Microsoft Patches Exploited Windows Zero-Day CVE-2023-21674
IPA warns a Microsoft Windows vulnerability, CVE-2023-21674, is being actively exploited in the wild and urges immediate patching.
Japan's IPA issued an alert following Microsoft's January 2023 Patch Tuesday release, highlighting multiple vulnerabilities across Microsoft products. Among these, CVE-2023-21674 stands out as Microsoft has confirmed active exploitation of this flaw in the wild. Successful exploitation could allow attackers to crash affected applications or gain control over a victim's computer, leading to a range of damaging outcomes.
Given the confirmed in-the-wild exploitation, IPA urges organizations and users to apply Microsoft's security updates as soon as possible to mitigate risk of further compromise. No specific threat actor, malware family, or targeted sector was identified in the advisory; the notice is a general call to action for all Windows users to patch promptly via Windows Update.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/20230111-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free