Skip to main content

Microsoft Releases February 2023 Security Updates

Scheduled updates for Microsoft products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled updates for Microsoft products


The following platforms are also known to be affected:

  • .NET Framework
  • 3D Builder
  • Azure App Service
  • Azure Data Box Gateway
  • Azure DevOps
  • Azure Machine Learning
  • HoloLens
  • Internet Storage Name Service
  • Microsoft Defender for Endpoint
  • Microsoft Defender for IoT
  • Microsoft Dynamics
  • Microsoft Edge (Chromium-based)
  • Microsoft Graphics Component
  • Microsoft Office OneNote
  • Microsoft Office Publisher
  • Microsoft Office Word
  • Microsoft PostScript Printer Driver
  • Microsoft WDAC OLE DB provider for SQL
  • Microsoft Windows Codecs Library
  • Power BI
  • Visual Studio
  • Windows Active Directory
  • Windows ALPC
  • Windows Common Log File System Driver
  • Windows Cryptographic Services
  • Windows Distributed File System (DFS)
  • Windows Fax and Scan Service
  • Windows HTTP.sys
  • Windows Installer
  • Windows iSCSI
  • Windows Kerberos
  • Windows MSHTML Platform
  • Windows ODBC Driver
  • Windows Protected EAP (PEAP)
  • Windows SChannel
  • Windows Win32K

Threat details

Introduction

Microsoft has released updates to address 80 vulnerabilities across their products, with 9 of them rated as critical and 3 reported as zero-day vulnerabilities. An unauthenticated, remote attacker could exploit some of these vulnerabilities to take control of an affected system.

Exploitation in the wild

Microsoft have released updates for three zero-day vulnerabilities.  The vulnerabilities referred to as CVE-2023-21823, CVE-2023-21715, and CVE-2023-23376 have been added to the CISA's Known Exploited Vulnerabilities Catalog.

In addition, a proof-of-concept has been published for CVE-2023-21716.


Threat updates

Date Update
7 Mar 2023 Proof-of-Concept released for CVE-2023-21716

This cyber alert has been updated to reflect this release.


Remediation advice

Affected organisations are encouraged to review Microsoft’s February 2023 Security Update Summary and Deployment Information and apply the relevant updates.



Last edited: 7 March 2023 2:08 pm