Microsoft January 2025 Patch Tuesday – 159 Vulnerabilities Fixed, Including 10 Critical RCE’s
Microsoft released a security as part of the Junuray Patch Tuesday that addressed 159 vulnerabilities, including 10 classified as critical Remote Code Execution (RCE) vulnerabilities. These fixes are crucial for securing Windows operating systems and related software against potential exploitation. Key Highlights of December 2024 Patch Tuesday Updates: Microsoft Patches 3 Zero-Day Vulnerabilities in January […] The post Microsoft January 2025 Patch Tuesday – 159 Vulnerabilities Fixed, Including 10 Critical RCE’s appeared first on Cyber Security News.
Microsoft released a security as part of the Junuray Patch Tuesday that addressed 159 vulnerabilities, including 10 classified as critical Remote Code Execution (RCE) vulnerabilities. These fixes are crucial for securing Windows operating systems and related software against potential exploitation.
Key Highlights of December 2024 Patch Tuesday Updates:
- CVE-2025-21362 & CVE-2025-21354: Both involve vulnerabilities in Microsoft Excel that allow remote code execution if a user opens a specially crafted file. These are critical as they could enable attackers to execute arbitrary code with user privileges.
- CVE-2025-21311: A critical vulnerability in Windows NTLM V1 that could allow privilege escalation, potentially giving attackers higher access levels on the system.
- CVE-2025-21309 & CVE-2025-21297: Both relate to vulnerabilities in Windows Remote Desktop Services, enabling remote code execution through maliciously crafted connections or files.
- CVE-2025-21307: Affects the Reliable Multicast Transport Driver (RMCAST), allowing remote attackers to execute arbitrary code.
- CVE-2025-21298 & CVE-2025-21296: These involve vulnerabilities in Windows OLE and BranchCache, respectively, which could permit remote code execution via crafted inputs.
- CVE-2025-21295 & CVE-2025-21294: Both are critical remote code execution vulnerabilities affecting authentication mechanisms (SPNEGO and Digest Authentication), which could compromise system integrity.
Microsoft Patches 3 Zero-Day Vulnerabilities in January 2025 Security Update
Microsoft has released its January 2025 Patch Tuesday updates, addressing numerous security vulnerabilities, including three critical zero-day flaws that were publicly disclosed and actively exploited.
The updates, aimed at improving the security of Windows and related software, fix issues ranging from privilege escalation to remote code execution and spoofing vulnerabilities. Below are the key details about the zero-day vulnerabilities that were patched:
CVE-2025-21275: Windows App Package Installer Elevation of Privilege Vulnerability
A critical elevation of privilege (EoP) vulnerability identified as CVE-2025-21275 has been fixed in the Windows App Package Installer. This flaw allows an attacker to gain SYSTEM-level privileges on a compromised device. Microsoft acknowledged that an attacker who successfully exploits this vulnerability could take complete control of the affected system.
This vulnerability was reported to Microsoft anonymously. While no specific details about ongoing exploitation have been disclosed, flaws like these are often sought after by attackers aiming to escalate access privileges.
CVE-2025-21308: Windows Themes Spoofing Vulnerability
Another concerning zero-day, tracked as CVE-2025-21308, was found in Windows Themes functionality. This spoofing vulnerability could be triggered merely by displaying a specially crafted Theme file in Windows Explorer.
Unlike many other attacks, users do not necessarily need to open or click on the malicious file—simply loading it in Windows Explorer could exploit the flaw.
The exploit works by leveraging the BrandImage and Wallpaper options in Theme files to specify a network file path.
When Windows Explorer processes these files, it automatically sends the logged-in user’s NTLM credentials to the remote host specified in the Theme file. Attackers can use these NTLM hashes to either crack the plain-text password or execute pass-the-hash attacks.
Steps to Mitigate CVE-2025-21308
Microsoft advises users to disable NTLM or enable the security policy “Restrict NTLM: Outgoing NTLM traffic to remote servers” to mitigate the risk of this vulnerability.
The flaw was discovered by Blaz Satler of 0patch at ACROS Security and is a bypass of a previous vulnerability (CVE-2024-38030). Notably, 0patch had already released micropatches for this flaw in October 2024 while awaiting Microsoft’s official fix.
Microsoft Access Vulnerabilities: CVE-2025-21186, CVE-2025-21366, CVE-2025-21395
Three remote code execution (RCE) vulnerabilities in Microsoft Access, tracked as CVE-2025-21186, CVE-2025-21366, and CVE-2025-21395, have been addressed. These flaws could be exploited by attackers to execute malicious code simply by tricking a victim into opening specially crafted Microsoft Access documents.
The vulnerabilities highlight the importance of avoiding untrusted files and having security solutions in place that can detect suspicious activity in office productivity tools.
Microsoft’s January 2025 Patch Tuesday emphasizes the ever-present risk of zero-day vulnerabilities in widely used software. Users are urged to apply updates immediately to protect their devices from potential exploitation.
Beyond installing updates, organizations should consider implementing additional mitigations, such as disabling NTLM for enterprise networks or using policies to restrict the use of vulnerable protocols.
