Microsoft fixes 63 vulnerabilities, including 2 zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-21358 +1 in the same advisory: …21184 | Windows Core Messaging Elevation of Privileges Vulnerability Windows Core Messaging Elevation of Privileges Vulnerability NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2025-21198 | Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.0 | <1% |
| — | ||
| CVE-2025-21418 +1 in the same advisory: …21391 | Local Privilege Escalation via Heap Overflow in Windows WinSock AFD Driver CVE-2025-21418 is a heap-based buffer overflow (CWE-122) in the Windows Ancillary Function Driver for WinSock (AFD.sys), a kernel-mode driver that services Winsock auxiliary socket operations. A local attacker with limited user privileges can trigger the overflow by issuing crafted Winsock requests to the AFD driver, requiring no user interaction. Successful exploitation elevates the attacker's privileges on the local machine (confidentiality, integrity, and availability all impacted), which is typically used to gain SYSTEM-level control as part of a broader intrusion or ransomware chain. Any system running the affected Windows 10, Windows 11, or Windows Server releases is exposed, since the AFD driver is a core component present on all of them. The flaw was a zero-day exploited in the wild before Microsoft patched it in the February 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-11. Do: Deploy Microsoft's February 2025 Patch Tuesday security updates for the affected Windows 10/11 and Windows Server releases immediately, prioritizing multi-user servers, jump hosts, and endpoints in ransomware-prone environments since exploitation was already active before patching. Verify deployment through your patch management/SCCM update history; there is no public PoC or known standalone mitigation, so patching is the required action per the CISA KEV entry. | 7.8 group max | 2% | KEV |
| masson the order of 1 billion+ Windows devices (all listed Windows 10/11 client and Windows Server releases) | |
| CVE-2025-21400 | Improper Authorization Leads to Remote Code Execution in Microsoft SharePoint Server CVE-2025-21400 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper authorization (CWE-285). According to the CVSS vector, exploitation occurs over the network with low attack complexity, but requires the attacker to hold low-privileged (authenticated) credentials and involves user interaction to trigger. Successful exploitation could allow arbitrary code execution in the context of the SharePoint server, with high impact on confidentiality, integrity, and availability. Organizations running affected on-premises SharePoint Server deployments are affected; the fix shipped in Microsoft's February 2025 Patch Tuesday, which addressed 63 vulnerabilities. There is no public proof-of-concept and no confirmed in-the-wild exploitation yet, but the high EPSS score (34.5%, 98th percentile) suggests a substantial probability of exploitation within 30 days. Do: Apply the February 2025 security updates from Microsoft for all affected SharePoint Server versions as soon as possible, prioritizing internet-facing servers. Until patched, restrict network access to SharePoint from untrusted sources and review authentication and application logs for anomalous activity. No public PoC or in-the-wild exploitation is known, but the elevated EPSS probability warrants treating this patch cycle as high priority. | 8.0 | 34% |
| mass≈100,000+ internet-exposed SharePoint servers, with total on-premises deployments plausibly in the hundreds of thousands (well over 1 million enterprise users) |
Full article809 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The company’s monthly Patch Tuesday update comes with more than two-thirds of the patches closing high-severity flaws.
Listen to this article
0:00
Learn more.
Microsoft patched 63 vulnerabilities affecting some of its underlying systems and core products, the company said in its latest security update Tuesday, including Microsoft Excel, Microsoft Office, Windows CoreMessaging and Windows Storage.
More than two-thirds of the vulnerabilities covered in the update are high-severity flaws on the CVSS scale. Vulnerabilities with high-severity base scores run across multiple Microsoft systems, impacting Windows Telephony Service, Windows Ancillary Function Driver, Microsoft Dynamics 365 Sales and other key services.
The vendor’s monthly batch of patches addresses two actively exploited zero-day vulnerabilities: privilege escalation flaws in Windows Storage, tracked as CVE-2025-21391, and Windows Ancillary Function Driver for WinSock, tracked as CVE-2025-21418.
The actively exploited vulnerability in Windows Storage, an improper link resolution before file access defect with a CVSS score of 7.1, allows an attacker to delete targeted files on a system. Microsoft said the vulnerability doesn’t put confidential data at risk, but noted it could allow an attacker to delete data, rendering the service inoperable.
Attackers who combine CVE-2025-21391 exploits with other vulnerabilities could escalate privileges and cause more severe damage, according to Mike Walters, president and co-founder of Action1.
“Large organizations with numerous Windows systems are at significant risk due to the widespread use of Windows Storage features,” Walters said in an email. “Given the ubiquity of Windows operating systems in business environments, potentially millions of organizations worldwide could be at risk. The actual number depends on Windows version adoption rates and existing security measures.”
The second zero-day addressed by Microsoft, a heap-based overflow vulnerability impacting Windows Ancillary Function Driver for WinSock, allows an attacker to gain system privileges and carries a CVSS score of 7.8.
Adam Barnett, lead software engineer at Rapid7, said in an email that organizations have used the Windows Ancillary Function Driver for foundational networking functionality for decades, effectively as a kernel driver that interacts with large amounts of user-supplied input.
“Microsoft is aware of existing exploitation in the wild, and with low attack complexity, low privilege requirements, and no requirement for user interaction, CVE-2025-21418 is one to prioritize for patching,” Barnett told CyberScoop.
Microsoft designated nine of the vulnerabilities addressed in the security update as “more likely” to be exploited. The majority of those defects carry high-severity scores on the CVSS scale, including CVE-2025-21400, a remote-code execution flaw in Microsoft SharePoint Server, and a pair of privilege escalation vulnerabilities in Windows CoreMessaging, CVE-2025-21184 and CVE-2025-21358.
“Microsoft’s exploitability likelihood rating is somewhat opaque, but to add more context about the nine vulnerabilities labeled likely to be exploited, we know that they all had low or no privileges required to exploit, and two of them had public exploit code available,” Jackson Rolf, security analyst at Censys, said in an email to CyberScoop.
Rolf noted that six of the vulnerabilities addressed by Microsoft this month are remote-code execution flaws impacting the Windows Telephony Service. The group of flaws carry low attack complexity and don’t require privileges for exploitation, he added.
The sole critical-severity vulnerability covered in Microsoft’s security update, CVE-2025-21198, is a remote-code execution flaw impacting the Linux agent in Microsoft High Performance Compute clusters. It requires an attacker to have access to the network connected to the targeted cluster or Linux compute node.
The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-february-2025/