Microsoft Patch Tuesday February 2025 – 61 Vulnerabilities Fixed, 3 Zero-Day’s Actively Exploited

Microsoft released a security update as part of the February Patch Tuesday that addressed 61 vulnerabilities, including 25 classified as critical Remote Code Execution (RCE) vulnerabilities, including 3 zero-day vulnerabilities that were actively exploited in the wild. The update covers a wide range of Microsoft products, including Windows, Office, Visual Studio, Azure, and .NET Framework. […] The post Microsoft Patch Tuesday February 2025 – 61 Vulnerabilities Fixed, 3 Zero-Day’s Actively Exploited appeared first on Cyber Security News.

Feb 12, 2025 - 09:25
 0
Microsoft Patch Tuesday February 2025 – 61 Vulnerabilities Fixed, 3 Zero-Day’s Actively Exploited

Microsoft released a security update as part of the February Patch Tuesday that addressed 61 vulnerabilities, including 25 classified as critical Remote Code Execution (RCE) vulnerabilities, including 3 zero-day vulnerabilities that were actively exploited in the wild.

The update covers a wide range of Microsoft products, including Windows, Office, Visual Studio, Azure, and .NET Framework.

The February update included fixes for:

  • 25 Remote Code Execution vulnerabilities
  • 19 Elevation of Privilege vulnerabilities
  • 9 Denial of Service vulnerabilities
  • 4 Security Feature Bypass vulnerabilities
  • 2 Spoofing vulnerabilities
  • 1 Information Disclosure vulnerability

Zero-Day Vulnerabilities

Among the vulnerabilities patched, three were actively exploited in the wild:

CVE-2023-24932: A Secure Boot security feature bypass vulnerability that could allow an attacker to evade security restrictions and execute unauthorized code.

“To exploit the vulnerability, an attacker who has physical access or Administrative rights to a target device could install an affected boot policy. Successful exploitation of this vulnerability requires an attacker to compromise admin credentials on the device.”

CVE-2025-21391: A Windows Storage elevation of privilege vulnerability that could enable an attacker to gain higher-level access to the system.

“This vulnerability does not allow disclosure of any confidential information, but could allow an attacker to delete data that could include data that results in the service being unavailable.”

CVE-2025-21418: An elevation of privilege vulnerability affecting the Windows Ancillary Function Driver for WinSock, potentially allowing attackers to escalate privileges on targeted systems.

“An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.”

Critical Vulnerabilities

Microsoft classified the following vulnerabilities as “Critical” due to their potential to allow remote code execution (RCE):

  • CVE-2025-21376: A Windows Lightweight Directory Access Protocol (LDAP) RCE vulnerability that could allow attackers to execute arbitrary code remotely.
  • CVE-2025-21379: A DHCP Client Service RCE vulnerability that may enable remote attackers to execute code with elevated privileges.
  • CVE-2025-21381: An RCE vulnerability in Microsoft Excel that could be triggered through malicious spreadsheet files.

Other Notable Vulnerabilities

In addition to the critical flaws, Microsoft addressed several “Important” vulnerabilities, including:

  • Remote Code Execution Vulnerabilities: Affecting .NET, Visual Studio, Microsoft Office, and Windows Telephony Service.
  • Elevation of Privilege Vulnerabilities: Impacting Azure Network Watcher VM Extension, Kernel Streaming WOW Thunk Service Driver, Microsoft AutoUpdate (MAU), and Windows Storage.
  • Denial of Service Vulnerabilities: Found in Windows Active Directory Domain Services API, Internet Connection Sharing (ICS), and Windows Kerberos.
  • Security Feature Bypass Vulnerabilities: Affecting Microsoft Surface and Windows Kernel security features.
  • Spoofing Vulnerabilities: Found in Microsoft Outlook and NTLM Hash Disclosure mechanisms.
  • Information Disclosure Vulnerabilities: Affecting Microsoft Excel.

