ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38030
Windows Themes Spoofing Vulnerability

Windows Themes Spoofing Vulnerability

NVD description · AI analysis pending
6.551%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2024-7344
Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.

Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.

NVD description · AI analysis pending
8.21% PoC
  • cs-grp neo impact
  • cs-grp greenguard
  • cs-grp sysreturn
  • +1 more
CVE-2025-21186
+2 in the same advisory: …21366 …21395
Microsoft Access Remote Code Execution Vulnerability

Microsoft Access Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.81%
  • microsoft 365 apps
  • microsoft access
  • microsoft office
  • +1 more
CVE-2025-21298
Use-After-Free RCE in Windows OLE (CVE-2025-21298)

CVE-2025-21298 is a use-after-free (CWE-416) vulnerability in the Windows OLE (Object Linking and Embedding) component that permits remote code execution. According to the published CVSS vector, it is network-exploitable without privileges or user interaction, triggered when the system processes maliciously crafted OLE content. A successful attacker gains arbitrary code execution in the context of the affected process, with high impact on confidentiality, integrity, and availability. The flaw affects nearly the entire supported Windows estate — Windows 10 1507 through 22H2, Windows 11 22H2 through 24H2, and Windows Server 2008 through 2019. As of the January 2025 Patch Tuesday release there is no known public proof-of-concept or confirmed in-the-wild exploitation, but the EPSS score of 80.9% (100th percentile) indicates a very high probability of exploitation within 30 days.

Do: Apply Microsoft's January 2025 Windows cumulative security updates to all affected Windows 10/11 and Windows Server hosts immediately, prioritizing internet-facing and server systems given the network-exploitable, critical rating. Verify via patch-reporting tools that the OLE update is present on each host; no vendor mitigations were noted in the available data, so updating is the primary defense. Although no exploitation is confirmed yet, the 80.9% EPSS score argues for completing remediation before a PoC or in-the-wild exploitation emerges.

9.8
group max
81%
  • microsoft Windows 10 1507
  • microsoft Windows 10 1607
  • microsoft Windows 10 1809
  • +9 more
mass≈1 billion+ Windows installations (essentially the entire supported Windows client and Server estate)
CVE-2025-21275
Windows App Package Installer Elevation of Privilege Vulnerability

Windows App Package Installer Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • microsoft windows 11 22h2
  • +1 more
CVE-2025-21311
Windows NTLM V1 Elevation of Privilege Vulnerability

Windows NTLM V1 Elevation of Privilege Vulnerability

NVD description · AI analysis pending
9.82%
  • microsoft windows 11 24h2
  • microsoft windows server 2022 23h2
  • microsoft windows server 2025
CVE-2025-21333
+2 in the same advisory: …21334 …21335
Actively Exploited Heap Overflow in Windows Hyper-V VSP Enables Privilege Escalation

CVE-2025-21333 is a heap-based buffer overflow (CWE-122) in the Windows Hyper-V NT Kernel Integration VSP, which Microsoft classifies as an elevation of privilege vulnerability. An attacker who already has low-privileged access to an affected system can trigger the overflow in this virtualization service provider component to gain higher privileges on the host, with high impact on confidentiality, integrity and availability (CVSS 3.1 score 7.8, local attack vector, no user interaction required). The flaw affects Windows 10 21H2 and 22H2, Windows 11 22H2, 23H2 and 24H2, Windows Server 2022 23H2, and Windows Server 2025. Microsoft patched it in the January 2025 Patch Tuesday release (part of a batch of eight zero-days), and it was exploited as a zero-day before the patch was available: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14 with ransomware use listed as unknown. A public proof-of-concept is available via Exploit-DB, so defenders should treat in-the-wild exploitation as confirmed.

Do: Apply Microsoft's January 2025 Patch Tuesday security updates (released 2025-01-14) to all systems running Windows 10 21H2/22H2, Windows 11 22H2/23H2/24H2, Windows Server 2022 23H2 or Windows Server 2025, prioritizing this KEV-listed, actively exploited zero-day; where updates cannot be applied, follow vendor mitigations or discontinue use of the affected versions per CISA's required action. Because the attack requires local access, prioritize patching multi-user hosts, VDI and terminal servers, and during threat hunting review endpoints for signs that malware or low-privileged users previously escalated privileges via the Hyper-V VSP component.

7.810% KEV PoC
  • microsoft Windows 10 21H2
  • microsoft Windows 10 22H2
  • microsoft Windows 11 22H2
  • +4 more
mass≈hundreds of millions of Windows endpoints potentially affected (affected versions span most of the Windows 10/11 install base), though only systems with…
Full article1,350 words · extracted from thehackernews.com · click to collapse

Microsoft kicked off 2025 with a new set of patches for a total of 161 security vulnerabilities across its software portfolio, including three zero-days that have been actively exploited in attacks.

Of the 161 flaws, 11 are rated Critical and 149 are rated Important in severity. One other flaw, a non-Microsoft CVE related to a Windows Secure Boot bypass (CVE-2024-7344, CVSS score: 6.7), has not been assigned any severity. According to the Zero Day Initiative, the update marks the largest number of CVEs addressed in a single month since at least 2017.

The fixes are in addition to seven vulnerabilities the Windows maker addressed in its Chromium-based Edge browser since the release of December 2024 Patch Tuesday updates.

Prominent among the patches released by Microsoft is a trio of flaws in Windows Hyper-V NT Kernel Integration VSP (CVE-2025-21333, CVE-2025-21334, and CVE-2025-21335, CVSS scores: 7.8) that the company said has come under active exploitation in the wild.

"An attacker who successfully exploited this vulnerability could gain SYSTEM privileges," the company said in an advisory for the three vulnerabilities.

