# Microsoft Patches Three Actively Exploited Zero-Days

Published: 2023-11-14 · Severity: high
Canonical: https://vorant.io/reports/b27bd4e7-d7c4-52d7-809a-c84ff7f8e1f5/microsoft-patches-three-actively-exploited-zero-days

> Microsoft's November 2023 patch addresses three actively exploited vulnerabilities that IPA warns could allow attackers to crash apps or take control of PCs.

The Information-technology Promotion Agency (IPA) of Japan issued an alert on November 15, 2023, regarding Microsoft's monthly security update, which addresses multiple vulnerabilities. Among these, three flaws—CVE-2023-36033, CVE-2023-36036, and CVE-2023-36025—have been confirmed by Microsoft as actively exploited in the wild. IPA urges users and administrators to apply the patches immediately due to the risk of expanding exploitation.

The vulnerabilities could allow an attacker to cause application crashes or gain control over affected Windows systems, posing significant risk to unpatched environments. As is typical with IPA advisories, specific technical details of the exploitation methods or threat actors involved are not disclosed, and the agency defers detailed inquiries to Microsoft or relevant vendors.

Given that these are zero-day vulnerabilities under active exploitation in widely deployed Windows components, organizations should prioritize patch deployment through Windows Update as soon as possible to mitigate risk of compromise.

## Mentioned in this report

- Vulnerabilities: CVE-2023-36025 (KEV), CVE-2023-36033 (KEV), CVE-2023-36036 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/1115-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b27bd4e7-d7c4-52d7-809a-c84ff7f8e1f5/microsoft-patches-three-actively-exploited-zero-days.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
