Patch Tuesday Patch Tuesday has arrived, and Microsoft has revealed one flaw in its products under active exploitation and 11 critical issues in its code to fix. Redmond delivered fixes for more than 120 flaws this month; none are rated with a CVSS severity score of nine or higher. The one that deserves most attention is CVE-2025-29824, an elevation of privilege (EoP) hole in the Windows Common Log File System Driver, because it is already being exploited. In a separate note, Microsoft explained the vulnerability is being exploited by a crew it has designated as Storm-2460, which uses the bug to deliver ransomware it’s dubbed PipeMagic. Victims have been found in the US, Spain, Venezuela, and Saudi Arabia. The 7.8-rated flaw allows an attacker to elevate privileges up to system level thanks to a use-after-free() flaw in the aforementioned driver. The issue affects all versions of Windows Server up to 2025 and Windows 10 and 11. Windows Server and Windows 11 have been patched, but Windows 10 awaits a fix. "The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information," Redmond wrote, regarding patches for Windows 10. This appears to be a common problem this month, with many of the patches excluding Windows 10 for the moment. We've asked Microsoft for clarification on release dates and what the issue is. Windows 10 is approaching end of life but it's not there yet. All of the critical flaws all a...
Bad luck, Windows 10 users. No fix yet for ransomware-exploited bug
The Register
·Iain Thomson
·Published Apr 8, 2025
·Updated
Affected Software
28 affected components
Microsoft Windows Server=up to 2025
Microsoft Windows 10
Microsoft Windows 11
Microsoft Office
Microsoft Excel
Microsoft LDAP
Microsoft Remote Desktop
Adobe Cold Fusion
Adobe After Effects
Adobe Media Encoder
Adobe Bridge
Adobe Commerce
Adobe AEM Forms
Adobe Premiere Pro
Adobe Photoshop
Adobe Animate
Adobe AEM Screens
Adobe FrameMaker
Adobe Adobe XMP Toolkit SDK
AMD GPU
AMD SMM
AMD SEV confidential computing
AMD Cpu
AMD GPU memory
AMD Ryzen Ai Software
Microsoft Windows Server=2025
Microsoft Windows 10
Microsoft Windows 11
Frequently Asked Questions
1
What critical issues were reported in this article regarding Microsoft products?
The article mentions 11 critical issues in Microsoft products that require fixing, along with one flaw actively exploited by ransomware.
2
Which Microsoft operating systems are affected by these vulnerabilities?
The affected operating systems include Microsoft Windows 10, Windows 11, and Windows Server up to 2025.
3
What security implications does the article highlight for users?
The article highlights the imminent risk to users due to unresolved vulnerabilities, particularly one that is currently being exploited by ransomware.
4
What software applications face vulnerabilities according to the article?
Vulnerabilities are reported in Microsoft Office products, including Excel and Remote Desktop, as well as various Adobe products like Photoshop and After Effects.
5
What actions does Microsoft recommend for affected users?
Microsoft recommends that affected users apply the available patches promptly to mitigate the risks associated with the identified vulnerabilities.