Microsoft’s Patch Tuesday for February fixes 3 zero-day bugs and more

TechSpot is about to celebrate its 25th anniversary. TechSpot means tech analysis and advice you can trust.

Why it matters: ‘Patch Tuesday’ is the unofficial term used by Microsoft for its monthly release of bugfixes for Windows and other software products. Like every other month since October 2003, Microsoft patched a lot of flaws in February that could make hackers’ malicious jobs easier.

Yesterday’s Valentine’s Day was a day for lovers, martyrs, and system administrators, as Microsoft released its monthly batch of security updates for Windows and other products. The Patch Tuesday for February 2023 brought fixes for a remarkable amount of bugs, including three dangerous zero-day flaws that are already being exploited by unknown hackers and cyber-criminals.

According to Microsoft’s official bulletin, the February 2023 Security Updates include bugfixes for several Windows components, the Visual Studio IDE, Azure components, .NET Framework, Microsoft Office applications (Word, Publisher, OneNote, SharePoint), SQL Server and much more. All things considered, the new Patch Tuesday should fix 77 individual security flaws.

Nine out of the 77 flaws have been classified with a “critical” severity level, as they can be abused to allow remote code execution on vulnerable systems. Considering the type of flaws and the effects they could have on Windows and other affected software, Microsoft has classified the vulnerabilities as follows: 12 Elevation of Privilege Vulnerabilities, 2 Security Feature Bypass Vulnerabilities, 38 Remote Code Execution Vulnerabilities, 8 Information Disclosure Vulnerabilities, 10 Denial of Service Vulnerabilities, 8 Spoofing Vulnerabilities. A full report about all solved bugs and related advisories has been published by Bleeping Computer and is available here.

The security flaws patched on February 14 don’t include three vulnerabilities in the Edge browser, which Microsoft already fixed at the beginning of the month. The most interesting – and dangerous – bugs fixed in February’s Patch Tuesday include three zero-day flaws, two of which were discovered in Windows components and the last one in Microsoft Publisher.

Known as CVE-2023-21823, the first zero-day bug is a “Windows Graphics Component Remote Code Execution Vulnerability,” which could provide remote code execution capabilities with SYSTEM privileges. Unlike the other patches, the CVE-2023-21823 fix is being distributed via the Microsoft Store rather than through the usual Windows Update channels. Users who disabled automatic updates for the Store will get this particular update as well.

The second zero-day bug is tracked as CVE-2023-23376, and it’s a “Windows Common Log File System Driver Elevation of Privilege Vulnerability” that an attacker could exploit to gain SYSTEM privileges. Finally, the third zero-day bug was discovered in Microsoft Publisher (CVE-2023-21715), and it could be abused by a maliciously crafted document to bypass Office macro policies and run code with no user warning.

Windows Security Updates for February 2023 are already being distributed through the official Windows Update service, update management systems such as WSUS, the Microsoft Store and as direct downloads from the Microsoft Update Catalog. Other software companies releasing their security updates in sync with Microsoft’s February Patch Tuesday include Adobe, Apple, Atlassian, Cisco, Google, Fortra, and SAP.

Read More
Leigha Roberie

Latest

Philippines SEC Signals Readiness for Real-World Asset Tokenization

You are here: Home / Cryptocurrency News / Philippines SEC Signals Readiness for Real-World Asset Tokenization The Philippines SEC has signalled the readiness of the country to tokenize its real-world assets (RWAs), with more and more trust being invested in the blockchain-powered financial tools. As per the opinion of the regulator, all the legal frameworks

FIFA president Infantino brushes off World Cup criticism as crypto ambitions linger in the background

Giovanni Infantino has never been accused of lacking confidence. At press conferences held between June 10-14, the FIFA president addressed a growing list of complaints about the 2026 World Cup by telling critics to “chill and relax.” The tournament, he insisted, would be a success. The critics have material to work with. Ticket prices for

Morocco’s World Cup win over Scotland sparks crypto prediction market frenzy

Morocco’s 1-0 victory over Scotland on June 19 wasn’t just a statement win for the Atlas Lions. It was also one of the most heavily traded sporting events in crypto prediction market history, with volumes exceeding $2 billion around the Group C opener alone. Ismael Saibari scored just 71 seconds into the match at Boston

Newsletter

Don't miss

Philippines SEC Signals Readiness for Real-World Asset Tokenization

You are here: Home / Cryptocurrency News / Philippines SEC Signals Readiness for Real-World Asset Tokenization The Philippines SEC has signalled the readiness of the country to tokenize its real-world assets (RWAs), with more and more trust being invested in the blockchain-powered financial tools. As per the opinion of the regulator, all the legal frameworks

FIFA president Infantino brushes off World Cup criticism as crypto ambitions linger in the background

Giovanni Infantino has never been accused of lacking confidence. At press conferences held between June 10-14, the FIFA president addressed a growing list of complaints about the 2026 World Cup by telling critics to “chill and relax.” The tournament, he insisted, would be a success. The critics have material to work with. Ticket prices for

Morocco’s World Cup win over Scotland sparks crypto prediction market frenzy

Morocco’s 1-0 victory over Scotland on June 19 wasn’t just a statement win for the Atlas Lions. It was also one of the most heavily traded sporting events in crypto prediction market history, with volumes exceeding $2 billion around the Group C opener alone. Ismael Saibari scored just 71 seconds into the match at Boston

5 Small Business Ideas for Retirees Who Don’t Want to Sit Still

Please enable JS and disable any ad blocker

Business delegation visits Kazakhstan to strengthen economic and trade cooperation

Astana, Kazakhstan, Jun 2, 2026 - (ACN Newswire) - A business delegation led by the Chief Executive of the Hong Kong Special Administrative Region (HKSAR), John Lee, and organised by the Hong Kong Trade Development Council (HKTDC), began its visit to Astana, the capital of Kazakhstan, on 1 June. During the visit, a total of 43

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID