{"id":2589,"date":"2025-05-18T16:08:38","date_gmt":"2025-05-18T16:08:38","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=2589"},"modified":"2025-05-18T16:08:38","modified_gmt":"2025-05-18T16:08:38","slug":"patch-tuesday-could-2025-version-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=2589","title":{"rendered":"Patch Tuesday, Could 2025 Version \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><strong>Microsoft<\/strong> on Tuesday launched software program updates to repair a minimum of 70 vulnerabilities in <strong>Home windows<\/strong> and associated merchandise, together with <em>5 zero-day flaws which might be already seeing energetic exploitation<\/em>. Including to the sense of urgency with this month\u2019s patch batch from Redmond are fixes for 2 different weaknesses that now have public proof-of-concept exploits obtainable.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter  wp-image-60331\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/07\/winupdatedate.png\" alt=\"\" width=\"749\" height=\"496\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/07\/winupdatedate.png 923w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/07\/winupdatedate-768x508.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/07\/winupdatedate-782x518.png 782w\" sizes=\"auto, (max-width: 749px) 100vw, 749px\"\/><\/p>\n<p>Microsoft and a number of other safety companies have\u00a0disclosed that attackers are exploiting a pair of bugs within the <strong>Home windows Widespread Log File System<\/strong> (CLFS) driver that enable attackers to raise their privileges on a weak machine. The Home windows CLFS is a important Home windows part liable for logging providers, and is broadly utilized by Home windows system providers and third-party functions for logging. Tracked as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2025-32701\" target=\"_blank\" rel=\"noopener\">CVE-2025-32701<\/a> &amp; <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2025-32706\" target=\"_blank\" rel=\"noopener\">CVE-2025-32706<\/a>, these flaws are current in all supported variations of Home windows 10 and 11, in addition to their server variations.<\/p>\n<p><strong>Kev Breen<\/strong>, senior director of risk analysis at <strong>Immersive Labs<\/strong>, mentioned privilege escalation bugs assume an attacker already has preliminary entry to a compromised host, usually by a phishing assault or through the use of stolen credentials. But when that entry already exists, Breen mentioned, attackers can achieve entry to the rather more highly effective Home windows SYSTEM account, which may disable safety tooling and even achieve area administration stage permissions utilizing credential harvesting instruments.<\/p>\n<p>\u201cThe patch notes don\u2019t present technical particulars on how that is being exploited, and no Indicators of Compromise (IOCs) are shared, which means the one mitigation safety groups have is to use these patches instantly,\u201d he mentioned. \u201cThe common time from public disclosure to exploitation at scale is lower than 5 days, with risk actors, ransomware teams, and associates fast to leverage these vulnerabilities.\u201d<\/p>\n<p>Two different zero-days patched by Microsoft right this moment additionally have been elevation of privilege flaws:\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2025-32709\" target=\"_blank\" rel=\"noopener\">CVE-2025-32709<\/a>, which issues afd.sys, the <strong>Home windows Ancillary Operate Driver<\/strong> that allows Home windows functions to connect with the Web; and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2025-30400\" target=\"_blank\" rel=\"noopener\">CVE-2025-30400<\/a>, a weak spot within the <strong>Desktop Window Supervisor<\/strong> (DWM) library for Home windows. As <strong>Adam Barnett<\/strong> at <strong>Rapid7<\/strong> notes, tomorrow marks the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.rapid7.com\/blog\/post\/2024\/05\/14\/patch-tuesday-may-2024\/\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/www.rapid7.com\/blog\/post\/2024\/05\/14\/patch-tuesday-may-2024\/&amp;source=gmail&amp;ust=1747257386891000&amp;usg=AOvVaw3VPzmtS8Na55bRRDOUkbDw\">one-year anniversary<\/a>\u00a0of\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2024-30051\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2024-30051&amp;source=gmail&amp;ust=1747257386891000&amp;usg=AOvVaw2HzZh4Tm-0eKXolluDR0FX\">CVE-2024-30051<\/a>, a earlier zero-day elevation of privilege vulnerability on this similar DWM part.<\/p>\n<p>The fifth zero-day patched right this moment is <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2025-30397\" target=\"_blank\" rel=\"noopener\">CVE-2025-30397<\/a>, a flaw within the <strong>Microsoft Scripting Engine<\/strong>, a key part utilized by <strong>Web Explorer<\/strong> and <strong>Web Explorer mode<\/strong> in <strong>Microsoft Edge<\/strong>.