6 Zero-Day Vulnerabilities and 10 High-Risk Security Flaws

Published:

spot_img

Microsoft Patch Tuesday Update – March 2025: Critical Vulnerabilities and Fixes

Microsoft’s March 2025 Patch Tuesday: Urgent Fixes for Zero-Day Vulnerabilities

In a critical update released on March 2025, Microsoft has addressed six actively exploited zero-day vulnerabilities, alongside an additional ten high-risk flaws, as part of its monthly Patch Tuesday initiative. This comprehensive update resolves a total of 57 Microsoft Common Vulnerabilities and Exposures (CVEs) and republishes ten non-Microsoft CVEs, including nine related to Google Chrome and one from Synaptics.

Among the six zero-days, vulnerabilities vary in severity from 4.6 to a staggering 7.8 on the Common Vulnerability Scoring System (CVSS:3.1). Notably, CVE-2025-24985, a 7.8-rated Remote Code Execution (RCE) vulnerability in the Windows Fast FAT File System Driver, poses a significant risk, requiring an attacker to deceive a local user into mounting a malicious virtual hard disk (VHD). Another critical flaw, CVE-2025-24983, allows elevation of privilege within the Windows Win32 Kernel Subsystem, potentially granting attackers SYSTEM-level access.

The Cybersecurity and Infrastructure Security Agency (CISA) has promptly added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, underscoring the urgency for users to apply these patches immediately.

In addition to the zero-days, Microsoft has flagged ten other vulnerabilities as "more likely" to be exploited, with severity ratings ranging from 4.3 to 8.1. These include critical flaws in Windows Remote Desktop Services and various security feature bypass vulnerabilities.

As organizations and individuals rush to secure their systems, other vendors have also joined the Patch Tuesday fray, releasing their own updates to address vulnerabilities. Cybersecurity experts urge all users to prioritize these updates to safeguard against potential attacks in an increasingly perilous digital landscape.

spot_img

Related articles

Recent articles

84 Hours of Internet Blackout in Iran Amid Growing Unrest

Iran's Internet Blackout: A Deepening Crisis Amid Unrest Four Days Without Connectivity Iran has plunged into a state of digital isolation as an internet blackout enters...

NSA Appoints Timothy Kosiba to Lead Cybersecurity Strategy

Appointment of Timothy Kosiba as NSA Deputy Director: A Leadership Milestone The National Security Agency (NSA) has recently announced a pivotal leadership change with the...

Comprehensive Threat Analysis of Cyber Campaigns in the UAE for H1 2025

Understanding the Cybersecurity Threat Landscape in the UAE: Insights from 2025 An analysis by Alain Penel, Vice President for the Middle East, Turkey, and CIS...

2026 Business Blast Radius: Dr. Amit Chaubey on Cyber Disruption as a Sovereign Risk

The 2026 Business Blast Radius: Insights from Dr. Amit Chaubey In a recent conversation with The Cyber Express, Dr. Amit Chaubey, the Managing Director and...