It's the last Patch Tuesday of 2023, which calls for celebration – just as soon as you update Windows, Adobe, Google, Cisco, FortiGuard, SAP, VMware, Atlassian and Apple products, of course. Let's start with Apple, since two of the bugs Cupertino disclosed yesterday may have already been used for evil purposes. While the fruit cart's December release fixes all the iThings, there's two especially concerning vulnerabilities in the WebKit (again) web browser engine that affect AppleTVs and Apple Watches, plus some older iPhones and iPads. Both bugs have already been fixed in a ton of other Apple products. CVE-2023-42916 is an out-of-bounds read flaw that could allow miscreants to access sensitive information, and CVE-2023-42917 is a memory corruption vulnerability that can lead to arbitrary code execution. Both were spotted by Clément Lecigne of Google's Threat Analysis Group – which indicates spyware may be involved, given TAG's proclivities. "Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1," the vendor commented about both bugs. And while Cupertino issued emergency fixes at the end of November to fix these security problems in some iPhones, iPads, and Macs, the patches issued address the same CVEs in older iPhones and iPads, as well as AppleTV HD and AppleTV 4K (all models) and Apple Watch Series 4 and later. Microsoft, meanwhile, closed out a very buggy year with just over 30 Windows patches – none of which are list...
Final Patch Tuesday of 2023 goes out with a bang
The Register
·Jessica Lyons Hardcastle
·Published Dec 13, 2023
·Updated
Affected Software
24 affected components
Apple WebKit
Microsoft Power Platform
Microsoft Azure Logic Apps
Microsoft Windows
Adobe Prelude
Adobe Illustrator
Adobe InDesign
Adobe Dimension
Adobe Experience Manager
Adobe Substance3D Stager
Adobe Substance3D Sampler
Adobe Substance3D After Effects
Adobe Substance3D Designer
Google Android
SAP Business Technology Platform (SAP BTP)
Atlassian Bamboo
Atlassian Bitbucket
Atlassian Jira
Atlassian Confluence Data Center
atlassian Confluence Server
cisco Apache Struts
VMware Workspace ONE Launcher
FortiGuard FortiOS
FortiGuard FortiPAM HTTPSd daemon
Frequently Asked Questions
1
What is the main topic of the article?
The article discusses the final Patch Tuesday of 2023 and the critical security updates released by various software vendors.
2
What security implications are discussed in the article?
The article highlights vulnerabilities found in multiple applications that could be exploited if not patched promptly.
3
What products or software are affected by the updates mentioned?
The affected products include Windows, Adobe Creative Suite, Google Android, Autodesk, Cisco Apache Struts, and many others.
4
Why is it important to update the affected software?
Updating the affected software is crucial to protect systems from potential exploits and security breaches.
5
Who released the patches mentioned in the article?
The patches were released by major vendors such as Microsoft, Apple, Adobe, Google, Cisco, VMware, and others.