Microsoft Patch Tuesday updates for January 2025 fixed three actively exploited flaws
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-21297 | Windows Remote Desktop Services Remote Code Execution Vulnerability Windows Remote Desktop Services Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.1 | 1% |
| — | ||
| CVE-2025-21298 | Use-After-Free RCE in Windows OLE (CVE-2025-21298) CVE-2025-21298 is a use-after-free (CWE-416) vulnerability in the Windows OLE (Object Linking and Embedding) component that permits remote code execution. According to the published CVSS vector, it is network-exploitable without privileges or user interaction, triggered when the system processes maliciously crafted OLE content. A successful attacker gains arbitrary code execution in the context of the affected process, with high impact on confidentiality, integrity, and availability. The flaw affects nearly the entire supported Windows estate — Windows 10 1507 through 22H2, Windows 11 22H2 through 24H2, and Windows Server 2008 through 2019. As of the January 2025 Patch Tuesday release there is no known public proof-of-concept or confirmed in-the-wild exploitation, but the EPSS score of 80.9% (100th percentile) indicates a very high probability of exploitation within 30 days. Do: Apply Microsoft's January 2025 Windows cumulative security updates to all affected Windows 10/11 and Windows Server hosts immediately, prioritizing internet-facing and server systems given the network-exploitable, critical rating. Verify via patch-reporting tools that the OLE update is present on each host; no vendor mitigations were noted in the available data, so updating is the primary defense. Although no exploitation is confirmed yet, the 80.9% EPSS score argues for completing remediation before a PoC or in-the-wild exploitation emerges. | 9.8 | 81% |
| mass≈1 billion+ Windows installations (essentially the entire supported Windows client and Server estate) | ||
| CVE-2025-21309 | Windows Remote Desktop Services Remote Code Execution Vulnerability Windows Remote Desktop Services Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.1 | 15% |
| — | ||
| CVE-2025-21333 | Actively Exploited Heap Overflow in Windows Hyper-V VSP Enables Privilege Escalation CVE-2025-21333 is a heap-based buffer overflow (CWE-122) in the Windows Hyper-V NT Kernel Integration VSP, which Microsoft classifies as an elevation of privilege vulnerability. An attacker who already has low-privileged access to an affected system can trigger the overflow in this virtualization service provider component to gain higher privileges on the host, with high impact on confidentiality, integrity and availability (CVSS 3.1 score 7.8, local attack vector, no user interaction required). The flaw affects Windows 10 21H2 and 22H2, Windows 11 22H2, 23H2 and 24H2, Windows Server 2022 23H2, and Windows Server 2025. Microsoft patched it in the January 2025 Patch Tuesday release (part of a batch of eight zero-days), and it was exploited as a zero-day before the patch was available: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14 with ransomware use listed as unknown. A public proof-of-concept is available via Exploit-DB, so defenders should treat in-the-wild exploitation as confirmed. Do: Apply Microsoft's January 2025 Patch Tuesday security updates (released 2025-01-14) to all systems running Windows 10 21H2/22H2, Windows 11 22H2/23H2/24H2, Windows Server 2022 23H2 or Windows Server 2025, prioritizing this KEV-listed, actively exploited zero-day; where updates cannot be applied, follow vendor mitigations or discontinue use of the affected versions per CISA's required action. Because the attack requires local access, prioritize patching multi-user hosts, VDI and terminal servers, and during threat hunting review endpoints for signs that malware or low-privileged users previously escalated privileges via the Hyper-V VSP component. | 7.8 | 10% | KEV PoC |
| mass≈hundreds of millions of Windows endpoints potentially affected (affected versions span most of the Windows 10/11 install base), though only systems with… |
Full article331 words · extracted from securityaffairs.com · click to collapse

Microsoft Patch Tuesday security updates for January 2025 addressed 161 vulnerabilities, including three actively exploited issues.
Microsoft Patch Tuesday security updates for January 2025 addressed 161 vulnerabilities in Windows and Windows Components, Office and Office Components, Hyper-V, SharePoint Server, .NET and Visual Studio, Azure, BitLocker, Remote Desktop Services, and Windows Virtual Trusted Platform Module.
11 of these vulnerabilities are rated Critical, and the other are rated Important in severity. ZDI researchers pointed out that this is the largest number of vulnerabilities addressed in by Microsoft montly security updates since 2017.
Five vulnerabilities are publicly known, while three flaws in Windows Hyper-V NT Kernel Integration VSP (CVE-2025-21333, CVE-2025-21334, and CVE-2025-21335, CVSS scores of 7.8) are actively exploited in the wild.
These three flaws are Elevation of Privilege issues in Hyper-V, authenticated users can exploit them to execute code with SYSTEM privileges.
Another interesting issue addressed with the release of Patch Tuesday security updates is a Windows OLE Remote Code Execution Vulnerability tracked as CVE-2025-21298 (CVSS score of 9.8).
A remote attacker can exploit the vulnerability to execute code on a target system by sending a specially crafted mail to an affected system with Outlook. The experts explained that the preview pane is not an attack vector, but previewing an attachment could trigger the code execution. The flaw is related the RTF files parsing.
A lack of validation of user-supplied data causes memory corruption. Experts to install the patch immediately, however mitigation includes reading mail in Outlook as plain text.
Microsoft also fixed a couple of Windows Remote Desktop Services Remote Code Execution issues tracked as CVE-2025-21297/CVE-2025-21309. Both vulnerabilities allow remote, unauthenticated attackers to execute arbitrary code by triggering a race condition. Exploitation requires no user interaction.
The full list of vulnerabilities addressed by Microsoft with Microsoft Patch Tuesday security updates for January 2025 is available here.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Microsoft Patch Tuesday)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/173102/security/microsoft-patch-tuesday-updates-for-january-2025.html