logo

January 2025 Patch Tuesday: 10 Critical Vulnerabilities and Eight Zero-Days Among 159 CVEs

ID: 5fc934fd-e06e-5d8b-aaf1-7b0cf568ffbd

STIX ID: report--5fc934fd-e06e-5d8b-aaf1-7b0cf568ffbd

Feed Name: Crowdstrike Blog

Threat Score
90/100

Date Published: 2025-01-14

Date Updated: 2026-04-27

Author: Falcon Exposure Management Team

...
...

This bulletin summarizes numerous Microsoft vulnerabilities—several critical RCEs and EoP flaws (multiple CVEs) affecting Hyper-V, Office Access, Remote Desktop Services, OLE, NTLMv1, BranchCache, and other components—notes active exploitation of Hyper-V zero-days and public disclosure of some Office access flaws, provides CVSS ratings (up to 9.8), attack vectors, and mitigation recommendations (patching, network-level controls, NTLM restrictions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.