Close Menu
NoMusica.com
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    NoMusica.comNoMusica.com
    • Entertainment
    • Music
      • Music Production
    • Tech
      • AI
      • Electronics & Gadgets
      • Apps & Updates
      • Smartphones
    • Films & Shows
    • Gaming
    • Streaming
    NoMusica.com
    Home»Apps & Updates

    Windows Users Alert: Microsoft Fixes 63 Security Bugs, Including Active Threats

    February 12, 2025
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft has rolled out its latest Patch Tuesday update, addressing 63 security vulnerabilities across its software ecosystem.

    This includes three critical flaws, 57 important ones, and two actively exploited vulnerabilities that have already been used in cyberattacks.

    Two Actively Exploited Vulnerabilities

    The most concerning flaws in this update are:

    • CVE-2025-21391 (CVSS 7.1) – Windows Storage Elevation of Privilege Vulnerability
      • Allows attackers to delete targeted files, which could disrupt system services.
      • Could be combined with other exploits to escalate privileges and cover up attacks.
    • CVE-2025-21418 (CVSS 7.8) – Windows Ancillary Function Driver (AFD.sys) Privilege Escalation
      • Exploited to gain SYSTEM privileges, giving attackers complete control over affected machines.
      • Similar to a previous Lazarus Group attack using a vulnerability in the same Windows component.

    These flaws are severe enough that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added them to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply patches by March 4, 2025.

    Most Severe Vulnerability – CVE-2025-21198 (CVSS 9.0)

    This remote code execution (RCE) vulnerability affects Microsoft’s High Performance Compute (HPC) Pack.

    Attackers can exploit it by sending a specially crafted HTTPS request, potentially compromising entire clusters of connected systems.

    Another RCE flaw (CVE-2025-21376, CVSS 8.1) in Windows LDAP could allow attackers to execute arbitrary code, posing a major risk to enterprise networks that rely on Active Directory.

    Other Key Fixes and Third-Party Patches

    • NTLMv2 hash disclosure vulnerability (CVE-2025-21377, CVSS 6.5) – Attackers could authenticate as a targeted user.
    • Security patches from other vendors include Adobe, AMD, Apple, Cisco, Google, Intel, NVIDIA, Samsung, and more.

    Final Thoughts

    This Patch Tuesday update is one of the most important in recent months, addressing actively exploited Windows vulnerabilities that could be used for privilege escalation, remote code execution, and system compromise.

    Windows users and IT administrators should prioritize these updates immediately to secure their systems.

    Microsoft Windows
    Sazid Kabir
    • Website
    • X (Twitter)
    • Pinterest
    • Instagram
    • LinkedIn

    Founder & Chief Editor, NoMusica.com. Sazid Kabir is a tech writer and music producer covering music, tech, and music production with both analytical and practical experience.

    Keep Reading

    Are APK Downloads Safe? Risks, Legal Issues, and Safer Alternatives

    5 Best Free Firewall Apps for Android in 2026 (No Root Needed Options Included)

    50+ Best Android Alternative Apps ― Free Movies, No Ads, Offline Maps

    10 Best Free Movie Apps in 2026 (Safe & Working)

    10 Best Free Music Apps in 2026 (No Subscription Needed)

    WhatsApp Tests ‘Plus’ Subscription With New Premium Features

    Add A Comment
    Leave A Reply Cancel Reply

    Latest Posts

    Rinbga founders, Adam Young & Harrison Gevirtz, Convicted for Stealing Millions of Dollars with Tech Support Fraud Scheme

    July 27, 2026

    Crypto Traders Bet Big on Cardi B’s Womb in Wild “Cardi Bee” Presale Frenzy

    July 24, 2026

    Snoop Dogg Biopic Set for 2027 Release with Jonathan Daviss in Lead Role

    July 23, 2026

    Kevin durant Ignores Lionel Messi & racist Argentian Soccer Team, refusing to shake their Hands

    July 19, 2026

    Spotify Removes Over 75 Million AI-Generated Tracks in Major Crackdown

    July 18, 2026
    Pages
    • Home
    • Blog
    • About
    • Contact
    • Advertise
    • Cookie Policy
    • Privacy Policy
    Categories
    • AI
    • Tech & Science
    • Films & TV Shows
    • Entertainment
    • Music
    • Streaming
    • Music Production
    Random Reads

    DWTS Contestant Robert Irwin Shares Heartbreaking Update on Dog

    China Adds 15th Batch of Internet Satellites to Growing Guowang Network

    MediaTek Reveals Dimensity 9500 with Advanced Core Design

    Facebook X (Twitter) Instagram Pinterest
    © 2026 WowPress Digital

    Type above and press Enter to search. Press Esc to cancel.