DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Microsoft Patch Tuesday 2023 Wrapped

DigitalCIO Bureau by DigitalCIO Bureau
December 14, 2023
in Tech News
0
Microsoft Patch Tuesday 2023 Wrapped
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

To commemorate the 20th anniversary of Microsoft Patch Tuesday, Tenable Research published its annual reflection on Patch Tuesday releases in 2023, delving into significant trends and insights.

Throughout 2023, Microsoft addressed a total of 909 Common Vulnerabilities and Exposures (CVEs), representing a marginal decrease of 0.87% compared to the 917 CVEs patched in 2022. The trajectory of Patch Tuesday releases has exhibited a consistent upward pattern since 2017, reaching its zenith in 2020 with 1,245 CVEs addressed.

July emerged as the pinnacle month for Patch Tuesday in 2023, witnessing Microsoft’s resolution of 130 CVEs. Notably, only two months surpassed the 100 mark in terms of CVEs patched (July and October), while four months recorded fewer than 60 CVEs addressed (May, September, November, December).

Patch Tuesday 2023 by severity
In 2023, most vulnerabilities were rated as important, accounting for 90% of all CVEs patched, followed by critical at 9.6%. These figures are relatively consistent with 2022 figures, when Microsoft patched 831 important CVEs, which accounted for 90.2% while critical vulnerabilities accounted for 85 CVEs or 9.2%. Further analysis reveals that most vulnerabilities patched by Microsoft fell into the Remote Code Execution (RCE) category, accounting for 36%, followed by  Elevation of Privilege (EoP) vulnerabilities at 26%. Information Disclosure vulnerabilities accounted for 12.5% of vulnerabilities patched.

Patch Tuesday 2023 zero-day vulnerabilities
Throughout the year, Microsoft addressed 23 zero-day vulnerabilities in its Patch Tuesday releases, with a noteworthy 52.2% attributed to EoP flaws. EoP vulnerabilities, often exploited by advanced persistent threat (APT) actors and determined cybercriminals, serve as a means to escalate privileges in the aftermath of a compromise.

Among the prominent zero-day vulnerabilities unveiled in the Patch Tuesday releases of 2023 is CVE-2023-23397, an EoP vulnerability in Microsoft Outlook that has been exploited by the Russian APT group APT28, also known as Forest Blizzard. Despite receiving a patch in March, ongoing observations by Unit 42 researchers reveal a campaign exploiting this flaw as recently as October 2023.

“Despite the routine monthly cadence of Patch Tuesday, the persistence of known vulnerabilities necessitates continuous organisational efforts. The year’s Patch Tuesday remained eventful, marked by the presence of multiple zero-day flaws and critical vulnerabilities spanning various Microsoft products. This underscores the ongoing challenges in maintaining robust cybersecurity despite regular patch releases,” said Satnam Narang, senior staff research engineer, Tenable.

Tags: Tenable
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

Red Hat AI now runs on AWS Trainium and Inferentia chips

by DigitalCIO Bureau
December 5, 2025
0
Red Hat AI now runs on AWS Trainium and Inferentia chips

Red Hat has announced an expanded collaboration with Amazon Web Services (AWS) to power enterprise-grade generative AI (gen AI) on AWS with Red Hat AI and AWS AI...

Read moreDetails

Kellton Acquires ServiceNow services provider Kumori Technologies

by DigitalCIO Bureau
December 5, 2025
0
CRISIL To Acquire Bridge To India Energy

Kellton has announced the acquisition of Kumori Technologies, a specialized ServiceNow services provider. The acquisition strengthens Kellton’s global ServiceNow delivery capabilities and advances its vision of building integrated,...

Read moreDetails

Hexaware Launches New Delivery Center in Cairo

by DigitalCIO Bureau
December 4, 2025
0
Hexaware Launches New Delivery Center in Cairo

Hexaware Technologies has strengthened its global delivery network with a new center in Cairo. Launching with 100 professionals, it will serve customers in Egypt, the Middle East, and...

Read moreDetails

Tata Technologies appoints Anand Sinha as Chief Digital and Information Officer

by DigitalCIO Bureau
December 3, 2025
0
Tata Technologies appoints Anand Sinha as Chief Digital and Information Officer

Anand Kumar Sinha has joined Tata Technologies as Chief Digital and Information Officer (CIDO). With an extensive experience in technology, focusing on IT operations, Technology Infrastructure, cybersecurity, ERP, AI,...

Read moreDetails

Cybercrime Will Become Increasingly Automated in 2026

by DigitalCIO Bureau
December 2, 2025
0
Trend Micro Named a Leader in Attack Surface Management in New Report

Trend Micro has released its annual Security Predictions Report for 2026, warning that the coming year will mark the true industrialization of cybercrime. Artificial intelligence (AI) and automation are now...

Read moreDetails
Next Post
Global Digital Transformation Spending to Reach $3.9tn by 2027

Indian small business owners strongly embrace digital transformation: GoDaddy

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

VTEX Partners with Vinculum to Elevate Customer Experience in India

Microsoft Partners With Brookfield To Deliver 10.5 GW of New Renewable Power Capacity

May 2, 2024
NXP and MicroEJ to Use Software Containers to Accelerate Embedded Platform Development

NXP and MicroEJ to Use Software Containers to Accelerate Embedded Platform Development

January 4, 2024

How to Mitigate Online Banking Fraud through CPFR

September 3, 2019

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud IBM Infographics Internet of Things (IoT) Kaspersky Microsoft Netskope New Relic NTT DATA Palo Alto Networks Panel Discussion Qlik Salesforce ServiceNow Sophos Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?