Patch Tuesday Microsoft’s Patch Tuesday bundle has appeared, with a dirty dozen flaws competing for your urgent attention – six of them rated critical and another six already being exploited by criminals. Let’s start with the six already exploited vulnerabilities, three of which impact Windows NTFS. The first is CVE-2025-24993 - a heap-based buffer overflow in NTFS used by Windows Server 2008 and later systems, as well as Windows 10 and 11. The flaw makes remote code execution (RCE) a possibility and is fairly simple to exploit, Redmond warns. Though it's technically an RCE, it requires some local action, such as getting a user to mount a malicious virtual hard disk (VHD) image, as Redmond explains: "This type of exploit is sometimes referred to as arbitrary code execution. The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability. "An attacker can trick a local user on a vulnerable system into mounting a specially crafted VHD that would then trigger the vulnerability." That said, this 7.8-severity flaw is being exploited in the wild. The second zero-day vulnerability, CVE-2025-24991, is an information-disclosure flaw in NTFS rated 5.5 on the ten-point CVSS severity scale. The bug allows an attacker to perform an out-of-bounds read to access data on the target system, but again only if the victim, for instance, mounts a specially crafted VHD. The other exploited NTFS issue is the 4.6-ra...
Microsoft's Patch Tuesday reports 6 flaws already under fire
The Register
·Iain Thomson
·Published Mar 12, 2025
·Updated
Affected Software
26 affected components
Microsoft Windows Server=2008
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Fast FAT File System Driver
Microsoft Win32 Kernel Subsystem
Microsoft Microsoft Management Console (MMC)
Microsoft Windows Remote Desktop Services (RDS)
Microsoft Remote Desktop Client
Microsoft Office
Microsoft Windows DNS Server
Microsoft Windows Subsystem For Linux
Microsoft Microsoft Access
Apple Safari
Adobe Illustrator
Adobe InDesign
Adobe Substance 3D Sampler
Adobe 3D Designer
Adobe 3D Painter
Adobe 3D Modeler
Google Android Framework
Google Android
Linux Linux kernel
Microsoft Windows Server=2008
Microsoft Windows Server
Microsoft Windows 10
Microsoft Windows 11
Frequently Asked Questions
1
What is the main focus of the article?
The article discusses Microsoft’s Patch Tuesday release, which includes six critical flaws and another six already being exploited by attackers.
2
Which specific Microsoft products are affected by the reported vulnerabilities?
The affected products include Microsoft Windows Server 2008, Windows 10, Windows 11, and several Microsoft management tools.
3
What is the urgency level of the flaws reported in the article?
The article indicates that six of the vulnerabilities are rated critical and require urgent attention.
4
Are any of the flaws under active exploitation?
Yes, the article notes that six of the vulnerabilities are already being exploited by criminals.
5
How does this Patch Tuesday compare to previous updates?
This Patch Tuesday features a significant number of flaws, which highlights an ongoing concern for security in Microsoft products.