2023-36579Microsoft Message Queuing Denial of Service VulnerabilityWindows Message QueuingImportant7.5Denial of ServiceNoNo
CVE-2023-36578Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36577Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution VulnerabilityMicrosoft WDAC OLE DB provider for SQLImportant8.8Remote Code ExecutionNoNo
CVE-2023-36576Windows Kernel Information Disclosure VulnerabilityWindows KernelImportant5.5Information DisclosureNoNo
CVE-2023-36575Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36574Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36573Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36572Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36571Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36570Microsoft Message Queuing Remote Code Execution VulnerabilityWindows Message QueuingImportant7.3Remote Code ExecutionNoNo
CVE-2023-36569Microsoft Office Elevation of Privilege VulnerabilityMicrosoft OfficeImportant8.4Elevation of PrivilegeNoNo
CVE-2023-36568Microsoft Office Click-To-Run Elevation of Privilege VulnerabilityMicrosoft OfficeImportant7Elevation of PrivilegeNoNo
CVE-2023-36567Windows Deployment Services Information Disclosure VulnerabilityWindows Deployment ServicesImportant7.5Information DisclosureNoNo
CVE-2023-36564Windows Search Security Feature Bypass VulnerabilityMicrosoft Windows Search ComponentImportant6.5Security Feature BypassNoNo
CVE-2023-36563Microsoft WordPad Information Disclosure VulnerabilityMicrosoft WordPadImportant6.5Information DisclosureYesYes
CVE-2023-36561Azure DevOps Server Elevation of Privilege VulnerabilityAzure DevOpsImportant7.3Elevation of PrivilegeNoNo
CVE-2023-36557PrintHTML API Remote Code Execution VulnerabilityWindows HTML PlatformImportant7.8Remote Code ExecutionNoNo
CVE-2023-36438Windows TCP/IP Information Disclosure VulnerabilityWindows TCP/IPImportant7.5Information DisclosureNoNo
CVE-2023-36435Microsoft QUIC Denial of Service VulnerabilityMicrosoft QUICImportant7.5Denial of ServiceNoNo
CVE-2023-36434Windows IIS Server Elevation of Privilege VulnerabilityWindows IISImportant9.8Elevation of PrivilegeNoNo
CVE-2023-36433Microsoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityMicrosoft DynamicsImportant6.5Information DisclosureNoNo
CVE-2023-36431Microsoft Message Queuing Denial of Service VulnerabilityWindows Message QueuingImportant7.5Denial of ServiceNoNo
CVE-2023-36429Microsoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityMicrosoft DynamicsImportant6.5Information DisclosureNoNo
CVE-2023-36420Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilitySQL ServerImportant7.3Remote Code ExecutionNoNo
CVE-2023-36419Azure HDInsight Apache Oozie Workflow Scheduler Elevation of Privilege VulnerabilityAzureImportant8.8Elevation of PrivilegeNoNo
CVE-2023-36417Microsoft SQL ODBC Driver Remote Code Execution VulnerabilitySQL ServerImportant7.8Remote Code ExecutionNoNo
CVE-2023-44487MITRE: CVE-2023-44487 HTTP/2 Rapid Reset AttackHTTP/2ImportantN/ADenial of ServiceYesNo
CVE-2023-29348Windows Remote Desktop Gateway (RD Gateway) Information Disclosure VulnerabilityWindows RDPImportant6.5Information DisclosureNoNo
CVE-2023-38166Layer 2 Tunneling Protocol Remote Code Execution VulnerabilityWindows Layer 2 Tunneling ProtocolCritical8.1Remote Code ExecutionNoNo
CVE-2023-38159Windows Graphics Component Elevation of Privilege VulnerabilityMicrosoft Graphics ComponentImportant7Elevation of PrivilegeNoNo
CVE-2023-36790Windows RDP Encoder Mirror Driver Elevation of Privilege VulnerabilityWindows RDPImportant7.8Elevation of PrivilegeNoNo
CVE-2023-36789Skype for Business Remote Code Execution VulnerabilitySkype for BusinessImportant7.2Remote Code ExecutionNoNo
CVE-2023-36786Skype for Business Remote Code Execution VulnerabilitySkype for BusinessImportant7.2Remote Code ExecutionNoNo
CVE-2023-36785Microsoft ODBC Driver for SQL Server Remote Code Execution VulnerabilitySQL ServerImportant7.8Remote Code ExecutionNoNo
CVE-2023-36780Skype for Business Remote Code Execution VulnerabilitySkype for BusinessImportant7.2Remote Code ExecutionNoNo
CVE-2023-36778Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange ServerImportant8Remote Code ExecutionNoNo
CVE-2023-36776Win32k Elevation of Privilege VulnerabilityWindows Win32KImportant7Elevation of PrivilegeNoNo
CVE-2023-36743Win32k Elevation of Privilege VulnerabilityWindows Win32KImportant7.8Elevation of PrivilegeNoNo
CVE-2023-36566Microsoft Common Data Model SDK Denial of Service VulnerabilityMicrosoft Common Data Model SDKImportant6.5Denial of ServiceNoNo
CVE-2023-36565Microsoft Office Graphics Elevation of Privilege VulnerabilityMicrosoft OfficeImportant7Elevation of PrivilegeNoNo
CVE-2023-36436Windows MSHTML Platform Remote Code Execution VulnerabilityWindows HTML PlatformImportant7.8Remote Code ExecutionNoNo
CVE-2023-36418Azure RTOS GUIX Studio Remote Code Execution VulnerabilityAzure Real Time Operating SystemImportant7.8Remote Code ExecutionNoNo
CVE-2023-36416Microsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityMicrosoft DynamicsImportant6.1SpoofingNoNo
CVE-2023-36415Azure Identity SDK Remote Code Execution VulnerabilityAzure SDKImportant8.8Remote Code ExecutionNoNo
CVE-2023-36414Azure Identity SDK Remote Code Execution VulnerabilityAzure SDKImportant8.8Remote Code ExecutionNoNo

Prioritize the right vulnerabilities and accelerate your time-to-remediation

Watch this 3-minute video to see what Frontline VM can do for you.