This website collects cookies to deliver better user experience, you agree to the Privacy Policy.
Accept
Sign In
The Texas Reporter
  • Home
  • Trending
  • Texas
  • World
  • Politics
  • Opinion
  • Business
    • Business
    • Economy
    • Real Estate
  • Crypto & NFTs
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Travel
    • Fashion
    • Books
    • Arts
  • Health
  • Sports
  • Entertainment
Reading: Microsoft Fixes 134 Vulnerabilities, Together with 1 Zero-Day
Share
The Texas ReporterThe Texas Reporter
Font ResizerAa
Search
  • Home
  • Trending
  • Texas
  • World
  • Politics
  • Opinion
  • Business
    • Business
    • Economy
    • Real Estate
  • Crypto & NFTs
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Travel
    • Fashion
    • Books
    • Arts
  • Health
  • Sports
  • Entertainment
Have an existing account? Sign In
Follow US
© The Texas Reporter. All Rights Reserved.
The Texas Reporter > Blog > World > Microsoft Fixes 134 Vulnerabilities, Together with 1 Zero-Day
World

Microsoft Fixes 134 Vulnerabilities, Together with 1 Zero-Day

Editorial Board
Editorial Board Published April 9, 2025
Share
Microsoft Fixes 134 Vulnerabilities, Together with 1 Zero-Day
SHARE
Microsoft Fixes 134 Vulnerabilities, Together with 1 Zero-Day
Microsoft CEO Satya Nadella. Picture: Microsoft Information

Microsoft’s Patch Tuesday safety replace for April included 134 flaws, considered one of which is an actively exploited zero-day flaw.

The safety patches for Home windows 10 have been unavailable when the Home windows 11 patches have been launched. The Home windows 10 patches have since arrived, however the delay was uncommon.

Tyler Reguly, affiliate director of safety R&D at world cybersecurity software program and companies supplier Fortra, instructed in an e-mail to TechRepublic that the 2 separate releases and a 40-minute delay within the Home windows 11 replace may level to one thing uncommon behind the scenes.

SEE: What’s Patch Tuesday? Microsoft’s Month-to-month Replace Defined

CVE-2025-29824 has been detected within the wild

The zero-day vulnerability was CVE-2025-29824, an elevation of privilege bug within the Home windows Frequent Log File System (CLFS) Driver.

“This vulnerability is significant because it affects a core component of Windows, impacting a wide range of environments, including enterprise systems and critical infrastructure,” Mike Walters, president and co-founder of patch automation firm Motion, wrote in an e-mail. “If exploited, it allows privilege escalation to SYSTEM level—the highest privilege on a Windows system.”

Elevation of privilege assaults require the menace actor to have a foothold within the system first.

“Elevation of privilege flaws in CLFS have become especially popular among ransomware operators over the years,” Satnam Narang, Tenable’s senior workers analysis engineer, mentioned in an e-mail.

“What makes this vulnerability particularly concerning is that Microsoft has confirmed active exploitation in the wild, yet at this time, no patch has been released for Windows 10 32-bit or 64-bit systems,” Ben McCarthy, lead cybersecurity engineer at safety coaching firm Immersive, added. “The lack of a patch leaves a critical gap in defense for a wide portion of the Windows ecosystem.”

The delayed rollout of Home windows 10 patches — paired with a 40-minute delay within the Home windows 11 replace — provides additional weight to issues about inner disruptions or challenges at Microsoft. Whereas the explanation for the delay stays unclear, safety researchers are paying attention to the timing, notably given the lively exploitation of CVE-2025-29824.

CVE-2025-29824 has been exploited towards “a small number of targets” in “organizations in the information technology (IT) and real estate sectors of the United States, the financial sector in Venezuela, a Spanish software company, and the retail sector in Saudi Arabia,” Microsoft disclosed.

“I was recently discussing CLFS vulnerabilities and how they seem to come in waves,” Reguly famous. “When a vulnerability in CLFS is patched, people tend to dig around and look at what’s going on and come across other vulnerabilities in the process. If I was a gambler, I would bet on CLFS appearing again next month.”

Distant code execution and Microsoft Workplace flaws are frequent patterns

Different notable elements of April’s Patch Tuesday embody a repair for CVE-2025-26663, a important flaw that might have an effect on organizations working Home windows Light-weight Listing Entry Protocol (LDAP) servers.

Reguly highlighted CVE-2025-27472, a vulnerability in Mark of the Net (MOTW) that Microsoft listed as Exploitation Extra Possible.  “It is common to see MOTW vulnerabilities utilized by threat actors,” he mentioned. “I wouldn’t be surprised if this is a vulnerability that we see exploited in the future.”

SEE: Select the best safety functions for your enterprise by balancing options, knowledge storage, and price. 

Microsoft launched a number of patches for CVEs in Workplace (CVE-2025-29791, CVE-2025-27749, CVE-2025-27748, and CVE-2025-27745). Microsoft Workplace’s recognition means these vulnerabilities have the potential for widespread issues, though all of them require profitable social engineering or distant code execution to inject a malicious file.

