Microsoft patches three worrying security flaws in its latest critical update, so update now

A hacker wearing a hoodie sitting at a computer, his face hidden.
(Image credit: Shutterstock / Who is Danny)

  • Microsoft released January 2025 Patch Tuesday cumulative update
  • It fixes more than 150 vulnerabilities, including three being actively abused in the wild
  • Other details about the flaws are not being disclosed at this time

The first Microsoft Patch Tuesday of 2025 is upon us, and it’s a big one, as the update patches 161 vulnerabilities found in various products, including three zero-day bugs that have been actively abused in the wild.

The three vulnerabilities are tracked as CVE-2025-21333, CVE-2025-21334, and CVE-2025-21335. All three have a severity score of 7.8 (high), and all are found in Windows Hyper-V NT Kernel Integration VSP.

"An attacker who successfully exploited this vulnerability could gain SYSTEM privileges," Microsoft said in the advisory for the flaws.

Added to CISA's KEV

Other details are not known right now, as Microsoft gives users enough time to apply the patch without a swarm of hackers going after them. Therefore, we don’t know who the threat actors are, who the victims were, or how the attackers managed to compromise their targets’ IT infrastructure.

However, in its write-up, The Hacker News says the trio are privilege escalation bugs, and, citing Satnam Narang, senior staff research engineer at Tenable, are thus “very likely used as part of post-compromise activity, where an attacker has already gained access to a target system by some other means."

Since the vulnerabilities are being actively exploited in the wild, users are advised to apply the patch immediately. CISA has already added all three to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies a deadline of February 4, to apply the patch.

While these three flaws are arguably the most dangerous ones (since they’re being actively used), Microsoft also addressed 11 critical-severity bugs, as well. The remaining 149 are rated as important. Zero Day Initiative says this is the largest Patch Tuesday since 2017. Aside from Patch Tuesday, Microsoft also addressed Edge browser flaws in a separate patch, fixing seven vulnerabilities in the process.

Via The Hacker News

You might also like

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
US government warns users to patch this critical Microsoft Outlook bug
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Representational image depecting cybersecurity protection
CISA says Oracle and Mitel have critical security flaws being exploited
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
CISA tells agencies to patch BeyondTrust bug now
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras