PatchSiren

Microsoft CVE debriefs · Page 65

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Microsoft CVE published 2023-07-11

CVE-2023-35311

CVE-2023-35311 is a Microsoft Outlook security feature bypass vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied sources confirm known exploitation and direct defenders to apply Microsoft updates as soon as possible, or discontinue use of the product if updates are unavailable. Because the source corpus does not include affected versions or exploit mechanics, the ma [truncated]

Known exploited Microsoft CVE published 2023-07-11

CVE-2023-32049

CVE-2023-32049 is a Microsoft Windows Defender SmartScreen security feature bypass vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2023-07-11. Because it is listed in KEV, organizations should treat it as a known-exploited Windows issue and confirm remediation using Microsoft’s guidance, with CISA’s due date of 2023-08-01 as the urgency benchmark.

Known exploited Microsoft CVE published 2023-07-11

CVE-2023-32046

CVE-2023-32046 is a Microsoft Windows MSHTML Platform privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-07-11. Because it is KEV-listed, defenders should treat it as an active risk and prioritize vendor remediation for affected Windows systems.

Known exploited Microsoft CVE published 2023-06-22

CVE-2016-0165

CVE-2016-0165 is a Microsoft Win32k privilege escalation vulnerability that CISA lists in the Known Exploited Vulnerabilities catalog. Because it is marked as known exploited, defenders should treat it as a high-priority patching issue and follow Microsoft’s remediation guidance without delay.

HIGH Microsoft CVE published 2023-05-09

CVE-2023-29335

CVE-2023-29335 is a Microsoft Word Security Feature Bypass Vulnerability with a CVSS 3.1 score of 7.5 (HIGH). Published on May 9, 2023, this vulnerability affects multiple Microsoft products including Word 2013 RT, Word 2013 SP1 RT, Word 2016, Office 2019, Microsoft 365 Apps for Enterprise, Office LTSC 2021, and various Windows 10, Windows 11, and Windows Server versions. The vulnerability requires user i [truncated]

Known exploited Microsoft CVE published 2023-05-09

CVE-2023-29336

CVE-2023-29336 is a Microsoft Win32k privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-05-09. The KEV listing means there is official evidence of exploitation in the wild, so organizations should treat this as a high-priority remediation item and apply the vendor’s guidance without delay.

Known exploited Microsoft CVE published 2023-04-11

CVE-2023-28252

CVE-2023-28252 is a Microsoft Windows privilege escalation issue affecting the Common Log File System (CLFS) driver. CISA lists it in the Known Exploited Vulnerabilities catalog, which means it is treated as actively exploited in the wild. The KEV entry also marks known ransomware campaign use, so this should be prioritized for patching on Windows systems that may be exposed to local privilege escalation paths.

Known exploited Microsoft CVE published 2023-04-07

CVE-2019-1388

CVE-2019-1388 is a Microsoft Windows privilege escalation issue associated with the Windows Certificate Dialog. CISA included it in the Known Exploited Vulnerabilities catalog, which means it has been observed being actively exploited in the wild. The KEV metadata also marks it as having known ransomware campaign use, so defenders should treat it as a high-priority remediation item and follow vendor guida [truncated]

Known exploited Microsoft CVE published 2023-03-30

CVE-2013-3163

CVE-2013-3163 is a Microsoft Internet Explorer memory corruption vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied corpus does not include a CVSS score, but the KEV listing indicates confirmed exploitation and a strong need to prioritize exposure reduction. CISA’s note says the impacted product is end-of-life and should be disconnected if still in use.

MEDIUM Microsoft CVE published 2023-03-14

CVE-2023-23391

CVE-2023-23391 is a Microsoft Office for Android spoofing vulnerability with a medium CVSS score of 5.5. The NVD record shows a user-interaction-dependent issue that can affect integrity, with no listed confidentiality or availability impact. Microsoft’s MSRC advisory is the primary vendor reference for remediation. For defenders, the main concern is Android deployments of Microsoft Office, especially whe [truncated]

Known exploited Microsoft CVE published 2023-03-14

CVE-2023-24880

CVE-2023-24880 is a Microsoft Windows SmartScreen security feature bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-03-14. The KEV record also marks this issue as associated with known ransomware campaign use, so it should be treated as a high-priority remediation item even though the source corpus does not provide deeper technical detail.

Known exploited Microsoft CVE published 2023-03-14

CVE-2023-23397

CVE-2023-23397 is a Microsoft Office Outlook privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-03-14. That KEV designation means defenders should treat it as a high-priority remediation item and follow Microsoft’s update guidance as soon as possible. The supplied source corpus is limited to official metadata and links, so this debrief intentionally s [truncated]

Known exploited Microsoft CVE published 2023-02-14

CVE-2023-23376

CVE-2023-23376 is a Microsoft Windows Common Log File System (CLFS) driver privilege escalation vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-14 and marked it as having known ransomware campaign use. That combination makes it a high-priority remediation item for Windows environments.

Known exploited Microsoft CVE published 2023-02-14

CVE-2023-21823

CVE-2023-21823 is a Microsoft Windows privilege escalation vulnerability affecting the Windows Graphic Component. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2023-02-14, which means it has been identified as actively exploited and should be prioritized for remediation. CISA’s required action is to apply updates per vendor instructions, with a KEV due date of 2023-03-07.

Known exploited Microsoft CVE published 2023-02-14

CVE-2023-21715

CVE-2023-21715 is a Microsoft Office Publisher security feature bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-02-14. Because it is KEV-listed, defenders should treat it as a priority patching item and follow Microsoft’s update guidance for affected Office installations, especially systems with Publisher installed.

