Microsoft Patch Tuesday for February 2025 — Snort rules and prominent vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-21177 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2025-21371 | Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 group max | 2% |
| — | ||
| CVE-2025-21198 | Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.0 | <1% |
| — | ||
| CVE-2025-21410 +1 in the same advisory: …21208 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2025-21379 | DHCP Client Service Remote Code Execution Vulnerability DHCP Client Service Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.1 | <1% |
| — | ||
| CVE-2025-21381 | Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2025-21418 +1 in the same advisory: …21391 | Local Privilege Escalation via Heap Overflow in Windows WinSock AFD Driver CVE-2025-21418 is a heap-based buffer overflow (CWE-122) in the Windows Ancillary Function Driver for WinSock (AFD.sys), a kernel-mode driver that services Winsock auxiliary socket operations. A local attacker with limited user privileges can trigger the overflow by issuing crafted Winsock requests to the AFD driver, requiring no user interaction. Successful exploitation elevates the attacker's privileges on the local machine (confidentiality, integrity, and availability all impacted), which is typically used to gain SYSTEM-level control as part of a broader intrusion or ransomware chain. Any system running the affected Windows 10, Windows 11, or Windows Server releases is exposed, since the AFD driver is a core component present on all of them. The flaw was a zero-day exploited in the wild before Microsoft patched it in the February 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-11. Do: Deploy Microsoft's February 2025 Patch Tuesday security updates for the affected Windows 10/11 and Windows Server releases immediately, prioritizing multi-user servers, jump hosts, and endpoints in ransomware-prone environments since exploitation was already active before patching. Verify deployment through your patch management/SCCM update history; there is no public PoC or known standalone mitigation, so patching is the required action per the CISA KEV entry. | 7.8 group max | 2% | KEV |
| masson the order of 1 billion+ Windows devices (all listed Windows 10/11 client and Windows Server releases) | |
| CVE-2025-21400 | Improper Authorization Leads to Remote Code Execution in Microsoft SharePoint Server CVE-2025-21400 is a remote code execution vulnerability in Microsoft SharePoint Server caused by improper authorization (CWE-285). According to the CVSS vector, exploitation occurs over the network with low attack complexity, but requires the attacker to hold low-privileged (authenticated) credentials and involves user interaction to trigger. Successful exploitation could allow arbitrary code execution in the context of the SharePoint server, with high impact on confidentiality, integrity, and availability. Organizations running affected on-premises SharePoint Server deployments are affected; the fix shipped in Microsoft's February 2025 Patch Tuesday, which addressed 63 vulnerabilities. There is no public proof-of-concept and no confirmed in-the-wild exploitation yet, but the high EPSS score (34.5%, 98th percentile) suggests a substantial probability of exploitation within 30 days. Do: Apply the February 2025 security updates from Microsoft for all affected SharePoint Server versions as soon as possible, prioritizing internet-facing servers. Until patched, restrict network access to SharePoint from untrusted sources and review authentication and application logs for anomalous activity. No public PoC or in-the-wild exploitation is known, but the elevated EPSS probability warrants treating this patch cycle as high priority. | 8.0 | 34% |
| mass≈100,000+ internet-exposed SharePoint servers, with total on-premises deployments plausibly in the hundreds of thousands (well over 1 million enterprise users) |
Full article738 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, February 11, 2025 14:24
Microsoft has released its monthly security update for February of 2025 which includes 63 vulnerabilities affecting a range of products, including 4 that Microsoft marked as “critical” and one marked as "moderate."
There are two notable "critical" vulnerabilities. The first is CVE-2025-21376, which is a remote code execution (RCE) vulnerability affecting the Windows Lightweight Directory Access Protocol (LDAP). This vulnerability is a remote unauthenticated Out-of-bounds Write (OOBW) caused by a race condition in LDAP and could potentially result in arbitrary code execution in the Local Security Authority Subsystem Service (lsass.exe). This is a process in the Microsoft Windows operating systems that is responsible for enforcing the security policy on the system. Successful exploitation of this vulnerability requires an attacker to win a race condition. CVE-2025-21376 has been assigned a CVSS 3.1 score of 8.1 and is considered “more likely to be exploited” by Microsoft.
CVE-2025-21379 is another notable critical remote code execution vulnerability. It was found in the DHCP Client Service and was also patched this month. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on vulnerable systems. The attacker must inject themselves into the logical network path between the target and the resource requested by the victim to read or modify network communications. This vulnerability has been assigned a CVSS 3.1 score of 7.1 and is considered "less likely to be exploited” by Microsoft.
CVE-2025-21177 is a critical privilege escalation vulnerability in the Microsoft Dynamics 365 Sales customer relationship management (CRM) software. A Server-Side Request Forgery (SSRF) allows an authorized attacker to elevate privileges over a network.
CVE-2025-21381 is a critical remote code execution vulnerability affecting Microsoft Excel and could enable an attacker to execute arbitrary code on vulnerable systems. This vulnerability could be triggered via the preview pane in affected applications. This vulnerability has been listed "less likely to be exploited" by Microsoft.
CVE-2025-21368 and CVE-2025-21369 are RCE vulnerabilities flagged "important" by Microsoft. They have a CVS 3.1 score of 8.8. To successfully exploit one of these remote code execution vulnerability, an attacker could send a malicious logon request to the target domain controller. Any authenticated attacker could trigger these vulnerabilities. It does not require admin or other elevated privileges.
CVE-2025-21400 is also an RCE vulnerability flagged "important" by Microsoft, affecting the Microsoft SharePoint Server. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on vulnerable systems. This attack requires a client to connect to a malicious server and could allow an attacker to gain code execution on the client. Microsoft considers this vulnerability as "more likely to be exploited".
CVE-2025-21391 and CVE-2025-21418 are the only vulnerabilities this month which are known to be exploited in the wild. Both are privilege elevation vulnerabilities. An attacker can use CVE-2025-21391 to delete critical system files. CVE-2025-21418, nestled within the Ancillary Function Driver (AFD), exposes a pathway to local privilege escalation through the Winsock API. An attacker who successfully exploits this vulnerability could gain SYSTEM privileges.
Talos would also like to highlight the following vulnerabilities that Microsoft considers to be “important”:
- CVE-2025-21190 Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21198 Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
- CVE-2025-21200 Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21201 Windows Telephony Server Remote Code Execution Vulnerability
- CVE-2025-21208 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2025-21371 Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21406 Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21407 Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21410 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page.
In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.
The rules included in this release that protect against the exploitation of many of these vulnerabilities are 58316, 58317, 62022, 62023, 64529-64532, 64537, 64539-64542, 64545. There are also these Snort 3 rules: 300612, 301136, 301137, 301139, 301140.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/february-patch-tuesday-release/