PRIOn Logo

Microsoft Patch Tuesday Analysis - December 2023


Everything You Need To Know About Patch Tuesday December 2023.

Microsoft has rolled out security patches covering 36 vulnerabilities. As of now, none of them are susceptible to active exploitation.

/
Cover Image for Microsoft Patch Tuesday Analysis - December 2023

What is Patch Tuesday

Patch Tuesday refers to regular, scheduled releases of software patches and updates by various technology companies, including Microsoft, Adobe, Oracle etc. It occurs on the second Tuesday of each month. During Patch Tuesday, Microsoft releases:

  • Security Updates

  • Bug Fixes

  • Improvements in its products (Windows OS, MS Office, other supported MS applications)

December 2023

Microsoft has rolled out security patches covering 36 vulnerabilities. Currently, there is no evidence of active exploitation and no proof of concept exploits have been discovered. It is noticeable that this month's release note is less comprehensive compared to previous months.

Products

In the provided image below, we can see that the primary vulnerable products are Windows Internet Connection Sharing (ICS), followed by Microsoft Edge (Chromium-Based) and Windows DHCP Server.

Affected MS Products

Vulnerability Types

In the image below we can observe that the predominant vulnerability type for this month is elevation of privilege (11), trailed by remote code execution (8) and Information Disclosure (7) respectively.

Vulnerability Types MS Products

The below heatmap depicts the distribution of various vulnerability types per MS product.

Heatmap Vulnerability Type per MS Product

CVSSv3 Score Distribution

It becomes evident that a significant majority of vulnerabilities gravitates towards the range of 7 to 9. This cluster underscores the high to critical severity of these vulnerabilities.

Bar Chart of CVSSv3 Scores

Statistics related to CVSSv3 score distribution:

  • mean: 7.3

  • min: 4.3

  • max: 9.6

  • median: 7.5

PRIOn KB Prioritization Decision Engine

PRIOn KB prioritization decision engine provides sensible default prioritization for vulnerabilities, which can also be customized to align with your security policies and requirements. The below pie chart provides a visual presentation of the distribution of vulnerabilities analysed via the PRIOn KB decision engine. At a glance, it becomes evident that the majority of the vulnerabilities, comprising a substantial 69.4% (25) of the total, fall into the "Significant" risk priority level. The "Routine" priority level makes up 30.6% (11) of the chart. As of now, none of the vulnerabilities being analysed fall into the "urgent" or "immediate" risk priority level.

PRIOn KB Patch Tuesday Bar Chart December 2023

In the table below, we have arranged all the examined CVEs by priority.

CVE

Score

Priority Label

CVE-2023-35618

68

Significant

CVE-2023-36019

66

Significant

CVE-2023-35628

63

Significant

CVE-2023-36020

62

Significant

CVE-2023-21740

61

Significant

CVE-2023-35621

61

Significant

CVE-2023-35622

61

Significant

CVE-2023-35624

61

Significant

CVE-2023-35630

61

Significant

CVE-2023-35631

61

Significant

CVE-2023-35632

61

Significant

CVE-2023-35633

61

Significant

CVE-2023-35634

61

Significant

CVE-2023-35638

61

Significant

CVE-2023-35639

61

Significant

CVE-2023-35641

61

Significant

CVE-2023-35643

61

Significant

CVE-2023-35644

61

Significant

CVE-2023-36004

61

Significant

CVE-2023-36005

61

Significant

CVE-2023-36006

61

Significant

CVE-2023-36010

61

Significant

CVE-2023-36011

61

Significant

CVE-2023-36391

61

Significant

CVE-2023-36696

61

Significant

CVE-2023-35619

59

Routine

CVE-2023-35625

59

Routine

CVE-2023-35629

59

Routine

CVE-2023-35636

59

Routine

CVE-2023-35642

59

Routine

CVE-2023-36003

59

Routine

CVE-2023-36009

59

Routine

CVE-2023-36012

59

Routine

CVE-2023-36880

59

Routine

CVE-2023-38174

59

Routine

CVE-2023-35635

59

Routine

How PRIOn can help

PRIOn is an AI driven vulnerability prioritization technology. PRIOn is here to automatically prioritize vulnerabilities, public or private, that matter most across your entire environment. Contact us here for any inquiry/demo. We are here to assist you to transform your vulnerability management lifecycle.


More from PRIOn

A Year in Review 2022

PRIOn Team
PRIOn Team
Cover Image for undefined