PatchSiren

Microsoft CVE debriefs · Page 64

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Microsoft CVE published 2024-05-14

CVE-2024-30051

CVE-2024-30051 is a Microsoft DWM Core Library privilege escalation vulnerability that CISA lists as known to be actively exploited. Because it is in the Known Exploited Vulnerabilities catalog and marked for known ransomware campaign use, it should be treated as an urgent remediation item rather than a routine patch.

Known exploited Microsoft CVE published 2024-05-14

CVE-2024-30040

CVE-2024-30040 is a Microsoft Windows MSHTML platform security feature bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-05-14. Because it is in KEV, defenders should treat it as an active-risk issue and prioritize Microsoft’s guidance and mitigations ahead of normal patch cycles.

Known exploited Microsoft CVE published 2024-04-30

CVE-2024-29988

CVE-2024-29988 is a Microsoft SmartScreen Prompt security feature bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-04-30. Because it is a KEV-listed issue, defenders should treat it as actively exploited or otherwise high-priority for remediation, even though the supplied corpus does not include deeper technical details or impact scope.

Known exploited Microsoft CVE published 2024-04-23

CVE-2022-38028

CVE-2022-38028 is a Microsoft Windows Print Spooler privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-04-23. Because it appears in KEV, defenders should treat it as a prioritized remediation item and follow Microsoft’s guidance referenced by CISA. The supplied source notes direct administrators to apply vendor mitigations or discontinue use if mitiga [truncated]

HIGH Microsoft CVE published 2024-04-09

CVE-2024-26257

CVE-2024-26257 is a high-severity remote code execution vulnerability in Microsoft Excel, published by NVD on 2024-04-09 and last modified on 2026-05-19. The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH) with a vector of AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating local attack vector, low attack complexity, no privileges required, but user interaction required, with high impacts to confidential [truncated]

Known exploited Microsoft CVE published 2024-03-26

CVE-2023-24955

CVE-2023-24955 is a Microsoft SharePoint Server code injection vulnerability that CISA added to its Known Exploited Vulnerabilities (KEV) catalog on 2024-03-26. CISA also marks it as having known ransomware campaign use. For defenders, that combination means this should be treated as an active exposure requiring prompt mitigation or remediation, not routine backlog work.

Known exploited Microsoft CVE published 2024-03-04

CVE-2024-21338

CVE-2024-21338 is a Microsoft Windows kernel exposed IOCTL with insufficient access control weakness. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-03-04 and marked it as associated with known ransomware campaign use. Because CISA set a remediation due date of 2024-03-25, this should be treated as a high-priority Windows remediation item.

Known exploited Microsoft CVE published 2024-02-29

CVE-2023-29360

CVE-2023-29360 is a Microsoft Streaming Service vulnerability described as an untrusted pointer dereference. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-02-29, which means it has been designated as known exploited and should be treated as a high-priority remediation item. The supplied CISA metadata sets a remediation due date of 2024-03-21 and directs defenders to apply vendor mit [truncated]

Known exploited Microsoft CVE published 2024-02-15

CVE-2024-21410

CVE-2024-21410 is a Microsoft Exchange Server privilege escalation vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-02-15. That KEV listing makes this a high-priority defensive issue for Exchange administrators and vulnerability management teams, with CISA directing organizations to apply vendor mitigations or discontinue use if mitigations are unavailable.

Known exploited Microsoft CVE published 2024-02-13

CVE-2024-21412

CVE-2024-21412 is a Microsoft Windows security feature bypass affecting Internet Shortcut files. CISA lists it in the Known Exploited Vulnerabilities catalog, with known ransomware campaign use noted. Because it is a KEV item, defenders should treat it as urgent and follow Microsoft’s mitigation guidance referenced by CISA.

Known exploited Microsoft CVE published 2024-02-13

CVE-2024-21351

CVE-2024-21351 is a Microsoft Windows SmartScreen security feature bypass that was published on 2024-02-13 and added to CISA’s Known Exploited Vulnerabilities catalog the same day. Because CISA tracks it as known exploited, defenders should treat it as a high-priority Windows issue and follow Microsoft’s guidance promptly.

Known exploited Microsoft CVE published 2024-01-10

CVE-2023-29357

CVE-2023-29357 is a Microsoft SharePoint Server privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-01-10. The KEV entry marks it as known to be used in ransomware campaigns and sets a remediation due date of 2024-01-31. The supplied corpus does not provide a CVSS score, so defensive urgency here is driven by KEV status and ransomware risk rather than [truncated]

Known exploited Microsoft CVE published 2023-11-16

CVE-2023-36584

CVE-2023-36584 is a Microsoft Windows Mark of the Web (MOTW) security feature bypass vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-16, which is a strong signal to treat it as actively exploited or at least credibly weaponized in the wild. For defenders, the immediate concern is ensuring Windows endpoints are updated and that Microsoft’s guidance is applied quickly, [truncated]

Known exploited Microsoft CVE published 2023-11-14

CVE-2023-36036

CVE-2023-36036 is a Microsoft Windows privilege escalation vulnerability affecting the Cloud Files Mini Filter Driver. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-14, so defenders should treat it as an urgent remediation item and follow vendor guidance as soon as possible.

Known exploited Microsoft CVE published 2023-11-14

CVE-2023-36033

CVE-2023-36033 affects Microsoft Windows Desktop Window Manager (DWM) Core Library and is categorized as a privilege escalation vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-14, which indicates known exploitation and makes prompt defensive action important.

