ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-49142
Microsoft Access Remote Code Execution Vulnerability

Microsoft Access Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.81%
  • microsoft 365 apps
  • microsoft access
  • microsoft office
  • +1 more
CVE-2025-21186
+2 in the same advisory: …21366 …21395
Microsoft Access Remote Code Execution Vulnerability

Microsoft Access Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.81%
  • microsoft 365 apps
  • microsoft access
  • microsoft office
  • +1 more
CVE-2025-21298
+1 in the same advisory: …21210
Use-After-Free RCE in Windows OLE (CVE-2025-21298)

CVE-2025-21298 is a use-after-free (CWE-416) vulnerability in the Windows OLE (Object Linking and Embedding) component that permits remote code execution. According to the published CVSS vector, it is network-exploitable without privileges or user interaction, triggered when the system processes maliciously crafted OLE content. A successful attacker gains arbitrary code execution in the context of the affected process, with high impact on confidentiality, integrity, and availability. The flaw affects nearly the entire supported Windows estate — Windows 10 1507 through 22H2, Windows 11 22H2 through 24H2, and Windows Server 2008 through 2019. As of the January 2025 Patch Tuesday release there is no known public proof-of-concept or confirmed in-the-wild exploitation, but the EPSS score of 80.9% (100th percentile) indicates a very high probability of exploitation within 30 days.

Do: Apply Microsoft's January 2025 Windows cumulative security updates to all affected Windows 10/11 and Windows Server hosts immediately, prioritizing internet-facing and server systems given the network-exploitable, critical rating. Verify via patch-reporting tools that the OLE update is present on each host; no vendor mitigations were noted in the available data, so updating is the primary defense. Although no exploitation is confirmed yet, the 80.9% EPSS score argues for completing remediation before a PoC or in-the-wild exploitation emerges.

9.8
group max
81%
  • microsoft Windows 10 1507
  • microsoft Windows 10 1607
  • microsoft Windows 10 1809
  • +9 more
mass≈1 billion+ Windows installations (essentially the entire supported Windows client and Server estate)
CVE-2025-21311
Windows NTLM V1 Elevation of Privilege Vulnerability

Windows NTLM V1 Elevation of Privilege Vulnerability

NVD description · AI analysis pending
9.82%
  • microsoft windows 11 24h2
  • microsoft windows server 2022 23h2
  • microsoft windows server 2025
CVE-2025-21333
+2 in the same advisory: …21334 …21335
Actively Exploited Heap Overflow in Windows Hyper-V VSP Enables Privilege Escalation

CVE-2025-21333 is a heap-based buffer overflow (CWE-122) in the Windows Hyper-V NT Kernel Integration VSP, which Microsoft classifies as an elevation of privilege vulnerability. An attacker who already has low-privileged access to an affected system can trigger the overflow in this virtualization service provider component to gain higher privileges on the host, with high impact on confidentiality, integrity and availability (CVSS 3.1 score 7.8, local attack vector, no user interaction required). The flaw affects Windows 10 21H2 and 22H2, Windows 11 22H2, 23H2 and 24H2, Windows Server 2022 23H2, and Windows Server 2025. Microsoft patched it in the January 2025 Patch Tuesday release (part of a batch of eight zero-days), and it was exploited as a zero-day before the patch was available: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14 with ransomware use listed as unknown. A public proof-of-concept is available via Exploit-DB, so defenders should treat in-the-wild exploitation as confirmed.

Do: Apply Microsoft's January 2025 Patch Tuesday security updates (released 2025-01-14) to all systems running Windows 10 21H2/22H2, Windows 11 22H2/23H2/24H2, Windows Server 2022 23H2 or Windows Server 2025, prioritizing this KEV-listed, actively exploited zero-day; where updates cannot be applied, follow vendor mitigations or discontinue use of the affected versions per CISA's required action. Because the attack requires local access, prioritize patching multi-user hosts, VDI and terminal servers, and during threat hunting review endpoints for signs that malware or low-privileged users previously escalated privileges via the Hyper-V VSP component.

