Microsoft Patches Eight Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-21186 | Microsoft Access Remote Code Execution Vulnerability Microsoft Access Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2025-21275 | Windows App Package Installer Elevation of Privilege Vulnerability Windows App Package Installer Elevation of Privilege Vulnerability NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-21298 | Use-After-Free RCE in Windows OLE (CVE-2025-21298) CVE-2025-21298 is a use-after-free (CWE-416) vulnerability in the Windows OLE (Object Linking and Embedding) component that permits remote code execution. According to the published CVSS vector, it is network-exploitable without privileges or user interaction, triggered when the system processes maliciously crafted OLE content. A successful attacker gains arbitrary code execution in the context of the affected process, with high impact on confidentiality, integrity, and availability. The flaw affects nearly the entire supported Windows estate — Windows 10 1507 through 22H2, Windows 11 22H2 through 24H2, and Windows Server 2008 through 2019. As of the January 2025 Patch Tuesday release there is no known public proof-of-concept or confirmed in-the-wild exploitation, but the EPSS score of 80.9% (100th percentile) indicates a very high probability of exploitation within 30 days. Do: Apply Microsoft's January 2025 Windows cumulative security updates to all affected Windows 10/11 and Windows Server hosts immediately, prioritizing internet-facing and server systems given the network-exploitable, critical rating. Verify via patch-reporting tools that the OLE update is present on each host; no vendor mitigations were noted in the available data, so updating is the primary defense. Although no exploitation is confirmed yet, the 80.9% EPSS score argues for completing remediation before a PoC or in-the-wild exploitation emerges. | 9.8 group max | 81% |
| mass≈1 billion+ Windows installations (essentially the entire supported Windows client and Server estate) | ||
| CVE-2025-21311 | Windows NTLM V1 Elevation of Privilege Vulnerability Windows NTLM V1 Elevation of Privilege Vulnerability NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2025-21333 | Actively Exploited Heap Overflow in Windows Hyper-V VSP Enables Privilege Escalation CVE-2025-21333 is a heap-based buffer overflow (CWE-122) in the Windows Hyper-V NT Kernel Integration VSP, which Microsoft classifies as an elevation of privilege vulnerability. An attacker who already has low-privileged access to an affected system can trigger the overflow in this virtualization service provider component to gain higher privileges on the host, with high impact on confidentiality, integrity and availability (CVSS 3.1 score 7.8, local attack vector, no user interaction required). The flaw affects Windows 10 21H2 and 22H2, Windows 11 22H2, 23H2 and 24H2, Windows Server 2022 23H2, and Windows Server 2025. Microsoft patched it in the January 2025 Patch Tuesday release (part of a batch of eight zero-days), and it was exploited as a zero-day before the patch was available: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14 with ransomware use listed as unknown. A public proof-of-concept is available via Exploit-DB, so defenders should treat in-the-wild exploitation as confirmed. Do: Apply Microsoft's January 2025 Patch Tuesday security updates (released 2025-01-14) to all systems running Windows 10 21H2/22H2, Windows 11 22H2/23H2/24H2, Windows Server 2022 23H2 or Windows Server 2025, prioritizing this KEV-listed, actively exploited zero-day; where updates cannot be applied, follow vendor mitigations or discontinue use of the affected versions per CISA's required action. Because the attack requires local access, prioritize patching multi-user hosts, VDI and terminal servers, and during threat hunting review endpoints for signs that malware or low-privileged users previously escalated privileges via the Hyper-V VSP component. | 7.8 | 10% | KEV PoC |
| mass≈hundreds of millions of Windows endpoints potentially affected (affected versions span most of the Windows 10/11 install base), though only systems with… |
Full article396 words · extracted from infosecurity-magazine.com · click to collapse
Microsoft released security updates for eight zero-day flaws in its first Patch Tuesday of 2025, with three of the vulnerabilities under active exploitation.
Microsoft defines zero-day vulnerabilities as software flaws that have either been publicly disclosed or are being actively exploited, with no patch available.
The three zero-days it fixed that belong to the latter group are CVE-2025-21333, CVE-2025-21334 and CVE-2025-21335. They’re described as Windows Hyper-V NT Kernel Integration VSP elevation of privilege (EoP) bugs, with a CVSS score of 7.8.
Immersive Labs senior director of threat research, Kev Breen, warned sysadmins not to be fooled by the relatively low CVSS score, given that Hyper-V is “heavily embedded” in Windows 11 and used for a range of security tasks, including device guard and credential guard.
“Very little information is provided by Microsoft about how threat actors are exploiting this vulnerability. However, they are listed as EoP vulnerabilities – meaning that if an attacker has already gained access to a host through something like a phishing attack, then they could use these vulnerabilities to gain system-level permissions on the infected device,” he explained.
“With system-level permissions, threat actors can enable other attack vectors like disabling security tooling or dumping credentials with tools like mimikatz to pivot across enterprise domains. These techniques are frequently observed by both nation-state and financially motivated groups like ransomware operators.”
Read more on Patch Tuesday: Microsoft Fixes Four Zero-Days in July Patch Tuesday
The five publicly disclosed zero-days, which are currently not being exploited, are:
- CVE-2025-21275: A Windows App Package Installer EoP vulnerability
- CVE-2025-21308: A Windows Themes spoofing vulnerability
- CVE-2025-21186, CVE-2025-21366 and CVE-2025-21395: Remote code execution (RCE) vulnerabilities in Microsoft Access
Tyler Reguly, associate director, Security R&D, at Fortra, also flagged three critical CVEs in this month’s Patch Tuesday with CVSS scores of 9.8.
- CVE-2025-21311: A Windows NTLM V1 EoP vulnerability
- CVE-2025-21307: An unauthenticated RCE vulnerability in the Windows Reliable Multicast Transport Driver (RMCAST), when listening on a Pragmatic General Multicast (PGM) port
- CVE-2025-21298: An RCE vulnerability in Windows OLE
With over 150 CVEs addressed by Microsoft this month, patch management must be automated if organizations are to keep their heads above water, Reguly argued.
“Patching vulnerabilities should not be a solo endeavour in the enterprise and, if it is, it may be time to talk to your leadership about staffing and tooling changes,” he added.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-patches-eight-zerodays/