Patch Tuesday roundup for January 2025
ID: 66045b1a-cfc5-5161-b8a5-d533fe71952c
STIX ID: report--66045b1a-cfc5-5161-b8a5-d533fe71952c
Feed Name: Expel Blog
Threat Score
Expel's January Patch Tuesday review covers 159 Microsoft CVEs and calls out three priority vulnerabilities—CVE-2025-21309 (Windows RDS remote code execution), CVE-2025-21314 (Windows SmartScreen spoofing), and CVE-2025-21311 (NTLM elevation, CVSS 9.8)—recommending prompt remediation; the report notes little evidence of active exploitation but warns these issues pose substantial risk due to wide platform impact and realistic exploitation paths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
