• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

6 Zero-Days in March 2025 Patch Tuesday – Krebs on Safety

Admin by Admin
April 14, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Microsoft in the present day issued greater than 50 safety updates for its varied Home windows working methods, together with fixes for a whopping six zero-day vulnerabilities which are already seeing lively exploitation.

Two of the zero-day flaws embody CVE-2025-24991 and CVE-2025-24993, each vulnerabilities in NTFS, the default file system for Home windows and Home windows Server. Each require the attacker to trick a goal into mounting a malicious digital arduous disk. CVE-2025-24993 would result in the potential of native code execution, whereas CVE-2025-24991 might trigger NTFS to reveal parts of reminiscence.

Microsoft credit researchers at ESET with reporting the zero-day bug labeled CVE-2025-24983, an elevation of privilege vulnerability in older variations of Home windows. ESET mentioned the exploit was deployed by way of the PipeMagic backdoor, able to exfiltrating knowledge and enabling distant entry to the machine.

ESET’s Filip Jurčacko mentioned the exploit within the wild targets solely older variations of Home windows OS: Home windows 8.1 and Server 2012 R2. Though nonetheless utilized by hundreds of thousands, safety help for these merchandise ended greater than a 12 months in the past, and mainstream help ended years in the past. Nonetheless, ESET notes the vulnerability itself is also current in newer Home windows OS variations, together with Home windows 10 construct 1809 and the still-supported Home windows Server 2016.

Rapid7’s lead software program engineer Adam Barnett mentioned Home windows 11 and Server 2019 onwards will not be listed as receiving patches, so are presumably not weak.

“It’s not clear why newer Home windows merchandise dodged this explicit bullet,” Barnett wrote. “The Home windows 32 subsystem remains to be presumably alive and properly, since there isn’t any obvious point out of its demise on the Home windows shopper OS deprecated options checklist.”

The zero-day flaw CVE-2025-24984 is one other NTFS weak spot that may be exploited by inserting a malicious USB drive right into a Home windows laptop. Barnett mentioned Microsoft’s advisory for this bug doesn’t fairly be part of the dots, however profitable exploitation seems to imply that parts of heap reminiscence could possibly be improperly dumped right into a log file, which might then be combed by by an attacker hungry for privileged data.

“A comparatively low CVSSv3 base rating of 4.6 displays the sensible difficulties of real-world exploitation, however a motivated attacker can generally obtain extraordinary outcomes ranging from the smallest of toeholds, and Microsoft does fee this vulnerability as essential by itself proprietary severity rating scale,” Barnett mentioned.

One other zero-day mounted this month — CVE-2025-24985 — might enable attackers to put in malicious code. As with the NTFS bugs, this one requires that the consumer mount a malicious digital arduous drive.

The ultimate zero-day this month is CVE-2025-26633, a weak spot within the Microsoft Administration Console, a part of Home windows that offers system directors a approach to configure and monitor the system. Exploiting this flaw requires the goal to open a malicious file.

This month’s bundle of patch love from Redmond additionally addresses six different vulnerabilities Microsoft has rated “crucial,” which means that malware or malcontents might exploit them to grab management over weak PCs with no assist from customers.

Barnett noticed that that is now the sixth consecutive month the place Microsoft has printed zero-day vulnerabilities on Patch Tuesday with out evaluating any of them as crucial severity at time of publication.

The SANS Web Storm Heart has a helpful checklist of all of the Microsoft patches launched in the present day, listed by severity. Home windows enterprise directors would do properly to regulate askwoody.com, which frequently has the inside track on any patches inflicting issues. Please think about backing up your knowledge earlier than updating, and go away a remark under should you expertise any points making use of this month’s updates.

Tags: KrebsMarchPatchSecurityTuesdayZeroDays
Admin

Admin

Next Post
E mail Is Nonetheless the Weakest Hyperlink

E mail Is Nonetheless the Weakest Hyperlink

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

May 17, 2025
Reconeyez Launches New Web site | SDM Journal

Reconeyez Launches New Web site | SDM Journal

May 15, 2025
Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

May 18, 2025
Flip Your Toilet Right into a Good Oasis

Flip Your Toilet Right into a Good Oasis

May 15, 2025
Apollo joins the Works With House Assistant Program

Apollo joins the Works With House Assistant Program

May 17, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Awakening Followers Are Combating A Useful resource Warfare With Containers

Awakening Followers Are Combating A Useful resource Warfare With Containers

July 9, 2025
Securing BYOD With out Sacrificing Privateness

Securing BYOD With out Sacrificing Privateness

July 9, 2025
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved