Patch Tuesday roundup for February 2025
ID: cb3511b0-0193-5d97-b733-c7c077965855
STIX ID: report--cb3511b0-0193-5d97-b733-c7c077965855
Feed Name: Expel Blog
Expel's February 2025 Patch Tuesday summary reviews 63 Microsoft CVEs and highlights three high-priority vulnerabilities—CVE-2025-21391 (Windows Storage elevation of privilege, actively exploited), CVE-2025-21418 (WinSock driver elevation of privilege, use-after-free to achieve SYSTEM, actively exploited), and CVE-2025-21377 (NTLM hash disclosure/spoofing requiring user interaction)—recommending prompt application of Microsoft updates across affected Windows Server and endpoint versions to mitigate active exploitation risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