Microsoft Patch Tuesday February 2025 – 61 Vulnerabilities list

CVE NumberCVE TitleExploitedcMax Severity
CVE-2025-21376Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityNoRemote Code ExecutionCritical
CVE-2025-21379DHCP Client Service Remote Code Execution VulnerabilityNoRemote Code ExecutionCritical
CVE-2025-21381Microsoft Excel Remote Code Execution VulnerabilityNoRemote Code ExecutionCritical
CVE-2023-24932Secure Boot Security Feature Bypass VulnerabilityYesSecurity Feature BypassImportant
CVE-2025-21176.NET, .NET Framework, and Visual Studio Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21178Visual Studio Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21172.NET and Visual Studio Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21188Azure Network Watcher VM Extension Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21206Visual Studio Installer Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21351Windows Active Directory Domain Services API Denial of Service VulnerabilityNoDenial of ServiceImportant
CVE-2025-21352Internet Connection Sharing (ICS) Denial of Service VulnerabilityNoDenial of ServiceImportant
CVE-2025-21368Microsoft Digest Authentication Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21369Microsoft Digest Authentication Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21375Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21383Microsoft Excel Information Disclosure VulnerabilityNoInformation DisclosureImportant
CVE-2025-21182Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21183Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21391Windows Storage Elevation of Privilege VulnerabilityYesElevation of PrivilegeImportant
CVE-2025-21418Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityYesElevation of PrivilegeImportant
CVE-2025-21419Windows Setup Files Cleanup Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21420Windows Disk Cleanup Tool Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2023-32002HackerOne: CVE-2023-32002 Node.js `Module._load()` policy Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-24036Microsoft AutoUpdate (MAU) Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-24039Visual Studio Code Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21259Microsoft Outlook Spoofing VulnerabilityNoSpoofingImportant
CVE-2025-21194Microsoft Surface Security Feature Bypass VulnerabilityNoSecurity Feature BypassImportant
CVE-2025-21208Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21406Windows Telephony Service Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21407Windows Telephony Service Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21410Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21190Windows Telephony Service Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21200Windows Telephony Service Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21201Windows Telephony Server Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21198Microsoft High Performance Compute (HPC) Pack Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21337Windows NTFS Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21347Windows Deployment Services Denial of Service VulnerabilityNoDenial of ServiceImportant
CVE-2025-21349Windows Remote Desktop Configuration Service Tampering VulnerabilityNoTamperingImportant
CVE-2025-21350Windows Kerberos Denial of Service VulnerabilityNoDenial of ServiceImportant
CVE-2025-21358Windows Core Messaging Elevation of Privileges VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21359Windows Kernel Security Feature Bypass VulnerabilityNoSecurity Feature BypassImportant
CVE-2025-21367Windows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21371Windows Telephony Service Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21377NTLM Hash Disclosure Spoofing VulnerabilityNoSpoofingImportant
CVE-2025-21386Microsoft Excel Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21387Microsoft Excel Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21390Microsoft Excel Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21392Microsoft Office Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21394Microsoft Excel Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21397Microsoft Office Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21400Microsoft SharePoint Server Remote Code Execution VulnerabilityNoRemote Code ExecutionImportant
CVE-2025-21179DHCP Client Service Denial of Service VulnerabilityNoDenial of ServiceImportant
CVE-2025-21181Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityNoDenial of ServiceImportant
CVE-2025-21184Windows Core Messaging Elevation of Privileges VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21212Internet Connection Sharing (ICS) Denial of Service VulnerabilityNoDenial of ServiceImportant
CVE-2025-21216Internet Connection Sharing (ICS) Denial of Service VulnerabilityNoDenial of ServiceImportant
CVE-2025-21254Internet Connection Sharing (ICS) Denial of Service VulnerabilityNoDenial of ServiceImportant
CVE-2025-21322Microsoft PC Manager Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21414Windows Core Messaging Elevation of Privileges VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-21373Windows Installer Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant
CVE-2025-24042Visual Studio Code JS Debug Extension Elevation of Privilege VulnerabilityNoElevation of PrivilegeImportant

With multiple critical vulnerabilities and three actively exploited zero-days, Microsoft urges users and organizations to apply the latest updates immediately. Cybersecurity professionals should prioritize patching affected systems to mitigate potential threats. Regular system updates and best security practices remain essential for reducing the risk of exploitation.

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates

The post Microsoft Patch Tuesday February 2025 – 61 Vulnerabilities Fixed, 3 Zero-Day’s Actively Exploited appeared first on Cyber Security News.