JPCERT-AT-2023-0028 JPCERT/CC 2023-11-15 <<< JPCERT/CC Alert 2023-11-15 >>> Microsoft Releases November 2023 Security Updates https://www.jpcert.or.jp/english/at/2023/at230028.html I. Overview Microsoft has released November 2023 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. It is recommended to check the information provided by Microsoft and apply the updates. Microsoft Corporation November 2023 Security Updates https://msrc.microsoft.com/update-guide/en-us/releaseNote/2023-Nov Microsoft Corporation Microsoft Security Updates for November 2023 (Monthly) (Japanese) https://msrc.microsoft.com/blog/2023/11/202311-security-update/ According to Microsoft, among the vulnerabilities, the following vulnerabilities have been confirmed to be exploited in the wild. Please consider applying the security update programs by referring to the information provided by Microsoft. CVE-2023-36025 Windows SmartScreen Security Feature Bypass Vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36025 CVE-2023-36033 Windows DWM Core Library Elevation of Privilege Vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36033 CVE-2023-36036 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36036 Microsoft has published a blog about the guidance regarding credentials leaked to GitHub Actions Logs through Azure CLI. Microsoft Microsoft guidance regarding credentials leaked to GitHub Actions Logs through Azure CLI https://msrc.microsoft.com/blog/2023/11/microsoft-guidance-regarding-credentials-leaked-to-github-actions-logs-through-azure-cli/ II. Solution Please apply the security update programs through Microsoft Update, Windows Update, etc. as soon as possible. Microsoft Update Catalog https://www.catalog.update.microsoft.com/ Windows Update: FAQ https://support.microsoft.com/en-us/help/12373/windows-update-faq III. References Microsoft Corporation Release Notes https://msrc.microsoft.com/update-guide/releaseNote The Exchange Team Released: November 2023 Exchange Server Security Updates https://techcommunity.microsoft.com/t5/exchange-team-blog/released-november-2023-exchange-server-security-updates/ba-p/3980209 If you have any information regarding this alert, please contact JPCERT/CC. ====================================================================== JPCERT Coordination Center (Early Warning Group) MAIL: ew-info@jpcert.or.jp https://www.jpcert.or.jp/english/