Microsoft's February security update contains substantially fewer vulnerabilities for admins to address compared to a month ago, but there's still plenty in it that requires immediate attention. Topping the list are two zero-day vulnerabilities that attackers are actively exploiting in the wild, two more that are publicly known but not exploited yet, a patch for a zero-day that Microsoft disclosed in December 2024, and an assortment of other common vulnerabilities and exposures (CVEs) with potentially severe consequences for affected organizations. In total, Microsoft released patches for 63 unique CVEs, a far cry from the massive 159 CVEs — including a startling eight zero-days — that the company disclosed in January. Microsoft assessed four of the bugs it disclosed today as being of critical severity. It rated the vast majority of the remaining bugs as important to address but of lesser severity for a variety of factors, including attack complexity and privileges required to exploit the vulnerability. The two actively exploited zero-day bugs in this month's update are CVE-2025-21418 (CVSS score 7.8), an elevation of privilege vulnerability in Windows Ancillary Function Driver for WinSock, and CVE-2025-21391 (CVSS 7.1), another elevation of privilege issue, this time affecting Windows Storage. Per its usual practice, Microsoft's advisories for both bugs offered no details on the exploitation activity. But security researchers had their own take on why organizations need to a...
Microsoft's February Patch a Lighter Lift Than January's
Dark Reading
·Jai Vijayan
·Published Feb 11, 2025
·Updated
Affected Software
9 affected components
Microsoft Windows Ancillary Function Driver for WinSock
Microsoft Windows Storage
Microsoft Microsoft Surface
Microsoft DHCP Client service
Microsoft Microsoft Dynamics 365 Sales
Microsoft Microsoft Excel
Microsoft Windows LDAP
Microsoft Microsoft High Performance Compute (HPC) Pack
Microsoft Security Update
Frequently Asked Questions
1
What is the main focus of Microsoft's February security patch article?
The article discusses Microsoft's February security update, which addresses fewer vulnerabilities compared to January's update but includes critical security issues that need prompt attention.
2
What notable vulnerabilities are highlighted in the February patch?
The February patch features two zero-day vulnerabilities that require immediate action from administrators.
3
Which Microsoft products are impacted by the February security update?
Affected products include Microsoft Windows Ancillary Function Driver for WinSock, Microsoft Windows Storage, Microsoft Surface, and Microsoft Excel among others.
4
How does the number of vulnerabilities in February's patch compare to January's patch?
February's patch includes significantly fewer vulnerabilities than January's patch, making it a lighter lift for system administrators.
5
What is the recommended action for administrators regarding the February security updates?
Administrators are advised to prioritize the immediate addressing of the critical vulnerabilities included in the February security patch.