Microsoft released security updates addressing 126 vulnerabilities across its software, including one actively exploited in ransomware attacks. Eleven vulnerabilities are critical, impacting Windows CLFS Driver (CVE-2025-29824), allowing privilege escalation. This EoP flaw, the sixth in the same component since 2022, requires only local access for exploitation. Patches for some Windows 10 versions are pending. Other critical flaws affect Windows Kerberos, Remote Desktop Services, Lightweight Directory Access Protocol, Microsoft Office, and Excel, and Hyper-V. CISA added CVE-2025-29824 to its Known Exploited Vulnerabilities catalog, mandating federal agency patching by April 29, 2025.
Prepared by Jonathan Pierce and reviewed by editorial team.
Comments