ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Fixes Another Two Actively Exploited Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-21194
Microsoft Surface Security Feature Bypass Vulnerability

Microsoft Surface Security Feature Bypass Vulnerability

NVD description · AI analysis pending
7.1<1%
  • microsoft surface hub 2s firmware
  • microsoft surface pro 8 for business 1983 firmware
  • microsoft surface laptop go firmware
  • +1 more
CVE-2025-21377
NTLM Hash Disclosure Spoofing Vulnerability in Windows and Windows Server

CVE-2025-21377 is an NTLM hash disclosure (spoofing) vulnerability in Microsoft Windows, tracked as CWE-73 (external control of file name or path). An attacker who can get a user to interact with attacker-influenced content, such as a crafted file or path reference, can cause Windows to authenticate or respond in a way that leaks the user's NTLM hash to an endpoint the attacker controls, consistent with the CVSS vector's network vector and required user interaction. The attacker gains the user's NTLM hash, which can be cracked offline or replayed to authenticate as (spoof) that user; the flaw affects confidentiality only, with no direct integrity or availability impact. Any user or server running the affected Windows releases is exposed, with the risk highest where users handle untrusted files or where NTLM authentication is permitted. As of the February 2025 Patch Tuesday coverage, this flaw is not reported as actively exploited and is not on the CISA KEV, with no public proof-of-concept known, though its high EPSS percentile (98th, ~24.5% chance of exploitation within 30 days) indicates elevated exploitation risk.

Do: Apply the February 2025 (or later) Windows security updates from Windows Update or the Microsoft Update Catalog on all affected Windows 10/11 clients and Windows Server 2008/2012/2016/2019 hosts. As interim hardening, restrict outbound NTLM authentication where feasible (e.g., limiting NTLM via group policy or blocking legacy NTLM traffic), since the flaw leaks NTLM hashes that can be cracked or replayed. Because this is not yet in CISA KEV and no public PoC is known, it can be prioritized within normal patch cycles, but the high EPSS score argues for patching internet-facing and file-handling systems first.

6.524%
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008 supported releases as covered by the February 2025 security updates
  • +3 more
mass≈1 billion+ Windows installations (affected versions span nearly the entire supported Windows client and server installed base)
CVE-2025-21418
+1 in the same advisory: …21391
Local Privilege Escalation via Heap Overflow in Windows WinSock AFD Driver

CVE-2025-21418 is a heap-based buffer overflow (CWE-122) in the Windows Ancillary Function Driver for WinSock (AFD.sys), a kernel-mode driver that services Winsock auxiliary socket operations. A local attacker with limited user privileges can trigger the overflow by issuing crafted Winsock requests to the AFD driver, requiring no user interaction. Successful exploitation elevates the attacker's privileges on the local machine (confidentiality, integrity, and availability all impacted), which is typically used to gain SYSTEM-level control as part of a broader intrusion or ransomware chain. Any system running the affected Windows 10, Windows 11, or Windows Server releases is exposed, since the AFD driver is a core component present on all of them. The flaw was a zero-day exploited in the wild before Microsoft patched it in the February 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-11.

Do: Deploy Microsoft's February 2025 Patch Tuesday security updates for the affected Windows 10/11 and Windows Server releases immediately, prioritizing multi-user servers, jump hosts, and endpoints in ransomware-prone environments since exploitation was already active before patching. Verify deployment through your patch management/SCCM update history; there is no public PoC or known standalone mitigation, so patching is the required action per the CISA KEV entry.

7.8
group max
2% KEV
  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008 supported editions as listed
  • +4 more
masson the order of 1 billion+ Windows devices (all listed Windows 10/11 client and Windows Server releases)
Full article417 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft has been forced to issue security updates for four more zero-day vulnerabilities, including two currently under active exploitation.

The tech giant’s February Patch Tuesday update round features fixes for over 50 CVEs, including 22 remote code execution (RCE) bugs, 19 elevation of privilege (EoP) flaws and two security feature bypass vulnerabilities.

The CVEs under active exploitation include CVE-2025-21391, a Windows Storage EoP bug with a CVSS score of 7.1.

“At first glance, it ‘only’ allows deleting targeted files, yet the real power lies in pairing it with code execution to escalate privileges. It poses no threat to confidentiality but can strike hard at integrity and availability – leaving servers crippled if key data is removed,” explained Saeed Abbasi, manager of vulnerability research at Qualys Threat Research Unit (TRU).

“Technically, the bug leverages an arbitrary file/folder deletion in Windows, allowing attackers to remove a crucial system item and recreate it with weak permissions. This tricks Windows into running attacker-controlled content, ultimately granting system-level access. In other words, don’t dismiss this as a minor bug: it’s a stealthy stepping stone to full control of a system.”

Read more on Patch Tuesday: Microsoft Patches Eight Zero-Days to Start the Year

The second actively exploited zero-day vulnerability is CVE-2025-21418 – another EoP bug, but this time in the Windows Ancillary Function Driver (AFD) for WinSock. It applies to all Windows versions containing the vulnerable AFD.sys driver, including Windows 10, Windows 11, Windows Server 2016 and later, according to Action1 co-founder, Alex Vovk.

“Successful exploitation grants system privileges, the highest level in Windows, allowing an attacker to install programs, manipulate data, create accounts with full user rights and modify system configurations and security settings,” he added.

“Potential attack paths include gaining initial access through social engineering or malware, leveraging the vulnerability to escalate privileges. If combined with an RCE vulnerability, an attacker could remotely compromise a system, elevate privileges to system, disable security tools to evade detection and execute multi-stage attacks to infiltrate secure environments.”

The two publicly disclosed zero-days which so far haven’t been exploited in the wild are:

  • CVE-2025-21194 – a Microsoft Surface security feature bypass bug which relates to “virtual machines within a Unified Extensible Firmware Interface (UEFI) host machine,” according to Microsoft. On certain hardware it may be possible to bypass the UEFI and compromise the hypervisor and secure kernel
  • CVE-2025-21377 – an NTLM hash disclosure spoofing vulnerability which could allow a remote attacker to login masquerading as a legitimate user

Image credit: Ken Wolter / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-fixes-two-actively/