7.810% KEV PoC
  • microsoft Windows 10 21H2
  • microsoft Windows 10 22H2
  • microsoft Windows 11 22H2
  • +4 more
mass≈hundreds of millions of Windows endpoints potentially affected (affected versions span most of the Windows 10/11 install base), though only systems with…
Full article753 words · extracted from krebsonsecurity.com · click to collapse

Microsoft today unleashed updates to plug a whopping 161 security vulnerabilities in Windows and related software, including three “zero-day” weaknesses that are already under active attack. Redmond’s inaugural Patch Tuesday of 2025 bundles more fixes than the company has shipped in one go since 2017.

Rapid7‘s Adam Barnett says January marks the fourth consecutive month where Microsoft has published zero-day vulnerabilities on Patch Tuesday without evaluating any of them as critical severity at time of publication. Today also saw the publication of nine critical remote code execution (RCE) vulnerabilities.

The Microsoft flaws already seeing active attacks include CVE-2025-21333, CVE-2025-21334 and, you guessed it– CVE-2025-21335. These are sequential because all reside in Windows Hyper-V, a component that is heavily embedded in modern Windows 11 operating systems and used for security features including device guard and credential guard.

Tenable’s Satnam Narang says little is known about the in-the-wild exploitation of these flaws, apart from the fact that they are all “privilege escalation” vulnerabilities. Narang said we tend to see a lot of elevation of privilege bugs exploited in the wild as zero-days in Patch Tuesday because it’s not always initial access to a system that’s a challenge for attackers as they have various avenues in their pursuit.

“As elevation of privilege bugs, they’re being used as part of post-compromise activity, where an attacker has already accessed a target system,” he said. “It’s kind of like if an attacker is able to enter a secure building, they’re unable to access more secure parts of the facility because they have to prove that they have clearance. In this case, they’re able to trick the system into believing they should have clearance.”

Several bugs addressed today earned CVSS (threat rating) scores of 9.8 out of a possible 10, including CVE-2025-21298, a weakness in Windows that could allow attackers to run arbitrary code by getting a target to open a malicious .rtf file, documents typically opened on Office applications like Microsoft Word. Microsoft has rated this flaw “exploitation more likely.”

Ben Hopkins at Immersive Labs called attention to the CVE-2025-21311, a 9.8 “critical” bug in Windows NTLMv1 (NT LAN Manager version 1), an older Microsoft authentication protocol that is still used by many organizations.

“What makes this vulnerability so impactful is the fact that it is remotely exploitable, so attackers can reach the compromised machine(s) over the internet, and the attacker does not need significant knowledge or skills to achieve repeatable success with the same payload across any vulnerable component,” Hopkins wrote.

Kev Breen at Immersive points to an interesting flaw (CVE-2025-21210) that Microsoft fixed in its full disk encryption suite Bitlocker that the software giant has dubbed “exploitation more likely.” Specifically, this bug holds out the possibility that in some situations the hibernation image created when one closes the laptop lid on an open Windows session may not be fully encrypted and could be recovered in plain text.

“Hibernation images are used when a laptop goes to sleep and contains the contents that were stored in RAM at the moment the device powered down,” Breen noted. “This presents a significant potential impact as RAM can contain sensitive data (such as passwords, credentials and PII) that may have been in open documents or browser sessions and can all be recovered with free tools from hibernation files.”

Tenable’s Narang also highlighted a trio of vulnerabilities in Microsoft Access fixed this month and credited to Unpatched.ai, a security research effort that is aided by artificial intelligence looking for vulnerabilities in code. Tracked as CVE-2025-21186, CVE-2025-21366, and CVE-2025-21395, these are remote code execution bugs that are exploitable if an attacker convinces a target to download and run a malicious file through social engineering. Unpatched.ai was also credited with discovering a flaw in the December 2024 Patch Tuesday release (CVE-2024-49142).

“Automated vulnerability detection using AI has garnered a lot of attention recently, so it’s noteworthy to see this service being credited with finding bugs in Microsoft products,” Narang observed. “It may be the first of many in 2025.”

If you’re a Windows user who has automatic updates turned off and haven’t updated in a while, it’s probably time to play catch up. Please consider backing up important files and/or the entire hard drive before updating. And if you run into any problems installing this month’s patch batch, drop a line in the comments below, please.

Further reading on today’s patches from Microsoft:

Tenable blog

SANS Internet Storm Center

Ask Woody

Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2025/01/microsoft-happy-2025-heres-161-security-updates/