It’s the second week of the month, which means that Microsoft has released its latest round of vulnerability fixes — and that threat actors are trying to exploit them before patches are applied.
With more than 60 vulnerabilities confirmed, your patch management capabilities will be put to use when it comes to assessing the risk to your business. However, when it comes to the most critical vulnerabilities, the bad guys had a head start. And these are likely to feature front and centre in their attacks.
Unfortunately, there are three such zero-day vulnerabilities to deal with this month.
Well, there are five zero-days if you use the Microsoft definition of the term, which includes those publicly disclosed as well as under active exploitation. You can check the others out, along with the rest of the vulnerabilities, by referencing Microsoft’s November 2023 security update bulletin.
Here’s what security experts have to say about the actively exploited zero-day trio.
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
First up is CVE-2023-36036. which Mike Walters, President and co-founder of Action1, explains is “a critical zero-day elevation of privilege issue affecting Microsoft Windows 10 and later, as well as Microsoft Windows Server 2008 and onwards.”
This vulnerability comes with a CVSS rating of 7.8, hence the critical assessment from Microsoft.
“The vulnerability,” Walters continues, “requires local access, is of low complexity and can be exploited without high-level privileges or user interaction.”
Yet successful exploitation would enable an attacker to gain system-level privileges. Walters says this makes it “an ideal tool for escalating privileges after initial access, such as through phishing”.
Windows DWM Core Library Elevation of Privilege Vulnerability
Next on the already exploited list is CVE-2023-36033. This is another elevation of privilege zero-day. Impacting the Windows Desktop Window Manager Core Library, which handles stuff such as rendering desktop graphical user interface elements, this one could also elevate an attacker to system access.
This will attract threat actors who might need to send a malicious document via email. Natalie Silva, Lead Cyber Security Content Engineer at Immersive Labs says such an attacker could access one of the “most privileged accounts on the Windows operating system, which could allow the attacker extensive control and access rights.”
Microsoft has rated this vulnerability as having an attack complexity value of low. Silva agrees: “The attacker would only need to possess privileges that are typically granted to basic users.”
Windows SmartScreen Security Feature Bypass Vulnerability
To complete the exploited threat triumvirate, CVE-2023-36025 is a bypass vulnerability, specifically bypassing Windows Defender SmartScreen security features.
“This is a significant concern,” says Jason Kikta, CISO at Automox, “as SmartScreen is designed to provide an additional layer of protection against phishing sites and malware downloads.”
While this means that an attacker would require a user to click a link or open a malicious document, file or website, that is no real barrier to most attacks.
“Threat actors thrive on scenarios that let them bypass security measures,” Kikta concludes. “They find it even more appealing when they can exploit security mechanisms to carry out malicious activities, appearing normal to the system and avoiding scrutiny.”
With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.