Initiatives for
As the national authority for Cybersecurity the CCB has developed several initiatives for specific publics which are presented here.
Reference:
Advisory #2023-69
Version:
1.0
Affected software:
Microsoft
Type:
Several types, ranging from information disclosure to remote code execution and Privilege escalation.
CVE/CVSS:
Microsoft patched 70 CVEs in its June 2023 Patch Tuesday release, 6 rated as critical and 62 rated as important.
https://msrc.microsoft.com/update-guide/releaseNote/2023-Jun
Microsoft's June 2023 Patch Tuesday includes 70 vulnerabilities (6 critical, 62 important, 1 moderate and 1 low), for a wide range of Microsoft products, impacting Microsoft Server and Workstations. Although this Patch Tuesday does not include actively exploited vulnerabilities some of these vulnerabilities are more likely to be exploited in the near future and urgent patching is advised.
Microsoft has released multiple patches for vulnerabilities covering a range of their products. These monthly releases are called “Patch Tuesday” and contain security fixes for Microsoft devices and software. This month’s release covers 70 vulnerabilities. 6 vulnerabilities are marked as critical and 62 as important. It does not include vulnerabilities which were made public prior to patch Tuesday. None of the patched vulnerabilities are actively exploited. Microsoft considers 8 of these vulnerabilities are more likely to be exploited in the near future, urgent patching is advised.
The CCB would like to point your attention to the following vulnerabilities:
The CCB recommends installing updates for vulnerable devices with the highest priority, after thorough testing.
https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2023-patch-tuesday-fixes-78-flaws-38-rce-bugs/
https://blog.qualys.com/vulnerabilities-threat-research/2023/06/13/microsoft-patch-tuesday-june-2023-security-update-review
https://isc.sans.edu/diary/June%202023%20Microsoft%20Patch%20Tuesday/29942
https://www.tenable.com/blog/microsofts-june-2023-patch-tuesday-addresses-70-cves-cve-2023-29357
https://www.tenable.com/blog/cve-2023-29357-cve-2023-24955-exploit-chain-released-for-microsoft-sharepoint-server