<span id=\"more-71250\"\/><\/p>\n<p><strong>Chris Goettl<\/strong> at <strong>Ivanti<\/strong> factors out that the Home windows 11 and Server 2025 updates embrace some new AI options that carry quite a lot of baggage and weigh in at round 4 gigabytes. Mentioned baggage consists of new synthetic intelligence (AI) capabilities, together with the controversial <strong>Recall<\/strong> function, which continuously takes screenshots of what customers are doing on Home windows CoPilot-enabled computer systems.<\/p>\n<p>Microsoft went again to the drafting board on Recall after a fountain of detrimental suggestions from safety consultants, who warned it might current a pretty goal and a possible gold mine for attackers. Microsoft seems to have made some efforts to stop Recall from scooping up delicate monetary info, however privateness and safety issues nonetheless linger. Former Microsoftie <strong>Kevin Beaumont<\/strong> has <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/cyberplace.social\/@GossiTheDog\/114360483150635243\" target=\"_blank\" rel=\"noopener\">a great teardown<\/a> on Microsoft\u2019s updates to Recall.<\/p>\n<p>In any case, <strong>windowslatest.com<\/strong> studies that <strong>Home windows 11 model 24H2<\/strong> reveals up prepared for downloads, even for those who don\u2019t need it.<\/p>\n<p>\u201cIt can now present up for \u2018obtain and set up\u2019 robotically for those who go to Settings &gt; Home windows Replace and click on Examine for updates, however solely when your machine doesn&#8217;t have a compatibility maintain,\u201d the publication <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.windowslatest.com\/2025\/05\/05\/windows-11-24h2-now-fully-ready-downloads-even-if-you-dont-want-it\/\" target=\"_blank\" rel=\"noopener\">reported<\/a>. \u201cEven for those who don\u2019t verify for updates, Home windows 11 24H2 will robotically obtain sooner or later.\u201d<\/p>\n<p>Apple customers seemingly have their very own patching to do. On Could 12 Apple launched safety updates to repair a minimum of 30 vulnerabilities in <strong>iOS<\/strong> and <strong>iPadOS<\/strong> (the up to date model <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/support.apple.com\/en-us\/122404\" target=\"_blank\" rel=\"noopener\">is eighteen.5<\/a>). <strong>TechCrunch<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/techcrunch.com\/2025\/05\/12\/apple-brings-emergency-satellite-features-to-iphone-13-with-ios-18-5\/\" target=\"_blank\" rel=\"noopener\">writes<\/a> that iOS 18.5 additionally expands emergency satellite tv for pc capabilities to iPhone 13 homeowners for the primary time (beforehand it was solely obtainable on iPhone 14 or later).<\/p>\n<p>Apple additionally <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/support.apple.com\/en-us\/100100\" target=\"_blank\" rel=\"noopener\">launched updates<\/a> for <strong>macOS Sequoia<\/strong>, <strong>macOS Sonoma<\/strong>, <strong>macOS Ventura<\/strong>, <strong>WatchOS<\/strong>, <strong>tvOS<\/strong> and <strong>visionOS<\/strong>. Apple mentioned there is no such thing as a indication of energetic exploitation for any of the vulnerabilities fastened this month.<\/p>\n<p>As all the time, please again up your machine and\/or essential knowledge earlier than trying any updates. And please be happy to hold forth within the feedback for those who run into any issues making use of any of those fixes.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Microsoft on Tuesday launched software program updates to repair a minimum of 70 vulnerabilities in Home windows and associated merchandise, together with 5 zero-day flaws which might be already seeing energetic exploitation. Including to the sense of urgency with this month\u2019s patch batch from Redmond are fixes for 2 different weaknesses that now have public [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":2591,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[406,262,1077,211,1078],"class_list":["post-2589","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-edition","tag-krebs","tag-patch","tag-security","tag-tuesday"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/2589","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2589"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/2589\/revisions"}],"predecessor-version":[{"id":2590,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/2589\/revisions\/2590"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/2591"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2589"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2589"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2589"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-05-06 16:52:01 UTC -->