# Microsoft Patches Five Exploited July 2023 Flaws

Published: 2023-07-11 · Severity: high
Canonical: https://vorant.io/reports/c88f800b-0cca-5ee1-ada0-0f1ead5a4b82/microsoft-patches-five-exploited-july-2023-flaws

> IPA warns five Microsoft vulnerabilities are already being exploited in the wild and urges immediate patching or mitigation.

Japan's IPA issued an urgent security alert following Microsoft's July 2023 Patch Tuesday release, highlighting five vulnerabilities that Microsoft has confirmed are being actively exploited: CVE-2023-32046, CVE-2023-32049, CVE-2023-35311, CVE-2023-36874, and CVE-2023-36884. Successful exploitation of these flaws could allow applications to crash or grant attackers control over affected Windows systems, posing a significant risk of expanding damage if left unpatched.

IPA advises organizations to apply Microsoft's official patches via Windows Update as soon as possible for most of the listed CVEs. For CVE-2023-36884, which at the time lacked a full patch, Microsoft provided mitigation guidance that IPA recommends implementing immediately. The alert does not provide technical details on the vulnerabilities' root causes, exploitation methods, or any observed threat actors or campaigns, focusing instead on urging prompt remediation across Microsoft product users.

## Mentioned in this report

- Vulnerabilities: CVE-2023-32046 (KEV), CVE-2023-32049 (KEV), CVE-2023-35311 (KEV), CVE-2023-36874 (KEV), CVE-2023-36884 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/0712-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c88f800b-0cca-5ee1-ada0-0f1ead5a4b82/microsoft-patches-five-exploited-july-2023-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
