• News/
  • https://www.theregister.com/2023/12/13/december_2023_patch_tuesday/

Final Patch Tuesday of 2023 goes out with a bang

The Register
·
Jessica Lyons Hardcastle
·
Published Dec 13, 2023
·
Updated

It's the last Patch Tuesday of 2023, which calls for celebration – just as soon as you update Windows, Adobe, Google, Cisco, FortiGuard, SAP, VMware, Atlassian and Apple products, of course. Let's start with Apple, since two of the bugs Cupertino disclosed yesterday may have already been used for evil purposes. While the fruit cart's December release fixes all the iThings, there's two especially concerning vulnerabilities in the WebKit (again) web browser engine that affect AppleTVs and Apple Watches, plus some older iPhones and iPads. Both bugs have already been fixed in a ton of other Apple products. CVE-2023-42916 is an out-of-bounds read flaw that could allow miscreants to access sensitive information, and CVE-2023-42917 is a memory corruption vulnerability that can lead to arbitrary code execution. Both were spotted by Clément Lecigne of Google's Threat Analysis Group – which indicates spyware may be involved, given TAG's proclivities. "Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1," the vendor commented about both bugs. And while Cupertino issued emergency fixes at the end of November to fix these security problems in some iPhones, iPads, and Macs, the patches issued address the same CVEs in older iPhones and iPads, as well as AppleTV HD and AppleTV 4K (all models) and Apple Watch Series 4 and later. Microsoft, meanwhile, closed out a very buggy year with just over 30 Windows patches – none of which are list...

Read full article

Affected Software

24 affected components
Apple WebKit
Microsoft Power Platform
Microsoft Azure Logic Apps
Microsoft Windows
Adobe Prelude
Adobe Illustrator
Adobe InDesign
Adobe Dimension
Adobe Experience Manager
Adobe Substance3D Stager
Adobe Substance3D Sampler
Adobe Substance3D After Effects
Adobe Substance3D Designer
Google Android
SAP Business Technology Platform (SAP BTP)
Atlassian Bamboo
Atlassian Bitbucket
Atlassian Jira
Atlassian Confluence Data Center
atlassian Confluence Server
cisco Apache Struts
VMware Workspace ONE Launcher
FortiGuard FortiOS
FortiGuard FortiPAM HTTPSd daemon
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of the article?

The article discusses the final Patch Tuesday of 2023 and the critical security updates released by various software vendors.

2

What security implications are discussed in the article?

The article highlights vulnerabilities found in multiple applications that could be exploited if not patched promptly.

3

What products or software are affected by the updates mentioned?

The affected products include Windows, Adobe Creative Suite, Google Android, Autodesk, Cisco Apache Struts, and many others.

4

Why is it important to update the affected software?

Updating the affected software is crucial to protect systems from potential exploits and security breaches.

5

Who released the patches mentioned in the article?

The patches were released by major vendors such as Microsoft, Apple, Adobe, Google, Cisco, VMware, and others.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203