Microsoft released the March 2025 Patch Tuesday, which fixes 57 vulnerabilities, including seven zero-days.

In the list below, you can see the categories of bugs that are being fixed this month:
• 23 vulnerabilities that allow remote code execution
• 23 vulnerabilities that allow elevation of privilege
• 4 vulnerabilities that allow information disclosure
• 3 vulnerabilities that allow spoofing
• 3 vulnerabilities that allow bypassing security features
• 1 vulnerability that allows Denial of Service attacks
The above numbers do not include Mariner bugs and 10 Microsoft Edge vulnerabilities that were patched a few days ago.
See also: Zygote Injection vulnerability allows code execution on Android
Microsoft Patch Tuesday March 2025: Zero-day vulnerabilities
This month's Patch Tuesday fixes six zero-day vulnerabilities that have already been exploited in attacks and one that has been publicly disclosed. Microsoft classifies a bug as a zero-day when it is publicly disclosed or exploited in attacks and no official patch is available.
Vulnerabilities that have been exploited:
CVE-2025-24983: Windows Win32 Kernel Subsystem – Elevation of Privilege
Microsoft says this vulnerability allows local attackers to gain SYSTEM privilegesafter winning a race condition. Microsoft has not provided details on how the flaw could be exploited in attacks.
CVE-2025-24984: Windows NTFS – Information Disclosure Vulnerability
Microsoft says this vulnerability can be exploited by attackers who have physical access to the device and can insert a malicious USB drive. The exploit allows attackers to read parts of the heap memory and steal information.
CVE-2025-24985: Windows Fast FAT File System Driver – Remote Code Execution
Microsoft's March Patch Tuesday also fixes a zero-day vulnerability that allows remote code execution.
“An attacker could trick a local user on a vulnerable system into installing a specially crafted VHD that would then trigger the vulnerability,” Microsoft explains. The company has not shared details on how the vulnerability could be exploited.
See also: CISA: Advantive VeraCore and Ivanti vulnerabilities in the KEV List
CVE-2025-24991: Windows NTFS – Information Disclosure Vulnerability
Microsoft says that attackers can exploit this flaw to read part of the heap memory and steal information.
Attackers can exploit the flaw by tricking a user into attaching a malicious VHD file.
CVE-2025-24993: Windows NTFS – Remote Code Execution
Microsoft says this vulnerability allows an attacker to execute arbitrary code.
"An attacker could trick a local user on a vulnerable system into installing a specially crafted VHD that would then trigger the vulnerability," Microsoft explains.
CVE-2025-26633: Microsoft Management Console – Security Bypass
"In an email or instant messaging, an attacker could send the targeted user a specially crafted file that is designed to exploit the vulnerability," Microsoft explains.
“In any case, an attacker would have no way to force a user to view content controlled by the attacker. Instead, an attacker would have to convince a user to take action. For example, an attacker could entice a user to either click on a link that directs the user to the attacker's website or send a malicious attachment“.
See also: Learn everything about out-of-bounds write vulnerabilities
As we mentioned earlier, Microsoft's March Patch Tuesday also fixes a zero-day vulnerability that has just been publicly disclosed. It is:
CVE-2025-26630: Microsoft Access – Remote Code Execution
To exploit the vulnerability, a user must be tricked into opening a specially crafted Access file. This can be done through phishing or social engineering attacks.
However, the flaw cannot be exploited through the preview window.

