Microsoft Releases February 2025 Patches

Microsoft has released software updates as part of its February 2025 Patch Tuesday. The updates fix 55 security vulnerabilities in total, including 4 zero-day vulnerabilities, 2 of which is being actively exploited.

The breakdown of the vulnerabilities are as follows:

  • 19 privilege escalation

  • 2 security feature bypass

  • 22 remote code execution

  • 1 information disclosure

  • 9 denial of service

  • 3 spoofing

The actively exploited vulnerabilities are as follows:

  • CVE-2025-21391 - vulnerability in Windows Storage that can lead to escalation of privilege

  • CVE-2025-21418 - vulnerability in Windows Ancillary Function Driver for WinSock that can lead to escalation of privilege

Why You Should Care?

Zero-day vulnerabilities are vulnerabilities where a flaw has been identified but there was no fix for the flaw, which means attackers will try to exploit as many targets as possible before users fix the vulnerability. This makes it extra dangerous, and needs to be addressed as soon as possible.

In this case, two zero-day vulnerabilities are already being exploited, which means it is only a matter of time before the attackers compromise your business. Now that patches are available, it is critical to apply the patches as soon as possible to avoid getting compromised.

What Should You Do?

  • Test the patches ASAP at your organization, and make sure it does not break any business applications

  • Prioritize patching the 2 actively exploited zero-days

  • Roll out the rest of the Patch Tuesday updates

References

  • https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2025-patch-tuesday-fixes-4-zero-days-55-flaws/

Previous
Previous

Microsoft released February 2025 software updates and more - February 16, 2025

Next
Next

Personal and health info of over 882 thousand people stolen and more - February 9, 2025