Known exploited Microsoft CVE published 2023-01-10

CVE-2023-21674

CVE-2023-21674 is a Microsoft Windows Advanced Local Procedure Call (ALPC) privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-01-10. Because it is on the KEV list, organizations should treat it as an active remediation item and follow vendor update guidance promptly. The supplied corpus does not include additional technical detail beyond the ALPC priv [truncated]

Known exploited Microsoft CVE published 2023-01-10

CVE-2022-41080

CVE-2022-41080 is a Microsoft Exchange Server privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-01-10. CISA also marks it as associated with known ransomware campaign use, which makes remediation urgent for any organization running Exchange Server.

HIGH Microsoft CVE published 2022-12-13

CVE-2022-44696

CVE-2022-44696 is a high-severity remote code execution vulnerability in Microsoft Office Visio. Published by NVD on 2022-12-13 and last modified on 2026-05-19, this vulnerability allows an attacker to execute arbitrary code when a user opens a specially crafted Visio file. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates a local attack vector requiring user interaction, with high impac [truncated]

Known exploited Microsoft CVE published 2022-12-13

CVE-2022-44698

CVE-2022-44698 is a Microsoft Defender SmartScreen security feature bypass. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-12-13 and marked it as known ransomware campaign use. Because it is in KEV, defenders should treat it as an urgent remediation item even though the supplied corpus does not include CVSS details or deeper exploit mechanics.

Known exploited Microsoft CVE published 2022-11-14

CVE-2022-41049

CVE-2022-41049 is a Microsoft Windows Mark of the Web (MOTW) security feature bypass vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-11-14, which is a strong signal to prioritize remediation on Windows endpoints and servers that handle files from untrusted sources.

HIGH Microsoft CVE published 2022-11-09

CVE-2022-41107

A remote code execution vulnerability in Microsoft Office Graphics allows an attacker to execute arbitrary code when a user opens a maliciously crafted file. The vulnerability requires user interaction and local attack vector, with high impact to confidentiality, integrity, and availability.

MEDIUM Microsoft CVE published 2022-11-09

CVE-2022-41104

A security feature bypass vulnerability in Microsoft Excel allows an attacker to circumvent security protections when a user opens a maliciously crafted file. The vulnerability requires local access and user interaction, with a medium severity CVSS 3.1 score of 5.5. Affected products include Microsoft 365 Apps for Enterprise, Excel 2013 SP1 (including RT), Excel 2016, Office 2019, and Office LTSC 2021. Mi [truncated]

MEDIUM Microsoft CVE published 2022-11-09

CVE-2022-41103

CVE-2022-41103 is a Microsoft Word information disclosure vulnerability with a CVSS 3.1 score of 5.5 (MEDIUM severity). Published on November 9, 2022, this vulnerability affects multiple Microsoft Office and SharePoint products where local attack vectors could lead to unauthorized information disclosure. The vulnerability requires user interaction and has low attack complexity, with no privileges required [truncated]

HIGH Microsoft CVE published 2022-11-09

CVE-2022-41063

CVE-2022-41063 is a remote code execution vulnerability in Microsoft Excel with a CVSS 3.1 score of 7.8 (HIGH). Published by NVD on November 9, 2022, and last modified on May 19, 2026, this vulnerability affects multiple Microsoft Office and Excel deployments including Microsoft 365 Apps for Enterprise (x64), Excel 2013 SP1 (including RT), Excel 2016, Office 2019, Office LTSC 2021, Office Online Server, a [truncated]

Known exploited Microsoft CVE published 2022-11-08

CVE-2022-41128

CVE-2022-41128 is a Microsoft Windows Scripting Languages remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-11-08. Because it is listed in KEV, organizations should treat it as a high-priority remediation item and follow vendor update guidance as soon as possible.

Known exploited Microsoft CVE published 2022-11-08

CVE-2022-41125

CVE-2022-41125 is a Microsoft Windows privilege escalation vulnerability affecting the CNG Key Isolation Service. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2022-11-08, which means the issue was already known to be exploited in the wild and should be treated as urgent for defenders.

Known exploited Microsoft CVE published 2022-11-08

CVE-2022-41091

CVE-2022-41091 is a Microsoft Windows Mark of the Web (MOTW) security feature bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-11-08. Because it is listed in KEV and marked as having known ransomware campaign use, organizations should treat it as a high-priority patching item and follow vendor guidance without delay.

Known exploited Microsoft CVE published 2022-11-08

CVE-2022-41073

CVE-2022-41073 is a Microsoft Windows Print Spooler privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-11-08. CISA’s KEV entry marks it as known exploited and notes known ransomware campaign use, which makes remediation a priority for Windows environments that have not yet confirmed vendor updates. The supplied authoritative guidance is straightforwar [truncated]

Known exploited Microsoft CVE published 2022-10-11

CVE-2022-41033

CVE-2022-41033 is a Microsoft Windows privilege escalation vulnerability affecting the COM+ Event System Service. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-11 and set a remediation due date of 2022-11-01, indicating it should be treated as an urgent patching item. Because the source corpus does not provide a CVSS score, the strongest prioritization signal here is its inclusio [truncated]

Known exploited Microsoft CVE published 2022-09-30

CVE-2022-41082

CVE-2022-41082 is a Microsoft Exchange Server remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-09-30. CISA marked the issue as actively exploited and noted known ransomware campaign use, so defenders should treat this as an urgent remediation item.