Microsoft has uncovered loads of Windows 11 security threats – here’s what you need to do

Young woman sitting on the floor with a laptop biting nails, nervous and very anxious
(Image credit: Asier Romero / Shutterstock)

Microsoft has revealed that it has discovered several serious security vulnerabilities in Windows 11, as well as other versions including Windows 10.

The revelations came as part of January 2022’s ‘Patch Tuesday’ – the day of the month that Microsoft releases a swathe of patches to fix issues in its software.

While many of the vulnerabilities, which don’t just affect new versions of Windows, but also older versions such as Windows 8, Windows 7 and Windows Server 2019, were fixed with patches, six of the threats were highlighted as zero day threats.

While many security vulnerabilities are thankfully found and fixed before malicious users find and exploit them, zero day threats are vulnerabilities that are already out in the wild, which means they are particularly worrying.

In total, Microsoft announced the existence of 97 new exploits – which is certainly a troubling number. As a report in Forbes explains, Microsoft has limited the information about the zero day exploits to ensure it has time to address them before they are exploited. Microsoft believes that so far, there have not been any attacks using the vulnerabilities. Obviously, though, time is of the essence.

The zero day vulnerabilities are:

  • Critical - CVE-2021-22947 - Open Source Curl Remote Code Execution Vulnerability
  • Important - CVE-2021-36976 - Libarchive Remote Code Execution Vulnerability
  • Important - CVE-2022-21919 - Windows User Profile Service Elevation of Privilege Vulnerability
  • Important - CVE-2022-21836 - Windows Certificate Spoofing Vulnerability
  • Important - CVE-2022-21874 - Windows Security Center API Remote Code Execution Vulnerability
  • Important - CVE-2022-21839 - Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability (limited to Windows 10 and Windows Server 2019)

Of the 97 vulnerabilities, eight are labeled as ‘critical’, with 88 labeled as ‘important’. This means they are particularly dangerous, so users should make sure they are protected against them as soon as possible.

What should you do?

Microsoft’s warning is certainly troubling, but there’s no need to panic, as long as you take some precautionary steps. While the zero day threats are in the wild, they’ve not been used and Microsoft is actively working on fixes.

Meanwhile, it has also created patches for many of the other vulnerabilities. So, the best thing you can do right now is ensure that Windows 11 (or whichever version you have installed) is updated with the latest security patches.

They should download automatically, and If that’s the case you may see a prompt in the taskbar to restart your PC. You may also notice when you go to turn off your PC that there are options to ‘Update and restart’ and ‘Update and shut down’ – make sure you pick one of those.

You should also check to make sure there are no updates waiting for you. To do this, open up Settings and go to Windows Update > Check for Updates. If any are found, download and install them.

If you have any anti-virus or anti-malware software installed, make sure they are updated as well.

Hopefully Microsoft will continue to investigate and fix these vulnerabilities ASAP.

Matt Hanson
Managing Editor, Core Tech

Matt is TechRadar's Managing Editor for Core Tech, looking after computing and mobile technology. Having written for a number of publications such as PC Plus, PC Format, T3 and Linux Format, there's no aspect of technology that Matt isn't passionate about, especially computing and PC gaming. He’s personally reviewed and used most of the laptops in our best laptops guide - and since joining TechRadar in 2014, he's reviewed over 250 laptops and computing accessories personally.

Read more
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
A building at the Microsoft Headquarters campus in Redmond, Washington (2014).
Microsoft patches worrying zero-day along with 71 other flaws
A hacker wearing a hoodie sitting at a computer, his face hidden.
Microsoft patches three worrying security flaws in its latest critical update, so update now
A laptop with the Windows 11 desktop on screen, glowing, while on a work desk
Are you unable to get security updates for Windows 11 24H2? Here’s the likely reason why, and the fix to get your PC safe and secure again
Representational image of a cybercriminal
Microsoft discovers five potentially damaging attacks against its own software
Angry businessman destroying his desk and laptop with a baseball bat
New patch for Windows 11 24H2 reportedly plays havoc with File Explorer, and some folks are claiming it's broken their PC
Latest in Windows
Portrait of African-American teenage boy studying at home or in college dorm and using laptop, copy space
Windows 11’s Notepad gets AI-powered ‘Rewrite’ feature, but not everyone’s going to be happy about it
Copilot on a laptop
Microsoft quietly updates Copilot to cut down on unauthorized Windows activations
Windows fail
It looks like Microsoft might have broken Windows 11 24H2 again as performance plummets with Intel's latest CPUs
Windows 11 update with Task Manager menu
Microsoft is fixing Windows 11 Task Manager’s quirky reporting of CPU usage, and a much-wanted change for the lock screen is coming, too
Young woman using laptop, looking annoyed
Microsoft’s latest bit of nagging in Windows 11 might come from a good place, but it’s seriously annoying some people
A man at a desk using a laptop and holding his hands up, while having a confused look on his face
Windows 11 24H2 bug is confusing people by displaying half the interface in one language, and the remainder in another
Latest in News
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now