Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

Sitecore XP’s hardcoding “B” password poses major RCE risks in enterprise deployments

How to protect your backup

Over a third of UK companies are not dangerously prepared for AI risks

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Microsoft patch Tuesday fixes 63 defects.
Identity

Microsoft patch Tuesday fixes 63 defects.

userBy userFebruary 12, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

February 12, 2025Ravi LakshmananTuesday / Vulnerability Patch

On Tuesday, Microsoft released fixes for 63 security flaws affecting software products. This includes two vulnerabilities that he said were active in the wild.

Of the 63 vulnerabilities, three are rated as important, 57 are rated as important, one is medium and two are rated as low severity. This is apart from the 23 flaws handled in chrome-based Edge Browser since the release of the patch Tuesday update last month.

This update is well known for fixing two actively exploited flaws –

CVE-2025-21391 (CVSS score: 7.1) – Windows Storage Privilege Vulnerability Elevation CVE-2025-21418 (CVSS score: 7.8) – Windows Ancillary Function Driver for Winsock’s height in Winsock

Cybersecurity

“Attackers will be able to delete only the target files on the system,” Microsoft said in an alert on CVE-2025-21391. “This vulnerability does not allow confidential disclosure, but it would prevent an attacker from deleting data that could contain data that would result from the service.”

Mike Walters, president and co-founder of Action1, chains vulnerabilities with other flaws, escalates privileges, complicates recovery efforts, and covers tracks by threat actors removing important forensic artifacts. He pointed out that subsequent actions can be taken to make it possible.

Meanwhile, CVE-2025-21418 concerns a case of privilege escalation in Afd.sys that can be exploited to achieve system privileges.

It is worth noting that similar defects in the same component (CVE-2024-38193) were revealed to have been weaponized last August by the Lazarus group associated with North Korea. In February 2024, the tech giant also offered out a Windows Kernel Privilege Escalation Fault (CVE-2024-21338) that affects Applocker drivers (AppID.SYS) that were also exploited by hacking crews.

These attack chains take advantage of the security flaws of native Windows drivers, resulting in traditional vulnerable drivers (BYOVD) attacks, thereby revealing the need to deploy other drivers into the target environment. That’s why it stands out.

Currently, it is unknown whether CVE-2025-21418 abuse also links to the Lazarus group. The US Cybersecurity and Infrastructure Security Agency (CISA) has announced that it has announced that it has both been approved in the Known Exploited Vulnerabilities (KEV) catalog, which requires federal agencies to be patched by March 4, 2025. Added a defect.

The most serious flaw Microsoft deals with in this month’s update is CVE-2025-21198 (CVSS score: 9.0), a remote code execution (RCE) vulnerability in the High Performance Calculation (HPC) Pack.

“Attackators send a specially created HTTPS request to the target head node and send it to a Linux computer node that grants the ability to perform RCE on other clusters or nodes connected to the target head node. , we can take advantage of this vulnerability,” Microsoft said.

Also, another RCE vulnerability affecting Windows Lightweight Directory Access Protocol (LDAP) that allows attackers to send specially written requests to execute arbitrary code (CVE-2025-21376, CVSS score: 8.1) It is also worth mentioning. However, successful exploitation of flaws requires threat actors to win over their racial state.

“Given the integrity of LDAP for Active Directory, which supports authentication and access control in an enterprise environment, compromise can lead to lateral movements, privilege escalations, and widespread network violations.”

Cybersecurity

Elsewhere, this update also resolves the NTLMV2 hash disclosure vulnerability (CVE-2025-21377, CVSS score: 6.5).

Software patches from other vendors

In addition to Microsoft, security updates have also been released by other vendors over the past few weeks, rectifying several vulnerabilities, including -.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHaitian children fall prey to horrifying gang violence, Amnesty warns | Crime News
Next Article High sonarization key for the success of the travel industry in 2025 report
user
  • Website

Related Posts

Sitecore XP’s hardcoding “B” password poses major RCE risks in enterprise deployments

June 17, 2025

How to protect your backup

June 17, 2025

New flodrix botnet variant exploits langflow ai server rce bug to launch DDOS attacks

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Sitecore XP’s hardcoding “B” password poses major RCE risks in enterprise deployments

How to protect your backup

Over a third of UK companies are not dangerously prepared for AI risks

New flodrix botnet variant exploits langflow ai server rce bug to launch DDOS attacks

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

There is a full stack to capture the $300 million global blockchain infrastructure market

Top Startup and Tech Funding News – June 16, 2025

Tron to be released by reverse merger after we paused the probe to founder Justinsan

Meet TwinH & Avatars: The Future of Digital Identity is Here

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.