CVE-2023-36005
published 2023-12-12CVE-2023-36005: Windows Telephony Server Elevation of Privilege Vulnerability
high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
Windows Telephony Server Elevation of Privilege Vulnerability
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20345 | 10.0.10240.20345 |
| microsoft | windows_10_1607 | < 10.0.14393.6529 | 10.0.14393.6529 |
| microsoft | windows_10_1809 | < 10.0.17763.5206 | 10.0.17763.5206 |
| microsoft | windows_10_21h2 | < 10.0.19041.3803 | 10.0.19041.3803 |
| microsoft | windows_10_22h2 | < 10.0.19045.3803 | 10.0.19045.3803 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20345 | 10.0.10240.20345 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.6529 | 10.0.14393.6529 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5206 | 10.0.17763.5206 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5206 | 10.0.17763.5206 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19041.3803 | 10.0.19041.3803 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.3803 | 10.0.19045.3803 |
| microsoft | windows_11_21h2 | < 10.0.22000.2652 | 10.0.22000.2652 |
| microsoft | windows_11_22h2 | < 10.0.22621.2861 | 10.0.22621.2861 |
| microsoft | windows_11_23h2 | < 10.0.22631.2861 | 10.0.22631.2861 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.2652 | 10.0.22000.2652 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.2861 | 10.0.22621.2861 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22621.2861 | 10.0.22621.2861 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.2861 | 10.0.22631.2861 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26864 | 6.1.7601.26864 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.22413 | 6.0.6003.22413 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24614 | 6.2.9200.24614 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.21715 | 6.3.9600.21715 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.6529 | 10.0.14393.6529 |
Microsoft
Windows Telephony Server Elevation of Privilege Vulnerability
vendor_msrc·2023-12-12·CVSS 7.5
CVE-2023-36005 [HIGH] CWE-591 Windows Telephony Server Elevation of Privilege Vulnerability
Windows Telephony Server Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could execute code in the security context of the “NT AUTHORITY\Network Service” account.
Windows Telephony Server: Windows Telephony Server
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.
GHSA
GHSA-33hq-6mqq-8gjp: Windows Telephony Server Elevation of Privilege Vulnerability
ghsa_unreviewed·2023-12-12
CVE-2023-36005 [HIGH] GHSA-33hq-6mqq-8gjp: Windows Telephony Server Elevation of Privilege Vulnerability
Windows Telephony Server Elevation of Privilege Vulnerability
No detection rules found.
No public exploits indexed.
Trendmicro
The December 2023 Security Update Review
blogs_trendmicro·2023-12-12
The December 2023 Security Update Review
# The December 2023 Security Update Review
Get the December 2023 security update and review.
By: Zero Day Initiative
2023/12/12
Read time: ( words)
Save to Folio
It’s the final patch Tuesday of 2023, and Apple, Adobe, and Microsoft have released their latest security offerings. Take a break from your holiday hustle and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
Apple Patches for December 2023
Apple kicked off the December release cycle with patches for iOS and iPadOS with eight CVEs. Two of these CVEs in Webkit are reported as being under active attack on iOS versions 16.7.1 and older. If you’re using an older iPhone or iPad, you should definitely update your device immediately. If you’re using a dev
Qualys
Microsoft and Adobe Patch Tuesday, December 2023 Security Update Review
blogs_qualys·2023-12-12
Microsoft and Adobe Patch Tuesday, December 2023 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for December 2023
Adobe Patches for December 2023
Zero-day Vulnerability Patched in December Patch Tuesday Edition
Other Critical Severity Vulnerabilities Patched in December Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Qualys Monthly Webinar Series
Microsoft has wrapped up the year with fewer security updates released in its Patch Tuesday, December 2023 edition. We invite you to join us to review and discuss the details of these security updates and patches.
## Microsoft Patch Tuesday for December 2023
In this month’s Patch Tuesday edition, Microsoft ha
Qualys
Qualys Review: Microsoft and Adobe December Security Patches | Qualys
blogs_qualys·2023-12-12
Qualys Review: Microsoft and Adobe December Security Patches | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for December 2023
- Adobe Patches for December 2023
- Zero-day Vulnerability Patched in December Patch Tuesday Edition
- Other Critical Severity Vulnerabilities Patched in December Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- Qualys Monthly Webinar Series
Microsoft has wrapped up the year with fewer security updates released in its Patch Tuesday, December 2023 edition. We invite you to join us to review and discuss the details of these security updates and patches.
## Microsoft Patch Tuesday for December 2023
In this month’s Patch Tuesday edition,
Bleepingcomputer
Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
blogs_bleepingcomputer·2023-12-12·CVSS 5.5
[MEDIUM] Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
## Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
## Lawrence Abrams
10 Elevation of Privilege Vulnerabilities
8 Remote Code Execution Vulnerabilities
6 Information Disclosure Vulnerabilities
5 Denial of Service Vulnerabilities
5 Spoofing Vulnerabilities
The total count of 34 flaws does not include 8 Microsoft Edge flaws fixed on December 7th.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5033375 cumulative update and Windows 10 KB5033372 cumulative update .
## One publicly disclosed zero-day fixed
This month's Patch Tuesday fixes one AMD zero-day vulnerability disclosed in August that previously remained unpatched.
The ' CVE-2023-20588 - AMD: CVE-2023-20588 AMD Speculative Leaks ' vul
Zscaler
Zscaler found Windows Security Vulnerabilities | 12-12-2023
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler found Windows Security Vulnerabilities | 12-12-2023
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2023-12-12
Published