Microsoft Patches Five Exploited July 2023 Flaws
IPA warns five Microsoft vulnerabilities are already being exploited in the wild and urges immediate patching or mitigation.
Japan's IPA issued an urgent security alert following Microsoft's July 2023 Patch Tuesday release, highlighting five vulnerabilities that Microsoft has confirmed are being actively exploited: CVE-2023-32046, CVE-2023-32049, CVE-2023-35311, CVE-2023-36874, and CVE-2023-36884. Successful exploitation of these flaws could allow applications to crash or grant attackers control over affected Windows systems, posing a significant risk of expanding damage if left unpatched.
IPA advises organizations to apply Microsoft's official patches via Windows Update as soon as possible for most of the listed CVEs. For CVE-2023-36884, which at the time lacked a full patch, Microsoft provided mitigation guidance that IPA recommends implementing immediately. The alert does not provide technical details on the vulnerabilities' root causes, exploitation methods, or any observed threat actors or campaigns, focusing instead on urging prompt remediation across Microsoft product users.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/0712-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free