DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Microsoft Patch Tuesday 2023 Wrapped

DigitalCIO Bureau by DigitalCIO Bureau
December 14, 2023
in Tech News
0
Microsoft Patch Tuesday 2023 Wrapped
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

To commemorate the 20th anniversary of Microsoft Patch Tuesday, Tenable Research published its annual reflection on Patch Tuesday releases in 2023, delving into significant trends and insights.

Throughout 2023, Microsoft addressed a total of 909 Common Vulnerabilities and Exposures (CVEs), representing a marginal decrease of 0.87% compared to the 917 CVEs patched in 2022. The trajectory of Patch Tuesday releases has exhibited a consistent upward pattern since 2017, reaching its zenith in 2020 with 1,245 CVEs addressed.

July emerged as the pinnacle month for Patch Tuesday in 2023, witnessing Microsoft’s resolution of 130 CVEs. Notably, only two months surpassed the 100 mark in terms of CVEs patched (July and October), while four months recorded fewer than 60 CVEs addressed (May, September, November, December).

Patch Tuesday 2023 by severity
In 2023, most vulnerabilities were rated as important, accounting for 90% of all CVEs patched, followed by critical at 9.6%. These figures are relatively consistent with 2022 figures, when Microsoft patched 831 important CVEs, which accounted for 90.2% while critical vulnerabilities accounted for 85 CVEs or 9.2%. Further analysis reveals that most vulnerabilities patched by Microsoft fell into the Remote Code Execution (RCE) category, accounting for 36%, followed by  Elevation of Privilege (EoP) vulnerabilities at 26%. Information Disclosure vulnerabilities accounted for 12.5% of vulnerabilities patched.

Patch Tuesday 2023 zero-day vulnerabilities
Throughout the year, Microsoft addressed 23 zero-day vulnerabilities in its Patch Tuesday releases, with a noteworthy 52.2% attributed to EoP flaws. EoP vulnerabilities, often exploited by advanced persistent threat (APT) actors and determined cybercriminals, serve as a means to escalate privileges in the aftermath of a compromise.

Among the prominent zero-day vulnerabilities unveiled in the Patch Tuesday releases of 2023 is CVE-2023-23397, an EoP vulnerability in Microsoft Outlook that has been exploited by the Russian APT group APT28, also known as Forest Blizzard. Despite receiving a patch in March, ongoing observations by Unit 42 researchers reveal a campaign exploiting this flaw as recently as October 2023.

“Despite the routine monthly cadence of Patch Tuesday, the persistence of known vulnerabilities necessitates continuous organisational efforts. The year’s Patch Tuesday remained eventful, marked by the presence of multiple zero-day flaws and critical vulnerabilities spanning various Microsoft products. This underscores the ongoing challenges in maintaining robust cybersecurity despite regular patch releases,” said Satnam Narang, senior staff research engineer, Tenable.

Tags: Tenable
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

Gartner: AI-optimized cloud infrastructure growing rapidly

by DigitalCIO Bureau
October 15, 2025
0
Infosys: Over $300 billion In Corporate Cloud Commitments Remain Untapped

AI-optimized infrastructure as a service (IaaS) is emerging as the next disruptive growth engine for AI infrastructure. As a result, end-user spending is projected to grow 146% by...

Read moreDetails

OpenAI and Broadcom to Build 10 Gigawatts of AI Infrastructure

by DigitalCIO Bureau
October 15, 2025
0

OpenAI and Broadcom have announced a collaboration for 10 gigawatts of custom AI accelerators. OpenAI will design the accelerators and systems, which will be developed and deployed in...

Read moreDetails

AI Skillsets Critical to Cybersecurity Skills Gap Solution

by DigitalCIO Bureau
October 14, 2025
0
Fortinet Expands Universal SASE Coverage with Two New India-Based Data Centres   

Fortinet has released its 2025 Global Cybersecurity Skills Gap Report, shedding light on the new and persistent challenges organizations face due to the cybersecurity skills gap. The global...

Read moreDetails

Visakhapatnam’s First 50 MW AI Edge Data Center Foundation Laid

by DigitalCIO Bureau
October 14, 2025
0
Visakhapatnam’s First 50 MW AI Edge Data Center Foundation Laid

In a major boost to the Andhra Pradesh government’s digital initiatives, Hon’ble Minister for IT, Electronics and Communications, Real Time Governance and Human Resources Development, Government of Andhra...

Read moreDetails

Mass scanning of Palo Alto Networks, Cisco and Fortinet Login portals

by DigitalCIO Bureau
October 13, 2025
0
Mass scanning of Palo Alto Networks, Cisco and Fortinet Login portals

Cybersecurity intelligence firm GreyNoise has observed an alarming increase in scanning activity against network equipment from major vendors in recent days. Scanning of Palo Alto Networks login portals...

Read moreDetails
Next Post
Global Digital Transformation Spending to Reach $3.9tn by 2027

Indian small business owners strongly embrace digital transformation: GoDaddy

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Humio Launches Bucket Storage and Introduces New Features

February 26, 2020
eScan Unveils Vision Core XDR

eScan Unveils Vision Core XDR

December 14, 2024
Coforge and Newgen Elevates Partnership

Ericsson and F.I.R.S.T partner at IIT Kanpur for driving innovative financial solutions

April 30, 2024

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud HCLTech Honeywell IBM Infographics Internet of Things (IoT) Kaspersky Microsoft Netskope NTT DATA Palo Alto Networks Panel Discussion Qlik Salesforce Sophos Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?