# Microsoft Patches Two Exploited Zero-Days

Published: 2023-05-09 · Severity: high
Canonical: https://vorant.io/reports/72b87eb9-d20d-58c7-80d5-aa224b71019a/microsoft-patches-two-exploited-zero-days

> IPA warns two actively exploited Microsoft vulnerabilities, CVE-2023-29336 and CVE-2023-24932, require urgent patching.

Japan's IPA issued an alert on May 10, 2023 regarding Microsoft's monthly security updates, highlighting that two of the disclosed vulnerabilities, CVE-2023-29336 and CVE-2023-24932, have been confirmed by Microsoft as actively exploited in the wild. The advisory notes that successful exploitation of the broader set of patched vulnerabilities could lead to application crashes or full attacker control of affected systems.

IPA urges organizations and users to apply Microsoft's patches immediately via Windows Update to mitigate the risk of expanding exploitation. No specific threat actor, malware family, or targeted sector is identified in the advisory; it serves as a general urgent patch notification for Windows environments.

## Mentioned in this report

- Vulnerabilities: CVE-2023-24932, CVE-2023-29336 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/0510-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/72b87eb9-d20d-58c7-80d5-aa224b71019a/microsoft-patches-two-exploited-zero-days.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
