ZeroHour
CyberScooppublished ()ingested @CyberScoopNews1

Microsoft patches zero-day actively exploited in string of ransomware attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-27480
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.112%
  • microsoft windows server 2012
  • microsoft windows server 2016
  • microsoft windows server 2019
  • +1 more
CVE-2025-27482
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.12%
  • microsoft windows server 2016
  • microsoft windows server 2019
  • microsoft windows server 2022
  • +1 more
CVE-2025-29792
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.31%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
CVE-2025-29794
+1 in the same advisory: …29793
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

NVD description · AI analysis pending
8.8
group max
5%
  • microsoft sharepoint enterprise server
  • microsoft sharepoint server
CVE-2025-29824
Use-After-Free Privilege Escalation in Microsoft Windows CLFS Driver (Actively Exploited)

CVE-2025-29824 is a use-after-free flaw (CWE-416) in the Windows Common Log File System (CLFS) kernel driver, scored 7.8 (High) with a local attack vector, low privileges required, and no user interaction. An authorized local attacker can trigger it by interacting with CLFS-managed log files in a way that references freed kernel memory. Successful exploitation elevates the attacker's local privileges, typically to SYSTEM, providing full control of the host that can be chained into ransomware deployment or lateral movement. Any unpatched system running the listed Windows 10, Windows 11, or Windows Server versions is affected. The flaw was exploited as a zero-day — reportedly by Play ransomware — before Microsoft shipped fixes in the April 2025 Patch Tuesday release; it was added to CISA's KEV catalog on 2025-04-08 with known ransomware use, and EPSS estimates a 13.9% probability of continued exploitation over 30 days (96th percentile).

Do: Apply Microsoft's April 2025 Patch Tuesday security updates for your Windows version immediately — the vendor update is the only complete fix, and the flaw is on the KEV list with known ransomware use, so prioritize servers and endpoints used by privileged users. Until patched, limit untrusted local code execution and review hosts for post-exploitation privilege escalation; public detection and mitigation scripts (e.g., Vicarius) are available to help hunt for exploitation. Federal agencies must apply the vendor mitigations per BOD 22-01 deadlines or discontinue use of affected versions.

7.814% KEV ransomware PoC ×2
  • microsoft Windows 10 1507 1507
  • microsoft Windows 10 1607 1607
  • microsoft Windows 10 1809 1809
  • +9 more
massHundreds of millions of Windows devices worldwide
Full article844 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Microsoft said Storm-2460 has exploited the zero-day in the Windows Common Log File System to attack organizations in the U.S., Venezuela, Spain and Saudi Arabia.

Listen to this article

0:00

Learn more.

A view of the Microsoft corporate logo in front of the Microsoft Office building on 41st street and 8th avenue on July 19, 2024 in New York City. (Photo by Craig T Fruchtman/Getty Images)

Microsoft addressed 126 vulnerabilities affecting its systems and core products, including a zero-day in the Windows Common Log File System (CLFS) that’s been actively exploited in a series of ransomware attacks, the company said in its latest security update Tuesday.

A group Microsoft tracks as Storm-2460 has exploited CVE-2025-29824 to initiate ransomware attacks “against a small number of targets,” Microsoft Threat Intelligence said in a research note released Tuesday. Victims include organizations in the IT and real estate sectors in the United States, the financial sector in Venezuela, a Spanish software company and the retail sector in Saudi Arabia, according to Microsoft.

Microsoft said it’s unsure how Storm-2460 gained initial access to devices on these networks, but noted successful exploitation of the software defect allows an attacker running a standard user account to escalate privileges. The zero-day, which Storm-2460 deployed via PipeMagic malware, has a CVSS score of 7.8.

“Ransomware threat actors value post-compromise elevation of privilege exploits because these could enable them to escalate initial access, including handoffs from commodity malware distributors, into privileged access,” Microsoft Threat Intelligence researchers said in the blog post. “They then use privileged access for widespread deployment and detonation of ransomware within an environment.”

Mike Walters, president and co-founder at Action1, said CVE-2025-29824 “is significant because it affects a core component of Windows, impacting a wide range of environments, including enterprise systems and critical infrastructure.”

Attackers can exploit the vulnerability to gain the highest privilege on a Windows system, Walters said. This allows attackers to install malware, modify system files and registry settings, disable security features, access sensitive data and maintain persistent access, resulting in full system compromise and lateral movement across networks, Walters added. 

CLFS vulnerabilities are common in Microsoft’s monthly security updates, according to Satnam Narang, senior staff research engineer at Tenable. “Since 2022, Microsoft has patched 32 CLFS vulnerabilities, averaging 10 each year, with six exploited in the wild,” Narang said in an email.

“Elevation of privilege flaws in CLFS have become especially popular among ransomware operators over the years,” Narang said. “While remote code execution flaws are consistently top overall Patch Tuesday figures, the data is reversed for zero-day exploitation. For the past two years, elevation of privilege flaws have led the pack and, so far in 2025, account for over half of all zero-days exploited.”

More than 40% of the vulnerabilities Microsoft patched on Tuesday allow attackers to achieve elevation of privileges, Narang said.

The batch of patches Microsoft released this month marks the vendor’s fourth monthly security update to include more than 100 vulnerabilities in the past year, and the second set of triple-digit defects in 2025 thus far. 

“For the first time in years, none of the vulnerabilities have a publicly available proof of concept,” Walters said.

Eighteen of the vulnerabilities in this month’s security update affect Microsoft Office and standalone Office products. All of the software defects affecting Microsoft Office are high-severity, and Microsoft designated three of those vulnerabilities — CVE-2025-29792, CVE-2025-29793 and CVE-2025-29794 — as “more likely” to be exploited.

Overall, Microsoft said 11 of the vulnerabilities it patched this month are “more likely” to be exploited. This set of more concerning flaws includes a pair of high-severity software defects — CVE-2025-27480 and CVE-2025-27482 — that could allow for remote code execution in Remote Desktop Gateway Service.

The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-april-2025/