Patch Tuesday Microsoft’s February patch collection is mercifully smaller than January’s mega-dump. But don't get too relaxed – some deserve close attention, and other vendors have stepped in with plenty more fixes. Of the 63 patches (including six released earlier in the month) Microsoft announced, two are already being exploited. Both require attackers to be local and authenticated. One is CVE-2025-21418: A CVSS 7.8-scored elevation of privilege vulnerability in the Windows Ancillary Function Driver for Winsock that allows an attacker to execute a specially crafted program to gain SYSTEM-level privileges. The flaw affects machines running Windows 10, 11, and various versions of Windows Server. The other: CVE-2025-21391, a CVSS 7.1-rated elevation of privilege vulnerability in Windows Storage that means a local attacker can delete files under limited and vague conditions. As Windows Storage is present in Windows Server, that raises the possibility that data apps rely on could be deleted. Microsoft also detailed two issues that are publicly known, even if they haven't yet been exploited. Those of you with Surface kit - a laptop or tablet – may wish to consider fixing CVE-2025-21194, a 7.1-rated vulnerability that means some PCs are susceptible to compromise of the hypervisor and the secure kernel. Hypervisor compromises are very nasty, but Microsoft says exploiting this flaw “requires multiple conditions to be met, such as specific application behavior, user actions, manipula...
Microsoft takes it easy on February's Patch Tuesday
The Register
·Iain Thomson
·Published Feb 12, 2025
·Updated
Affected Software
44 affected components
Microsoft Windows Ancillary Function Driver for WinSock
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Server
Microsoft Windows Storage
Microsoft Surface
Microsoft Windows LDAP
Microsoft Excel
Microsoft DHCP Client service
Microsoft Dynamics 365
Microsoft Windows Telephony
Microsoft Office
Adobe Commerce
Adobe Magneto
Adobe InDesign
Adobe Illustrator
Adobe Substance 3D
Adobe InCopy
Adobe Photoshop Elements
SAP NetWeaver
SAP Enterprise Project Connection
Fortinet FortiOS
Fortinet FortiProxy
Microsoft Windows Ancillary Function Driver for WinSock =Windows 10, 11, and various versions of Windows Server
Microsoft Windows Storage=Windows Storage (Windows Server where present)
Microsoft Hypervisor and secure kernel (Surface kit PCs)=Some Surface laptop or tablet PCs
Microsoft Windows=Windows components affected by CVE-2025-21377 (as described: file selection/right-click/inspection/other action)
Microsoft Windows LDAP=Windows LDAP
Microsoft Windows (HPC head node / Linux compute node affected by CVE-2025-21198)=HPC cluster head node and Linux compute node
Microsoft Excel=Excel (five patches; CVE-2025-21381 prioritized)
Microsoft DHCP Client service=All builds of Windows
Microsoft Dynamics 365=Dynamics 365
Microsoft Windows Telephony=Windows Telephony (six patches)
Microsoft Office=Microsoft Office (multiple vulnerabilities; RCE and spoofing)
Adobe Adobe Commerce (Magneto)=Adobe Commerce/Magento
Adobe InDesign=InDesign
Adobe Illustrator=Illustrator (three critical-rated bugs)
Adobe Substance 3D=Substance 3D
Adobe InCopy=InCopy
Adobe Photoshop Elements=Photoshop Elements on macOS on Arm
SAP SAP NetWeaver=NetWeaver (bulk of 21 patches)
SAP Enterprise Project Connection=Enterprise Project Connection
Fortinet FortiOS=FortiOS
Fortinet FortiProxy=FortiProxy
Frequently Asked Questions
1
What is the main focus of the February 2025 Patch Tuesday report?
The article discusses the smaller size of Microsoft's February 2025 patch release compared to January's and highlights the importance of certain patches.
2
What is the total number of patches included in the February update?
There are a total of 63 patches included in the February 2025 update, with six being of particular concern.
3
Which Microsoft products are affected by the patches mentioned in the article?
Affected Microsoft products include Windows 10, Windows 11, Windows Server, and various components like the Windows DHCP Client Service and Office.
4
Are there any major security implications highlighted in the article?
Yes, the article emphasizes that some of the patches warrant close attention due to their potential security implications.
5
Which other vendors besides Microsoft are mentioned in relation to more fixes?
The article notes that other vendors have stepped in to provide additional fixes, though specific vendors are not detailed.