{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"Microsoft Visual Studio 2022 version 17.0","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft Visual Studio 2022 version 17.2","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2019 pour syst\u00e8mes x64 (CU 18)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft Visual Studio 2022 version 17.5","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft OLE DB Driver 19 pour SQL Server","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2014 Service Pack 3 pour syst\u00e8mes 32 bits (CU 4)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2016 pour syst\u00e8mes x64 Service Pack 3 (GDR)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2008 R2 pour x64-Based Systems Service Pack 3 (QFE)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2012 pour syst\u00e8mes 32 bits Service Pack 4 (QFE)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2022 pour syst\u00e8mes x64 (GDR)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Raw Image Extension","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2014 Service Pack 3 pour syst\u00e8mes x64 (CU 4)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2014 Service Pack 3 pour syst\u00e8mes x64 (GDR)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft Malware Protection Engine","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2008 pour x64-Based Systems Service Pack 4 (QFE)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Visual Studio Code","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2016 pour syst\u00e8mes x64 Service Pack 3 Azure Connectivity Pack","product":{"name":"Azure","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft ODBC Driver 18 pour SQL Server","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft Dynamics 365 (on-premises) version 9.1","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft 365 Apps pour Enterprise pour syst\u00e8mes 32 bits","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft 365 Apps pour Enterprise pour 64 bits Systems","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2017 pour syst\u00e8mes x64 (GDR)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2017 pour syst\u00e8mes x64 (CU 31)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft Visual Studio 2022 version 17.4","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2019 pour syst\u00e8mes x64 (GDR)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2008 pour syst\u00e8mes 32 bits Service Pack 4 (QFE)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2012 pour syst\u00e8mes x64 Service Pack 4 (QFE)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft Dynamics 365 (on-premises) version 9.0","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft ODBC Driver 17 pour SQL Server","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft OLE DB Driver 18 pour SQL Server","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2008 R2 pour 32-Bit Systems Service Pack 3 (QFE)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Microsoft SQL Server 2014 Service Pack 3 pour syst\u00e8mes 32 bits (GDR)","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}},{"description":"Send Customer Voice survey from Dynamics 365","product":{"name":"N/A","vendor":{"name":"Microsoft","scada":false}}}],"affected_systems_content":null,"content":"## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2023-28262","url":"https://www.cve.org/CVERecord?id=CVE-2023-28262"},{"name":"CVE-2023-23375","url":"https://www.cve.org/CVERecord?id=CVE-2023-23375"},{"name":"CVE-2023-28287","url":"https://www.cve.org/CVERecord?id=CVE-2023-28287"},{"name":"CVE-2023-24860","url":"https://www.cve.org/CVERecord?id=CVE-2023-24860"},{"name":"CVE-2023-28291","url":"https://www.cve.org/CVERecord?id=CVE-2023-28291"},{"name":"CVE-2023-28313","url":"https://www.cve.org/CVERecord?id=CVE-2023-28313"},{"name":"CVE-2023-28314","url":"https://www.cve.org/CVERecord?id=CVE-2023-28314"},{"name":"CVE-2023-28285","url":"https://www.cve.org/CVERecord?id=CVE-2023-28285"},{"name":"CVE-2023-28299","url":"https://www.cve.org/CVERecord?id=CVE-2023-28299"},{"name":"CVE-2023-28296","url":"https://www.cve.org/CVERecord?id=CVE-2023-28296"},{"name":"CVE-2023-24893","url":"https://www.cve.org/CVERecord?id=CVE-2023-24893"},{"name":"CVE-2023-28263","url":"https://www.cve.org/CVERecord?id=CVE-2023-28263"},{"name":"CVE-2023-28292","url":"https://www.cve.org/CVERecord?id=CVE-2023-28292"},{"name":"CVE-2023-28304","url":"https://www.cve.org/CVERecord?id=CVE-2023-28304"},{"name":"CVE-2023-28260","url":"https://www.cve.org/CVERecord?id=CVE-2023-28260"},{"name":"CVE-2023-28295","url":"https://www.cve.org/CVERecord?id=CVE-2023-28295"},{"name":"CVE-2023-28311","url":"https://www.cve.org/CVERecord?id=CVE-2023-28311"},{"name":"CVE-2023-23384","url":"https://www.cve.org/CVERecord?id=CVE-2023-23384"},{"name":"CVE-2023-28309","url":"https://www.cve.org/CVERecord?id=CVE-2023-28309"}],"links":[{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28292 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28292"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28287 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28287"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28304 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28304"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28296 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28296"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-24893 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24893"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28291 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28291"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-23375 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23375"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28285 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28285"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-24860 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24860"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28262 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28262"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28314 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28314"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-23384 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23384"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28309 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28309"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28260 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28260"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28295 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28295"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28313 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28313"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28263 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28263"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28311 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28311"},{"title":"Bulletin de s\u00e9curit\u00e9 Microsoft CVE-2023-28299 du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28299"}],"reference":"CERTFR-2023-AVI-0309","revisions":[{"description":"Version initiale","revision_date":"2023-04-12T00:00:00.000000"}],"risks":[{"description":"Usurpation d'identit\u00e9"},{"description":"Ex\u00e9cution de code arbitraire \u00e0 distance"},{"description":"D\u00e9ni de service"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"},{"description":"\u00c9l\u00e9vation de privil\u00e8ges"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 corrig\u00e9es dans <span\nclass=\"textit\">les produits Microsoft</span>. Elles permettent \u00e0 un\nattaquant de provoquer un d\u00e9ni de service, une atteinte \u00e0 la\nconfidentialit\u00e9 des donn\u00e9es, une ex\u00e9cution de code \u00e0 distance, une\nusurpation d'identit\u00e9 et une \u00e9l\u00e9vation de privil\u00e8ges.\n","title":"Multiples vuln\u00e9rabilit\u00e9s dans les produits Microsoft","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Microsoft du 11 avril 2023","url":"https://msrc.microsoft.com/update-guide/"}]}
