logo

February 2025 Patch Tuesday: Four Zero-Days and Three Critical Vulnerabilities Among 67 CVEs

ID: c3e25f96-1507-5557-bd0c-aa992fbecd89

STIX ID: report--c3e25f96-1507-5557-bd0c-aa992fbecd89

Feed Name: Crowdstrike Blog

Threat Score
88/100

Date Published: 2025-02-11

Date Updated: 2026-04-27

Author: Falcon Exposure Management Team

...
...

This CrowdStrike advisory summarizes multiple Microsoft security fixes including actively exploited zero-days (e.g., CVE-2025-21418, CVE-2025-21391), several critical remote code execution vulnerabilities (notably an unauthenticated LDAP RCE CVE-2025-21376), and other high-impact issues such as NTLMv2 hash disclosure, Excel RCE, and DHCP client RCE; it provides CVSS scores, impact descriptions, urgent patching and mitigation guidance (for example restricting RPCs to Active Directory servers), and points to the Falcon platform dashboard for tracking affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.