Microsoft January 2025 Patch Tuesday
CVE Number | CVE Title | Impact | Max Severity |
CVE-2025-21417 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21413 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21411 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21409 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21405 | Visual Studio Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21403 | On-Premises Data Gateway Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21402 | Microsoft Office OneNote Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21395 | Microsoft Access Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21393 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | Important |
CVE-2025-21389 | Windows upnphost.dll Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21382 | Windows Graphics Component Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21378 | Windows CSC Service Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21374 | Windows CSC Service Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21372 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21370 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21366 | Microsoft Access Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21365 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21364 | Microsoft Excel Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21363 | Microsoft Word Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21362 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | Critical |
CVE-2025-21361 | Microsoft Outlook Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21360 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21357 | Microsoft Outlook Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21356 | Microsoft Office Visio Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21354 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | Critical |
CVE-2025-21348 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21346 | Microsoft Office Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21345 | Microsoft Office Visio Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21344 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21343 | Windows Web Threat Defense User Service Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21341 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21340 | Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21339 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21338 | GDI+ Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21336 | Windows Cryptographic Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21335 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21334 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21333 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21332 | MapUrlToZone Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21331 | Windows Installer Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21330 | Windows Remote Desktop Services Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21329 | MapUrlToZone Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21328 | MapUrlToZone Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21327 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21326 | Internet Explorer Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21324 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21323 | Windows Kernel Memory Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21321 | Windows Kernel Memory Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21320 | Windows Kernel Memory Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21319 | Windows Kernel Memory Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21318 | Windows Kernel Memory Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21317 | Windows Kernel Memory Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21316 | Windows Kernel Memory Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21315 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21314 | Windows SmartScreen Spoofing Vulnerability | Spoofing | Important |
CVE-2025-21313 | Windows Security Account Manager (SAM) Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21312 | Windows Smart Card Reader Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21311 | Windows NTLM V1 Elevation of Privilege Vulnerability | Elevation of Privilege | Critical |
CVE-2025-21310 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21309 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Remote Code Execution | Critical |
CVE-2025-21308 | Windows Themes Spoofing Vulnerability | Spoofing | Important |
CVE-2025-21307 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Remote Code Execution | Critical |
CVE-2025-21306 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21305 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21304 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21303 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21302 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21301 | Windows Geolocation Service Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21300 | Windows upnphost.dll Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21299 | Windows Kerberos Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21298 | Windows OLE Remote Code Execution Vulnerability | Remote Code Execution | Critical |
CVE-2025-21297 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Remote Code Execution | Critical |
CVE-2025-21296 | BranchCache Remote Code Execution Vulnerability | Remote Code Execution | Critical |
CVE-2025-21295 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | Remote Code Execution | Critical |
CVE-2025-21294 | Microsoft Digest Authentication Remote Code Execution Vulnerability | Remote Code Execution | Critical |
CVE-2025-21293 | Active Directory Domain Services Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21292 | Windows Search Service Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21291 | Windows Direct Show Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21290 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21289 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21288 | Windows COM Server Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21287 | Windows Installer Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21286 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21285 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21284 | Windows Virtual Trusted Platform Module Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21282 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21281 | Microsoft COM for Windows Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21280 | Windows Virtual Trusted Platform Module Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21278 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21277 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21276 | Windows MapUrlToZone Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21275 | Windows App Package Installer Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21274 | Windows Event Tracing Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21273 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21272 | Windows COM Server Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21271 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21270 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21269 | Windows HTML Platforms Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21268 | MapUrlToZone Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21266 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21265 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21263 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21261 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21260 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21258 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21257 | Windows WLAN AutoConfig Service Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21256 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21255 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21252 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21251 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21250 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21249 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21248 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21246 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21245 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21244 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21243 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21242 | Windows Kerberos Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21241 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21240 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21239 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21238 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21237 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21236 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21235 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21234 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21233 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21232 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21231 | IP Helper Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21230 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21229 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21228 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21227 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21226 | Windows Digital Media Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21225 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21224 | Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21223 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21220 | Microsoft Message Queuing Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21219 | MapUrlToZone Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21218 | Windows Kerberos Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21217 | Windows NTLM Spoofing Vulnerability | Spoofing | Important |
CVE-2025-21215 | Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21214 | Windows BitLocker Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21213 | Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21211 | Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21210 | Windows BitLocker Information Disclosure Vulnerability | Information Disclosure | Important |
CVE-2025-21207 | Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability | Denial of Service | Important |
CVE-2025-21202 | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21193 | Active Directory Federation Server Spoofing Vulnerability | Spoofing | Important |
CVE-2025-21189 | MapUrlToZone Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
CVE-2025-21187 | Microsoft Power Automate Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21186 | Microsoft Access Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21178 | Visual Studio Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21176 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21173 | .NET Elevation of Privilege Vulnerability | Elevation of Privilege | Important |
CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2025-21171 | .NET Remote Code Execution Vulnerability | Remote Code Execution | Important |
CVE-2024-7344 | Cert CC: CVE-2024-7344 Howyar Taiwan Secure Boot Bypass | ||
CVE-2024-50338 | GitHub: CVE-2024-50338 Malformed URL allows information disclosure through git-credential-manager | Information Disclosure | Important |
Microsoft has published a complete list of patched vulnerabilities, which provides detailed information about the exploitation methods, vulnerability descriptions, and other information.
All users should update their products to the latest version to prevent threat actors from exploiting these vulnerabilities.
The post Microsoft January 2025 Patch Tuesday – 159 Vulnerabilities Fixed, Including 10 Critical RCE’s appeared first on Cyber Security News.
What's Your Reaction?