Microsoft: 6 Zero-Days in March 2025 Patch Tuesday
ID: 061b3274-1325-53df-b49d-afaa8bb1f71d
STIX ID: report--061b3274-1325-53df-b49d-afaa8bb1f71d
Feed Name: Krebs on Security
Microsoft released more than 50 security updates addressing six zero-day vulnerabilities actively exploited in the wild, including multiple NTFS flaws (CVE-2025-24991, CVE-2025-24993, CVE-2025-24984, CVE-2025-24985), an MMC bug (CVE-2025-26633), and an ESET-reported elevation-of-privilege issue (CVE-2025-24983) observed delivered via the PipeMagic backdoor; attack vectors include mounting malicious virtual hard disks, inserting crafted USB drives, and opening malicious files, and administrators are urged to apply patches and back up data before updating.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
