9VSA23-00943-01 CSIRT comparte información de actualización de seguridad de Microsoft para diciembre 2023

El CSIRT de Gobierno comparte información sobre las vulnerabilidades parchadas en el Update Tuesday de Microsoft correspondiente a diciembre de 2023.

9VSA23-00943-01.png

Resumen

El CSIRT de Gobierno comparte información sobre las vulnerabilidades parchadas en el Update Tuesday de Microsoft correspondiente a diciembre de 2023.

Vulnerabilidades

Impacto

Vulnerabilidades de riesgo crítico:

CVE-2023-35630: Vulnerabilidad de ejecución remota de código en Internet Connection Sharing (ICS).

CVE-2023-35628: Vulnerabilidad de ejecución remota de código en Windows MSHTML Platform.

CVE-2023-35641: Vulnerabilidad de ejecución remota de código en Internet Connection Sharing (ICS).

CVE-2023-36019: Vulnerabilidad de spoofing en Microsoft Power Platform Connector.

Mitigación

Este paquete de actualización mensual está disponible para su descarga aquí: https://catalog.update.microsoft.com/Search.aspx?q=KB5033420

Productos afectados
Azure Connected Machine Agent

Azure Logic Apps

Azure Machine Learning SDK

Dynamics 365 for Finance and Operations Platform Update 60

Dynamics 365 for Finance and Operations Version 10.0.37 Platform Update 61

Dynamics 365 for Finance and Operations Version 10.0.38 Platform Update 62

Microsoft 365 Apps for Enterprise for 32-bit Systems

Microsoft 365 Apps for Enterprise for 64-bit Systems

Microsoft Dynamics 365 (on-premises) version 9.0

Microsoft Dynamics 365 (on-premises) version 9.1

Microsoft Malware Protection Platform

Microsoft Office 2016 (32-bit edition)

Microsoft Office 2016 (64-bit edition)

Microsoft Office 2019 for 32-bit editions

Microsoft Office 2019 for 64-bit editions

Microsoft Office LTSC 2021 for 32-bit editions

Microsoft Office LTSC 2021 for 64-bit editions

Microsoft Office LTSC for Mac 2021

Microsoft Power Platform

Windows 10 for 32-bit Systems

Windows 10 for x64-based Systems

Windows 10 Version 1607 for 32-bit Systems

Windows 10 Version 1607 for x64-based Systems

Windows 10 Version 1809 for 32-bit Systems

Windows 10 Version 1809 for ARM64-based Systems

Windows 10 Version 1809 for x64-based Systems

Windows 10 Version 21H2 for 32-bit Systems

Windows 10 Version 21H2 for ARM64-based Systems

Windows 10 Version 21H2 for x64-based Systems

Windows 10 Version 22H2 for 32-bit Systems

Windows 10 Version 22H2 for ARM64-based Systems

Windows 10 Version 22H2 for x64-based Systems

Windows 11 version 21H2 for ARM64-based Systems

Windows 11 version 21H2 for x64-based Systems

Windows 11 Version 22H2 for ARM64-based Systems

Windows 11 Version 22H2 for x64-based Systems

Windows 11 Version 23H2 for ARM64-based Systems

Windows 11 Version 23H2 for x64-based Systems

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2012

Windows Server 2012 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 R2 (Server Core installation)

Windows Server 2016

Windows Server 2016 (Server Core installation)

Windows Server 2019

Windows Server 2019 (Server Core installation)

Windows Server 2022

Windows Server 2022 (Server Core installation)

Windows Server 2022, 23H2 Edition (Server Core installation)

Enlaces

https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec

Informe

El informe oficial publicado por el CSIRT del Gobierno de Chile está disponible en el siguiente enlace: 9VSA23-00943-01.