Close Menu
Karachi Chronicle
  • Home
  • AI
  • Business
  • Entertainment
  • Fashion
  • Politics
  • Sports
  • Tech
  • World

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Russia-Ukraine War: Putin says he will meet Zelensky, but only in the “final stage” of discussion

Three times more fatal! Thanks to the SIC, China’s J-20 stealth fighters can now detect enemy jets at distances such as F-35, F-22, and more.

Chinese researchers release the world’s first fully automated AI-based processor chip design system

Facebook X (Twitter) Instagram
  • Home
  • About us
  • Advertise
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram Pinterest Vimeo
Karachi Chronicle
  • Home
  • AI
  • Business
  • Entertainment
  • Fashion
  • Politics
  • Sports
  • Tech
  • World
Karachi Chronicle
You are at:Home » Microsoft February 2025 Patch Tuesday fixed 57 bugs and 3 important
Tech

Microsoft February 2025 Patch Tuesday fixed 57 bugs and 3 important

Adnan MaharBy Adnan MaharFebruary 12, 2025No Comments3 Mins Read0 Views
Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


Microsoft tracked Tuesday’s update this month to a major patch in January, including fixes for 159 vulnerabilities with more modest crops. This time, we released 57 new common vulnerabilities and exposure (CVE) fixes in the update, three of which are important.

The Zero Day Initiative’s Dustin Childs describes one of the vulnerabilities as unprecedented in the wild. This is Windows Storage Height Privilege (EOP) vulnerability, CVE-2025-21391.

In a blog post, Childs said: “This is… a kind of bug that we’ve never seen. The vulnerability allows attackers to delete target files. How does this lead to privilege escalation? My colleague, Simon Zucker Brown details the technique here. We’ve seen similar issues in the past, but this seems to be the first time this technique has been exploited in the wild. We also have completely lost the system. It could be paired with a code execution bug to take over. We’ll quickly test and deploy this.”

In Computer Weekly’s sister title SearchWindowsServer, Tom Walat chose two new zero-day vulnerabilities Microsoft fixed in the patch on Tuesday.

“The first new zero-day is the Winsock Ancillary Function driver for Winsock Promotion Vulnerability (CVE-2025-21418), rated as important with a CVSS (Common Vulnerability Scoring System) score of 7.8. This bug affects all currently supported Windows desktop and server systems,” he writes.

The second new zero day is the Storage EOP Vulnerability (CVE-2025-21391) commented on by Childrens. Walat added: If successful, an attacker can delete files on the system, causing service disruptions and take other actions, such as increasing privileges. ”

Childs has selected CVE-2025-21376, a Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution (RCE) vulnerability. “The vulnerability allows remote, unrecognized attackers to execute code on the affected system simply by sending a malicious request to the target,” he writes. “Because user interactions are not involved, this bug will be decorative between affected LDAP servers. Microsoft lists this as “highly exploitable” so this is It may not be possible, but I treat this as urgent exploitation. Quickly test and deploy patches. ”

In the CVE note for this “critical” vulnerability with a CVSS rating of 8.1, Microsoft said: Successful exploitation can result in buffer overflows, which can be used to enable remote code execution. ”

The update also includes several bug fixes for Microsoft Excel, including the RCE vulnerability CVE-2025-21387. “This is one of several Excel fixes where the preview pane is an attack vector, and I’m also confused that Microsoft needs user interaction,” Childs said. “They also need multiple patches to fully address this vulnerability. This can be used to open malicious Excel files or preview malicious attachments in Outlook. This can be exploited by doing so. In any case, make sure you have tested and deployed all the patches you need.”

The vulnerability is one of six Excel flaws that Microsoft fixed this month, which proved to be a relatively light patch on Tuesday.



Source link

Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
Previous ArticleTesla can’t afford another Twitter size distraction
Next Article 1 Must-see 1 quote for AI stock investors from ARM Holdings CEO
Adnan Mahar
  • Website

Adnan is a passionate doctor from Pakistan with a keen interest in exploring the world of politics, sports, and international affairs. As an avid reader and lifelong learner, he is deeply committed to sharing insights, perspectives, and thought-provoking ideas. His journey combines a love for knowledge with an analytical approach to current events, aiming to inspire meaningful conversations and broaden understanding across a wide range of topics.

Related Posts

Chinese researchers release the world’s first fully automated AI-based processor chip design system

June 13, 2025

Qualcomm’s Snapdragon Chips gets into trouble after a judge refuses to dismiss the case

May 30, 2025

Amazon will face Elon Musk’s Tesla with the robot launch.

May 7, 2025
Leave A Reply Cancel Reply

Top Posts

20 Most Anticipated Sex Movies of 2025

January 22, 2025110 Views

President Trump’s SEC nominee Paul Atkins marries multi-billion dollar roof fortune

December 14, 2024102 Views

Alice Munro’s Passive Voice | New Yorker

December 23, 202458 Views

How to tell the difference between fake and genuine Adidas Sambas

December 26, 202437 Views
Don't Miss
AI June 1, 2025

Dig into Google Deepmind CEO “Shout Out” Chip Engineers and Openai CEO Sam Altman, Sundar Pichai responds with emojis

Demis Hassabis, CEO of Google Deepmind, has expanded public approval to its chip engineers, highlighting…

Google, Nvidia invests in AI startup Safe Superintelligence, co-founder of Openai Ilya Sutskever

This $30 billion AI startup can be very strange by a man who said that neural networks may already be aware of it

As Deepseek and ChatGpt Surge, is Delhi behind?

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to Karachi Chronicle, your go-to source for the latest and most insightful updates across a range of topics that matter most in today’s fast-paced world. We are dedicated to delivering timely, accurate, and engaging content that covers a variety of subjects including Sports, Politics, World Affairs, Entertainment, and the ever-evolving field of Artificial Intelligence.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Russia-Ukraine War: Putin says he will meet Zelensky, but only in the “final stage” of discussion

Three times more fatal! Thanks to the SIC, China’s J-20 stealth fighters can now detect enemy jets at distances such as F-35, F-22, and more.

Chinese researchers release the world’s first fully automated AI-based processor chip design system

Most Popular

ATUA AI (TUA) develops cutting-edge AI infrastructure to optimize distributed operations

October 11, 20020 Views

10 things you should never say to an AI chatbot

November 10, 20040 Views

Character.AI faces lawsuit over child safety concerns

December 12, 20050 Views
© 2025 karachichronicle. Designed by karachichronicle.
  • Home
  • About us
  • Advertise
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.