Microsoft Patches Two Exploited Zero-Days
IPA warns two actively exploited Microsoft vulnerabilities, CVE-2023-29336 and CVE-2023-24932, require urgent patching.
Japan's IPA issued an alert on May 10, 2023 regarding Microsoft's monthly security updates, highlighting that two of the disclosed vulnerabilities, CVE-2023-29336 and CVE-2023-24932, have been confirmed by Microsoft as actively exploited in the wild. The advisory notes that successful exploitation of the broader set of patched vulnerabilities could lead to application crashes or full attacker control of affected systems.
IPA urges organizations and users to apply Microsoft's patches immediately via Windows Update to mitigate the risk of expanding exploitation. No specific threat actor, malware family, or targeted sector is identified in the advisory; it serves as a general urgent patch notification for Windows environments.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/0510-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free