logo

Microsoft's February Patch a Lighter Lift Than January's

ID: e09f66aa-8700-5e64-9a86-9f983dd2061b

STIX ID: report--e09f66aa-8700-5e64-9a86-9f983dd2061b

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-02-11

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Microsoft's February 2025 security update addresses 63 CVEs, including multiple critical remote code execution and privilege-escalation flaws and several zero-day vulnerabilities. The bulletin calls out two zero-days being actively exploited (CVE-2025-21418 and CVE-2025-21391), previously disclosed unpatched issues (e.g., CVE-2025-21377), and other high-severity bugs affecting Windows components, Microsoft Dynamics 365, Excel, LDAP, and HPC — urging administrators to prioritize immediate patching to prevent SYSTEM-level escalation, data deletion, and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.