Microsoft has issued fixes for 98 security vulnerabilities in its first Patch Tuesday of the year, a volume of flaws nearly double December’s total which has surprised analysts.
The fresh wave of patches in 2023 includes fixes for 11 ‘critical’ flaws and one actively exploited zero-day vulnerability.
According to Microsoft, 11 vulnerabilities were given a ‘critical’ rating due to their potential to enable remote code execution, elevate privileges, and bypass vital security features.
Analysis from the Zero-Day Initiative claimed that the volume of vulnerabilities “is the largest we’ve seen from Microsoft for a January release in quite some time”.
Patches were also issued for critical vulnerability exploits affecting a raft of Windows products, including Windows Defender, Windows BitLocker, Office, and Microsoft Exchange Server.
December saw the tech giant issue fixes for two zero-day vulnerabilities affecting Windows SmartScreen and DirectX.
The latest patch cycle included fixes for 39 privilege escalation vulnerabilities. While these vulnerabilities often come with lower CVSSv3 scores, security experts warn that these are typically seen in the early stages of an attack.
The zero-day’s patch addresses an actively exploited elevation of privilege vulnerability. Tracked as CVE-2023-21674, the vulnerability was given an 8.8 CVSSv3 rating and could be used to capitalise on an initial infection on a targeted host.
Microsoft also disclosed details of another elevation of privilege vulnerability that it has now been patched.
CVE-2023-21549 affects the Windows SMB Witness Service and also received a ‘critical’ severity score. Microsoft listed the vulnerability as ‘publicly known’ but added there is currently no real evidence of exploitation.
“To exploit this vulnerability, an attacker could execute a specially crafted malicious script which executes an RPC call to an RPC host,” Microsoft said in its update.
This particular vulnerability affects Windows OS versions starting from Windows 7 and Windows Server 2008.
Earlier this week, the tech giant confirmed it would no longer provide security updates for Windows 7 and Windows 8.1 through its Extended Security Update programme.
Ⓒ Future Publishing









Ltd