Microsoft's January update contains patches for a record 159 vulnerabilities, including eight zero-day bugs, three of which attackers are already actively exploiting. The update is Microsoft's largest ever and is notable also for including three bugs that the company said were discovered by an artificial intelligence (AI) platform. Microsoft assessed 10 of the vulnerabilities disclosed this week as being of critical severity and the remaining ones as important bugs to fix. As always, the patches address vulnerabilities in a wide range of Microsoft technologies, including Windows OS, Microsoft Office, .NET, Azure, Kerberos, and Windows Hyper-V. They include more than 20 remote code execution (RCE) vulnerabilities, nearly the same number of elevation-of-privilege bugs, and an assortment of other denial-of-service flaws, security bypass issues, and spoofing and information disclosure vulnerabilities. Multiple security researchers pointed to the three actively exploited bugs in this month's update as the vulnerabilities that need immediate attention. The vulnerabilities, identified as CVE-2025-21335, CVE-2025-21333, and CVE-2025-21334, are all privilege escalation issues in a component of the Windows Hyper-V's NT Kernel. Attackers can exploit the bug relatively easily and with minimal permissions to gain system-level privileges on affected systems. Microsoft itself has assigned each of the three bugs a relatively moderate severity score of 7.8 out of 10 on the CVSS scale. But the...
Microsoft Rings in 2025 With Record Security Update
Dark Reading
·Jai Vijayan
·Published Jan 14, 2025
·Updated
Affected Software
18 affected components
Microsoft Windows
Microsoft Microsoft Office
Microsoft .NET
Microsoft Azure
Microsoft Kerberos
Microsoft Windows Hyper-V
Microsoft Windows App Package Installer
Microsoft Windows Themes
Microsoft Microsoft Access
Microsoft Windows NTLMv1
Microsoft Windows Reliable Multicast Transport Driver
Microsoft Windows OLE
Microsoft Windows OS
Microsoft Microsoft Office
Microsoft .NET
Microsoft Azure
Microsoft Kerberos
Microsoft Windows Hyper-V
Frequently Asked Questions
1
What is the significance of Microsoft's January 2025 security update?
The January 2025 security update is notable for containing a record 159 patches for vulnerabilities, including eight zero-day bugs that are actively being exploited.
2
Which major Microsoft products are impacted by the January 2025 update?
The update affects several Microsoft products, including Windows, Microsoft Office, .NET, Azure, and Windows Hyper-V.
3
How many vulnerabilities did Microsoft address in this update?
Microsoft addressed a total of 159 vulnerabilities in its January 2025 security update.
4
What types of vulnerabilities are included in this security update?
The update includes eight zero-day vulnerabilities, three of which are currently being exploited by attackers.
5
What is the potential impact of these vulnerabilities?
These vulnerabilities could potentially allow attackers to execute malicious code, leading to unauthorized access or system compromise.