Whereas a few of these CVEs enabled distant code execution (RCE), this month’s Patch Tuesday advised a unique story general.

Should-read safety protection

“For the first time since August 2024, Patch Tuesday vulnerabilities skewed more towards elevation of privilege bugs, which accounted for over 40% (49) of all patched vulnerabilities,” Narang mentioned. “We typically see remote code execution (RCE) flaws dominate Patch Tuesday releases, but only a quarter of flaws (31) were RCEs this month.”

Reguly famous that Workplace, browsers, and MOTW have typically appeared in Patch Tuesday updates currently.

“If I were an infosec buyer, think CISO, I’d be looking at the trends in Microsoft vulnerabilities – recurring and commonly exploited technologies like Office, Edge, CLFS, and MOTW – and I’d be asking my vendors how they are helping me proactively defend against these types of vulnerabilities,” he mentioned.

Apple releases massive safety replace

As KrebsonSecurity identified, Apple customers shouldn’t neglect about safety patches.

Apple launched a big safety replace on March 31, addressing some actively exploited vulnerabilities. Basically, Patch Tuesday is an efficient time for organizations to push updates to company-owned units.

Contemplate backing up units earlier than updating in case one thing breaks within the newly put in software program.

TAGGED:Fixesincluding: •MicrosoftVulnerabilitiesZeroDay
Share This Article
Twitter Email Copy Link Print
Previous Article Michelle Obama Breaks Silence on Divorce Rumors: ‘I Was Making a Alternative For Myself’ Michelle Obama Breaks Silence on Divorce Rumors: ‘I Was Making a Alternative For Myself’
Next Article Walmart CEO says ‘there will likely be a Christmas’ regardless of lingering fears of a commerce battle Walmart CEO says ‘there will likely be a Christmas’ regardless of lingering fears of a commerce battle

Editor's Pick

‘Closing Vacation spot: Bloodlines’ continues Warner Bros. field workplace sizzling streak

‘Closing Vacation spot: Bloodlines’ continues Warner Bros. field workplace sizzling streak

Loss of life shouldn't be looming for the “Final Destination” franchise on the field workplace. Its sixth installment, “Final Destination: Bloodlines,” drew…

By Editorial Board 4 Min Read
Alpine’s Sizzling Hatch EV Has a Constructed-In, ‘Gran Turismo’ Model Driving Teacher

One other win over its Renault 5 sibling is a multi-link rear…

3 Min Read
Louis Vuitton Is Dropping a New Perfume As a result of It’s Sizzling | FashionBeans

We independently consider all beneficial services and products. Any services or products…

2 Min Read

Latest

Arizona hiker Hannah Moody’s physique discovered off path day after she was reported lacking

Arizona hiker Hannah Moody’s physique discovered off path day after she was reported lacking

The physique of a hiker was discovered off a path…

May 23, 2025

Germany Misses As much as $2.8 Billion Promoting Practically 50,000 Bitcoin at $54K-$57.6K as Value Doubles Over $104K – “The Defiant”

In mid-2024, the German authorities bought…

May 23, 2025

Europe is on edge as Russia builds up forces on Finland’s border. May this frontier be the subsequent battle zone?

Finland is intently monitoring Russia’s army…

May 23, 2025

Your Excellent Summer time Day Begins With These Goal Necessities

We could obtain a portion of…

May 23, 2025

The Finest Memorial Day Mattress Offers (and Bedding, Too!)

Memorial Day is quick approaching, as…

May 23, 2025

You Might Also Like

Power value cap drop is welcome – however eyes shall be on Trump, Ukraine and the climate forward of winter | Cash Information
World

Power value cap drop is welcome – however eyes shall be on Trump, Ukraine and the climate forward of winter | Cash Information

The most recent vitality value cap announcement brings a welcome if modest discount in costs for 22 million customers, and…

3 Min Read
Do you have to be mouth taping? What’s driving the viral pattern – Nationwide
World

Do you have to be mouth taping? What’s driving the viral pattern – Nationwide

Mouth taping, the observe of sealing the lips shut throughout sleep to encourage nasal respiration, has gained traction on-line, promoted as…

7 Min Read
Starmer’s winter gasoline minimize U-turn declare ‘not credible’ | Politics Information
World

Starmer’s winter gasoline minimize U-turn declare ‘not credible’ | Politics Information

Sir Keir Starmer’s declare he's U-turning on slicing winter gasoline funds for pensioners as a result of he now has…

6 Min Read
Politics At Play Over IPL Remaining Venue Shift
World

Politics At Play Over IPL Remaining Venue Shift

Final Up to date:Could 23, 2025, 08:31 IST West Bengal Sports activities Minister Aroop Biswas criticised the justification given by…

4 Min Read
The Texas Reporter

About Us

Welcome to The Texas Reporter, a newspaper based in Houston, Texas that covers a wide range of topics for our readers. At The Texas Reporter, we are dedicated to providing our readers with the latest news and information from around the world, with a focus on issues that are important to the people of Texas.

Company

  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • WP Creative Group
  • Accessibility Statement

Contact Us

  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability

Term of Use

  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices

© The Texas Reporter. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?