Known exploited Microsoft CVE published 2023-11-14

CVE-2023-36025

CVE-2023-36025 is a Microsoft Windows SmartScreen security feature bypass that CISA added to its Known Exploited Vulnerabilities catalog on 2023-11-14. Because it is listed in KEV, organizations should treat it as a confirmed-exploitation concern and prioritize Microsoft’s vendor guidance and any available mitigations.

HIGH Microsoft CVE published 2023-11-14

CVE-2023-33128

CVE-2023-33128 is a remote code execution vulnerability affecting .NET and Visual Studio, with specific impact on Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0). Published on June 11, 2024, this vulnerability carries a HIGH severity CVSS score of 7.3. The vulnerability stems from the underlying .NET and Visual Studio components used by the affected Siemens product. According to CISA advisory ICSA-24-165-04 [truncated]

Known exploited Microsoft CVE published 2023-10-10

CVE-2023-41763

CVE-2023-41763 is a Microsoft Skype for Business privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-10-10. Because it is officially listed as known exploited, defenders should treat it as an urgent remediation item and follow vendor mitigation guidance or discontinue use if mitigations are not available.

Known exploited Microsoft CVE published 2023-10-10

CVE-2023-36563

CVE-2023-36563 is a Microsoft WordPad information disclosure vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2023-10-10. Because it is in KEV, defenders should treat it as actively exploited risk rather than a theoretical issue. CISA’s required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

Known exploited Microsoft CVE published 2023-10-04

CVE-2023-28229

CVE-2023-28229 is a Microsoft Windows privilege escalation vulnerability affecting the CNG Key Isolation Service. It was added to CISA’s Known Exploited Vulnerabilities catalog on 2023-10-04, which makes it a high-priority issue for defenders. CISA’s required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

Known exploited Microsoft CVE published 2023-09-12

CVE-2023-36802

CVE-2023-36802 affects Microsoft Streaming Service Proxy and is described as a privilege escalation vulnerability. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2023-09-12, which means it is treated as actively exploited and should be prioritized for defensive action. The supplied corpus does not include a CVSS score or deeper technical details, so the safest response is to follow [truncated]

Known exploited Microsoft CVE published 2023-09-12

CVE-2023-36761

CVE-2023-36761 is an information disclosure vulnerability in Microsoft Word that CISA added to its Known Exploited Vulnerabilities catalog on 2023-09-12. Because it is listed in KEV, defenders should treat it as a high-priority issue: apply Microsoft’s mitigations or stop using the affected product if mitigations are unavailable. The public record provided here does not include exploit details, but the KE [truncated]

Known exploited Microsoft CVE published 2023-08-09

CVE-2023-38180

CVE-2023-38180 is a Microsoft .NET Core and Visual Studio denial-of-service vulnerability. CISA listed it in the Known Exploited Vulnerabilities catalog on the same day it was published in the supplied corpus, so it should be treated as a high-priority remediation item.

MEDIUM Microsoft CVE published 2023-08-08

CVE-2023-35391

CVE-2023-35391 is an information disclosure vulnerability affecting ASP.NET Core SignalR and Visual Studio, with confirmed impact on Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0). Published June 11, 2024, this vulnerability carries a CVSS 3.1 score of 6.2 (MEDIUM severity). The underlying ASP.NET Core SignalR flaw can expose sensitive information to unauthorized actors. Siemens has identified this vulnera [truncated]

Known exploited Microsoft CVE published 2023-07-17

CVE-2023-36884

CVE-2023-36884 is a Microsoft Windows Search remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-07-17. The KEV record marks it as known to be used in ransomware campaigns, which makes this a high-priority defensive issue for Windows environments. Based on the supplied sources, the safest response is to follow Microsoft’s remediation guidance, apply m [truncated]

MEDIUM Microsoft CVE published 2023-07-11

CVE-2023-33162

CVE-2023-33162 is a Microsoft Excel information disclosure vulnerability with a CVSS 3.1 score of 5.5 (MEDIUM severity). The vulnerability was published on July 11, 2023, and last modified on May 19, 2026. The issue allows an attacker to disclose sensitive information through local attack vectors, requiring user interaction but no privileges. The vulnerability affects multiple Microsoft Office and Microso [truncated]

HIGH Microsoft CVE published 2023-07-11

CVE-2023-33161

CVE-2023-33161 is a high-severity remote code execution vulnerability in Microsoft Excel, published by NVD on 2023-07-11 and last modified on 2026-05-19. The vulnerability affects Microsoft 365 Apps for Enterprise (x64 and x86) and Microsoft Office 2019 and 2021 for macOS. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates a local attack vector requiring user interaction, with high impact [truncated]

HIGH Microsoft CVE published 2023-07-11

CVE-2023-33152

CVE-2023-33152 is a Microsoft ActiveX Remote Code Execution vulnerability affecting multiple Microsoft Office products. Published on July 11, 2023, this vulnerability carries a HIGH severity CVSS score of 7.0. The vulnerability was last modified on May 19, 2026, indicating ongoing updates to its record. Microsoft has released patches and vendor advisories to address this issue. The vulnerability affects M [truncated]

MEDIUM Microsoft CVE published 2023-07-11

CVE-2023-33151

A spoofing vulnerability in Microsoft Outlook that could allow an attacker to manipulate email content or sender information to deceive users. The vulnerability affects multiple versions of Microsoft Office and Microsoft 365 Apps across x86 and x64 architectures. With a CVSS score of 6.5 (MEDIUM), this vulnerability requires user interaction to exploit, with network-based attack vectors and low attack com [truncated]

Known exploited Microsoft CVE published 2023-07-11

CVE-2023-36874

CVE-2023-36874 is a Microsoft Windows privilege escalation vulnerability in the Windows Error Reporting Service. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-07-11, which means defenders should treat it as a priority remediation item and follow vendor guidance promptly.