ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Fixes Over 130 CVEs in April Patch Tuesday

criticalVulnerability exploited in the wildimportance 60CVE-2025-29824CVE-2025-27472

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-27472
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

NVD description · AI analysis pending
5.42%
  • microsoft windows 10 1507
  • microsoft windows server 2012
CVE-2025-29824
Use-After-Free Privilege Escalation in Microsoft Windows CLFS Driver (Actively Exploited)

CVE-2025-29824 is a use-after-free flaw (CWE-416) in the Windows Common Log File System (CLFS) kernel driver, scored 7.8 (High) with a local attack vector, low privileges required, and no user interaction. An authorized local attacker can trigger it by interacting with CLFS-managed log files in a way that references freed kernel memory. Successful exploitation elevates the attacker's local privileges, typically to SYSTEM, providing full control of the host that can be chained into ransomware deployment or lateral movement. Any unpatched system running the listed Windows 10, Windows 11, or Windows Server versions is affected. The flaw was exploited as a zero-day — reportedly by Play ransomware — before Microsoft shipped fixes in the April 2025 Patch Tuesday release; it was added to CISA's KEV catalog on 2025-04-08 with known ransomware use, and EPSS estimates a 13.9% probability of continued exploitation over 30 days (96th percentile).

Do: Apply Microsoft's April 2025 Patch Tuesday security updates for your Windows version immediately — the vendor update is the only complete fix, and the flaw is on the KEV list with known ransomware use, so prioritize servers and endpoints used by privileged users. Until patched, limit untrusted local code execution and review hosts for post-exploitation privilege escalation; public detection and mitigation scripts (e.g., Vicarius) are available to help hunt for exploitation. Federal agencies must apply the vendor mitigations per BOD 22-01 deadlines or discontinue use of affected versions.

7.814% KEV ransomware PoC ×2
  • microsoft Windows 10 1507 1507
  • microsoft Windows 10 1607 1607
  • microsoft Windows 10 1809 1809
  • +9 more
massHundreds of millions of Windows devices worldwide
Full article443 words · extracted from infosecurity-magazine.com · click to collapse

System administrators have double the workload this month versus March’s Patch Tuesday announcement, after Microsoft published fixes for over 130 CVEs.

However, there was only one zero-day bug announced this month, compared to seven in March.

CVE-2025-29824 is an actively exploited elevation of privilege (EoP) vulnerability in the Windows Common Log File System (CLFS), that stems from a use-after-free condition. An attacker doesn’t need admin privileges to exploit the vulnerability – only local access.

“The vulnerability arises from improper memory handling in the CLFS driver (clfs.sys). Under certain memory manipulation conditions, a use-after-free can be triggered, which an attacker can exploit to execute code at the highest privilege level in Windows,” explained Ben McCarthy, lead cybersecurity engineer at Immersive. 

“This type of vulnerability is especially dangerous in post-compromise scenarios. Once an attacker has a foothold on a machine – via phishing, malware, or other vectors – they can exploit the CLFS bug to elevate privileges, maintain persistence, and move laterally across an enterprise network. It is a favored class of vulnerability in targeted attacks and ransomware operations.”

Read more on Patch Tuesday: Microsoft Patches Eight Zero-Days to Start the Year

Updates are only currently available for Windows Server and Windows 11. Users of Windows 10 for x64-and 32-bit systems will have to wait. This leaves a potentially “critical gap in defense” for a large number of Windows users, warned McCarthy.

“In the absence of a security update, organizations should take proactive steps to mitigate risk. Security teams are advised to monitor the CLFS driver closely using EDR/XDR tools,” he said.

“This includes watching for processes interacting with clfs.sys, being spawned by it, or showing anomalous behavior when communicating with other drivers or memory spaces. Until a patch is made available, visibility and endpoint behavior analysis are the most effective defenses against exploitation of this actively abused vulnerability.”

EoP vulnerabilities were by far the most common type fixed this Patch Tuesday, with Microsoft issuing updates for 49 in total. Next came remote code execution (31) and information disclosure (17) CVEs.

Beyond CVSS

Tyler Reguly, associate director, security R&D, at Fortra, argued that security teams need to look beyond severity scores to prioritize patching.

“This is a month that really demonstrates that CVSS severity is not necessarily the best metric for prioritization. CVE-2025-29824 has a base score of 7.8, while another vulnerability that I would pay attention to, CVE-2025-27472, only has a base score of 5.4,” he explained.

“In the case of Microsoft, prioritization is better done utilizing the Microsoft Exploitability Index and focusing on vulnerabilities with an index of 0 (exploitation detected) or 1 (exploitation more likely).”

Image credit: Below the Sky / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-fixes-130-cves-april/