References https://nvd.nist.gov/vuln/detail/CVE-2023-28302 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28302 https://www.asiainfo-sec.com/security/notice/detail-6838.html https://www.anquanke.com/post/id/288253 https://blog.csdn.net/weixin_37813152/article/details/132081666 https://blog.nsfocus.net/microsoftapril/ https://zhuanlan.zhihu.com/p/624804810 https://www.cnblogs.com/hacker520/p/17314429.html https://cn-sec.com/archives/1928287.html https://zone.ci/e/tags/index.php?page=250&tagname=%E6%8B%92%E7%BB%9D%E5%8A%A1%E6%BC%8F%E6%B4%9E&line=25&tempid=11 https://cn-sec.com/archives/1668882.html https://community.fortinet.com/fortidast-51/outbreak-alert-cve-2023-28302-microsoft-message-queuing-msmq-denial-of-service-vulnerability-146498 https://software.sonicwall.com/applications/ips/index.asp?ev=sig&sigid=2723 https://nsfocusglobal.com/microsofts-april-security-update-for-multiple-high-risk-product-vulnerabilities/ https://github.com/advisories/GHSA-j2x9-pqv3-56mg https://medium.com/@arivazhagan0220/whitepaper-microsoft-message-queuing-msmq-remote-code-execution-risk-f1ad4309489d https://www.secpod.com/blog/microsoft-april-2023-patch-tuesday-addresses-97-vulnerabilities-including-a-zero-day https://www.akamai.com/zh/blog/security-research/akamai-perspective-patch-tuesday-april-2023 https://www.yijinglab.com/industry/20230727080755 https://www.venustech.com.cn/new_type/aqtg/20230412/25437.html
Related VulnerabilitiesPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)Windows截图工具NTLM信息泄露漏洞(CVE-2026-33829)Gradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)Windows Shell Link 敏感信息泄露与欺骗漏洞(CVE-2026-25185)PoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCsharepoint-lists-api-disclosure: Microsoft SharePoint - List API DisclosurePoCCVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows - Log File ExposurePoCsharepoint-layouts-disclosure: Microsoft SharePoint - Layouts DisclosurePoCsharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page Disclosure