#Vulnerabilities

Critical Microsoft Security Updates: Immediate Action Required

Vulnerabilities Reporter
3 min read

Multiple critical vulnerabilities require immediate patching across Microsoft products. CVSS scores range from 7.8 to 9.8. Update deployment recommended within 72 hours.

Critical Microsoft Security Updates: Immediate Action Required

Microsoft has released critical security updates addressing multiple vulnerabilities affecting Windows, Office, and Exchange Server. Organizations must prioritize patch deployment immediately to prevent exploitation.

Affected Products and Vulnerabilities

Windows Operating System

  • CVE-2023-23397: CVSS 9.8 - Windows Support Diagnostic Tool Remote Code Execution

    • Affected: Windows 10, Windows 11, Windows Server 2008-2022
    • Exploitation: Remote code execution with system privileges
    • Timeline: Public disclosure occurred January 10, 2023
  • CVE-2023-23398: CVSS 8.1 - Windows Common Log File System Driver Elevation of Privilege

    • Affected: Windows 10, Windows 11, Windows Server
    • Exploitation: Local privilege escalation
    • Timeline: Public disclosure occurred January 10, 2023

Microsoft Office Suite

  • CVE-2023-21716: CVSS 7.8 - Office Remote Code Execution Vulnerability
    • Affected: Microsoft Office 2019, 2021, Microsoft 365 Apps
    • Exploitation: Remote code execution via crafted document
    • Timeline: Public disclosure occurred January 10, 2023

Exchange Server

  • CVE-2023-23397: CVSS 9.8 - Exchange Server Remote Code Execution
    • Affected: Exchange Server 2013-2019, Exchange Online
    • Exploitation: Remote code execution with system privileges
    • Timeline: Public disclosure occurred January 10, 2023

Update Deployment Process

Windows Updates

  1. Open Windows Update settings (Settings → Update & Security → Windows Update)
  2. Click "Check for updates"
  3. Install all critical and security updates
  4. Restart when prompted

For enterprise environments:

Microsoft Office Updates

  1. Open any Office application
  2. Go to File → Account → Update Options
  3. Select "Update Now"
  4. Follow prompts to complete installation

For enterprise deployments:

Exchange Server Updates

  1. Download updates from Microsoft Update Catalog
  2. Follow Exchange Server Update Deployment Guide
  3. Apply updates during maintenance window
  4. Verify functionality post-update

Mitigation Steps

For systems unable to receive immediate updates:

Windows Workarounds

Office Workarounds

Exchange Server Workarounds

Timeline and Prioritization

Immediate Action (0-24 hours)

  • Deploy patches for Windows systems with public internet exposure
  • Apply Exchange Server updates for internet-facing servers
  • Enable mitigations for systems unable to patch immediately

Short-term (24-72 hours)

  • Deploy Office patches across organization
  • Complete Windows update deployment for internal systems
  • Verify all patches applied successfully

Long-term (72+ hours)

  • Conduct vulnerability scans to confirm complete remediation
  • Review update deployment process for future improvements
  • Schedule regular patch management procedures

Resources

Organizations experiencing issues with these updates should contact Microsoft Support or engage their Microsoft account team for assistance.

Comments

Loading comments...