# Microsoft Patches Two Exploited Zero-Days

Published: 2023-09-12 · Severity: high
Canonical: https://vorant.io/reports/f1f23616-b01a-5c6e-a063-4bcaa8ca855c/microsoft-patches-two-exploited-zero-days

> IPA Japan warns two Microsoft vulnerabilities, CVE-2023-36802 and CVE-2023-36761, are being actively exploited and urges immediate patching.

Japan's IPA issued an alert following Microsoft's September 2023 Patch Tuesday release, highlighting a batch of vulnerability fixes across Microsoft products. Among the disclosed flaws, Microsoft confirmed that two vulnerabilities—CVE-2023-36802 and CVE-2023-36761—have already been exploited in the wild, prompting IPA to urge organizations to apply patches immediately to prevent further damage.

The advisory notes that successful exploitation of the broader set of patched vulnerabilities could lead to application crashes or allow attackers to gain control of affected systems. No specific threat actor, malware family, or targeted sector is named in this advisory; it functions as a general awareness bulletin directing users to apply Microsoft's official updates via Windows Update.

## Mentioned in this report

- Vulnerabilities: CVE-2023-36761 (KEV), CVE-2023-36802 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/0913-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f1f23616-b01a-5c6e-a063-4bcaa8ca855c/microsoft-patches-two-exploited-zero-days.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
