Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In its November 14, 2023 report on Microsoft’s November Patch Tuesday, SecurityWeek said two vulnerabilities—CVE-2023-36033 and CVE-2023-36036—were being exploited in active attacks. Microsoft released patches in that rollout. This is a historical report, not evidence that either vulnerability is being actively exploited today.

Which Microsoft vulnerabilities were reported exploited?

The two flaws named in the report were CVE-2023-36033 and CVE-2023-36036. SecurityWeek described them as exploited zero-days in Microsoft’s November 2023 Patch Tuesday release.

The report did not give enough technical detail to compare how the vulnerabilities work, which specific products or versions are affected, or their individual severity ratings. Those details should be checked in Microsoft’s advisories rather than inferred from the fact that the flaws were grouped in the same report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What was the reported impact?

Microsoft’s advisories, as quoted by SecurityWeek, warned: “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.” The article does not identify a named spokesperson for that statement.

SecurityWeek said the advisories did not provide details about the live attacks or indicators of compromise. The report therefore does not establish who carried out the attacks, how an exploit was delivered, which organizations or systems were targeted, or what defenders could use as a forensic signature.

Should you patch CVE-2023-36033 or CVE-2023-36036?

If a system may be affected, check Microsoft’s current Security Update Guide for each CVE and follow the installation instructions for the exact product and version in use. SecurityWeek reported that Microsoft issued patches in the November 2023 rollout, but the report alone does not establish which versions are affected or whether a particular device has the relevant update installed.

  1. Search the Security Update Guide for CVE-2023-36033 and CVE-2023-36036.
  2. Confirm whether the advisory lists the Windows product and version you use, and review its required update and installation guidance.
  3. Check the device’s update history or your organization’s patch-management system to verify whether the relevant update is installed. If the system is managed by an employer or IT provider, ask them to confirm its status.

Because the original report is from November 2023, use Microsoft’s advisory and the device’s current update state for remediation decisions—not the historical headline alone.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What else was in Microsoft’s November 2023 release?

SecurityWeek reported 59 documented security vulnerabilities across the release. That is the release-wide count, not a count of exploited flaws or a severity rating for CVE-2023-36033 and CVE-2023-36036. The article also mentioned CVE-2023-36397, a separate Windows PGM vulnerability reported with a CVSS score of 9.8 out of 10; that score does not apply to either of the two vulnerabilities covered here.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Who received discovery credit?

SecurityWeek credited Quan Jin, DBAPPSecurity WeBin Lab, and Microsoft’s threat-intelligence teams. Its report does not specify which person or team discovered each individual CVE.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.