As is customary, it's currently not known how these shortcomings are being exploited, and in what context. Microsoft also makes no mention of the identity of the threat actors weaponizing them or the scale of the attacks.

But given that they are privilege escalation bugs, they are very likely used as part of post-compromise activity, where an attacker has already gained access to a target system by some other means, Satnam Narang, senior staff research engineer at Tenable, pointed out.

"The Virtualization Service Provider (VSP) resides in the root partition of a Hyper-V instance, and provides synthetic device support to child partitions over the Virtual Machine Bus (VMBus): it's the foundation of how Hyper-V allows the child partition to trick itself into thinking that it's a real computer," Rapid7's lead software engineer, Adam Barnett, told The Hacker News.

"Given that the entire thing is a security boundary, it’s perhaps surprising that no Hyper-V NT Kernel Integration VSP vulnerabilities have been acknowledged by Microsoft until today, but it won’t be at all shocking if more now emerge."

The exploitation of Windows Hyper-V NT Kernel Integration VSP has also resulted in the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding them to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the fixes by February 4, 2025.

Separately, Redmond has warned that five of the bugs are publicly known -

It's worth noting that CVE-2025-21308, which could lead to improper disclosure of an NTLM hash, was previously flagged by 0patch as a bypass for CVE-2024-38030. Micropatches for the vulnerability were released in October 2024.

All the three Microsoft Access issues, on the other hand, have been credited to Unpatched.ai, an AI-guided vulnerability discovery platform. Action1 also noted that while the flaws are categorized as remote code execution (RCE) vulnerabilities, exploitation requires an attacker to convince the user to open a specially crafted file.

The update is also notable for closing out five Critical severity flaws -

  • CVE-2025-21294 (CVSS score: 8.1) - Microsoft Digest Authentication Remote Code Execution Vulnerability
  • CVE-2025-21295 (CVSS score: 8.1) - SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
  • CVE-2025-21298 (CVSS score: 9.8) - Windows Object Linking and Embedding (OLE) Remote Code Execution Vulnerability
  • CVE-2025-21307 (CVSS score: 9.8) - Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
  • CVE-2025-21311 (CVSS score: 9.8) - Windows NTLM V1 Elevation of Privilege Vulnerability

"In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted email to the victim," Microsoft said in its bulletin for CVE-2025-21298.

"Exploitation of the vulnerability might involve either a victim opening a specially crafted email with an affected version of Microsoft Outlook software, or a victim's Outlook application displaying a preview of a specially crafted email . This could result in the attacker executing remote code on the victim's machine."

To safeguard against the flaw, it's recommended that users read email messages in plain text format. It's also advising the use of Microsoft Outlook to reduce the risk of users opening RTF Files from unknown or untrusted sources.

"The CVE-2025-21295 vulnerability in the SPNEGO Extended Negotiation (NEGOEX) security mechanism allows unauthenticated attackers to run malicious code remotely on affected systems without user interaction," Saeed Abbasi, manager of vulnerability research at Qualys Threat Research Unit, said.

"Despite a high attack complexity (AC:H), successful exploitation can fully compromise enterprise infrastructure by undermining a core security mechanism layer, leading to potential data breaches. Because no valid credentials are required, the risk of widespread impact is significant, highlighting the need for immediate patches and vigilant mitigation."

As for CVE-2025-21294, Microsoft said a bad actor could successfully exploit this vulnerability by connecting to a system which requires digest authentication, triggering a race condition to create a use-after-free scenario, and then leveraging it to execute arbitrary code.

"Microsoft Digest is the application responsible for performing initial authentication when a server receives the first challenge response from a client," Ben Hopkins, cybersecurity engineer at Immersive Labs, said. "The server works by checking that the client has not already been authenticated. CVE-2025-21294 involves exploitation of this process for attackers to achieve remote code execution (RCE)."

Among the list of vulnerabilities that have been tagged as more likely to be exploited is an information disclosure flaw affecting Windows BitLocker (CVE-2025-21210, CVSS score: 4.2) that could allow for the recovery of hibernation images in plaintext assuming an attacker is able to gain physical access to the victim machine's hard disk.

"Hibernation images are used when a laptop goes to sleep and contains the contents that were stored in RAM at the moment the device powered down," Kev Breen, senior director of threat research at Immersive Labs, said.

"This presents a significant potential impact as RAM can contain sensitive data (such as passwords, credentials, and PII) that may have been in open documents or browser sessions and can all be recovered with free tools from hibernation files."

Details Emerge About CVE-2025-21210

Security researcher Maxim Suhanov, who is credited with discovering and reporting the BitLocker information disclosure flaw (CVE-2025-21210), has described it as a practical randomization attack against the native encryption feature.

The vulnerability has been codenamed CrashXTS owing to its targeting of the XTS-AES mode of the AES encryption algorithm and how BitLocker handles crash dump configurations.

"In short, it's possible to block the BitLocker crash dump filter driver (dumpfve.sys) from being loaded by corrupting a single field within one registry key (HKLM\System\ControlSet001\Control\CrashControl) – in particular, the value list offset must be corrupted (randomized), so all values belonging to this key are removed (and our target is the DumpFilters value, which references the dumpfve.sys driver)," Suhanov explained.

"After this, the Windows kernel will write unencrypted hibernation images to the disk (because the kernel uses 'the crash dump way' to write hibernation images, instead of the usual filter driver called fvevol.sys, and this way now excludes the BitLocker crash dump filter driver, dumpfve.sys)."

Software Patches from Other Vendors

Besides Microsoft, security updates have also been released by other vendors over the past few weeks to rectify several vulnerabilities, including —

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/01/3-actively-exploited-zero-day-flaws.html