Microsoft Patch Tuesday March 2025: All vulnerabilities fixed:
| Tags | CVE ID | CVE Title | Severity |
|---|---|---|---|
| .NET | CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability | Important |
| ASP.NET Core & Visual Studio | CVE-2025-24070 | ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability | Important |
| Azure Agent Installer | CVE-2025-21199 | Azure Agent Installer for Backup and Site Recovery Elevation of Privilege Vulnerability | Important |
| Azure Arc | CVE-2025-26627 | Azure Arc Installer Elevation of Privilege Vulnerability | Important |
| Azure CLI | CVE-2025-24049 | Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability | Important |
| Azure PromptFlow | CVE-2025-24986 | Azure Promptflow Remote Code Execution Vulnerability | Important |
| Kernel Streaming WOW Thunk Service Driver | CVE-2025-24995 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Important |
| Microsoft Local Security Authority Server (lsasrv) | CVE-2025-24072 | Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability | Important |
| Microsoft Management Console | CVE-2025-26633 | Microsoft Management Console Security Feature Bypass Vulnerability | Important |
| Microsoft Office | CVE-2025-24083 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2025-26629 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2025-24080 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2025-24057 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office Access | CVE-2025-26630 | Microsoft Access Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2025-24081 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2025-24082 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2025-24075 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Word | CVE-2025-24077 | Microsoft Word Remote Code Execution Vulnerability | Important |
| Microsoft Office Word | CVE-2025-24078 | Microsoft Word Remote Code Execution Vulnerability | Important |
| Microsoft Office Word | CVE-2025-24079 | Microsoft Word Remote Code Execution Vulnerability | Important |
| Microsoft Streaming Service | CVE-2025-24046 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important |
| Microsoft Streaming Service | CVE-2025-24067 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important |
| Microsoft Windows | CVE-2025-25008 | Windows Server Elevation of Privilege Vulnerability | Important |
| Microsoft Windows | CVE-2024-9157 | Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading Vulnerability | Important |
| Remote Desktop Client | CVE-2025-26645 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Role: DNS Server | CVE-2025-24064 | Windows Domain Name Service Remote Code Execution Vulnerability | Critical |
| Role: Windows Hyper-V | CVE-2025-24048 | Windows Hyper-V Elevation of Privilege Vulnerability | Important |
| Role: Windows Hyper-V | CVE-2025-24050 | Windows Hyper-V Elevation of Privilege Vulnerability | Important |
| Visual Studio | CVE-2025-24998 | Visual Studio Elevation of Privilege Vulnerability | Important |
| Visual Studio | CVE-2025-25003 | Visual Studio Elevation of Privilege Vulnerability | Important |
| Visual Studio Code | CVE-2025-26631 | Visual Studio Code Elevation of Privilege Vulnerability | Important |
| Windows Common Log File System Driver | CVE-2025-24059 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important |
| Windows Cross Device Service | CVE-2025-24994 | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability | Important |
| Windows Cross Device Service | CVE-2025-24076 | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability | Important |
| Windows exFAT File System | CVE-2025-21180 | Windows exFAT File System Remote Code Execution Vulnerability | Important |
| Windows Fast FAT Driver | CVE-2025-24985 | Windows Fast FAT File System Driver Remote Code Execution Vulnerability | Important |
| Windows File Explorer | CVE-2025-24071 | Microsoft Windows File Explorer Spoofing Vulnerability | Important |
| Windows Kernel Memory | CVE-2025-24997 | DirectX Graphics Kernel File Denial of Service Vulnerability | Important |
| Windows Kernel-Mode Drivers | CVE-2025-24066 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important |
| Windows MapUrlToZone | CVE-2025-21247 | MapUrlToZone Security Feature Bypass Vulnerability | Important |
| Windows Mark of the Web (MOTW) | CVE-2025-24061 | Windows Mark of the Web Security Feature Bypass Vulnerability | Important |
| Windows NTFS | CVE-2025-24993 | Windows NTFS Remote Code Execution Vulnerability | Important |
| Windows NTFS | CVE-2025-24984 | Windows NTFS Information Disclosure Vulnerability | Important |
| Windows NTFS | CVE-2025-24992 | Windows NTFS Information Disclosure Vulnerability | Important |
| Windows NTFS | CVE-2025-24991 | Windows NTFS Information Disclosure Vulnerability | Important |
| Windows NTLM | CVE-2025-24996 | NTLM Hash Disclosure Spoofing Vulnerability | Important |
| Windows NTLM | CVE-2025-24054 | NTLM Hash Disclosure Spoofing Vulnerability | Important |
| Windows Remote Desktop Services | CVE-2025-24035 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical |
| Windows Remote Desktop Services | CVE-2025-24045 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical |
| Windows Routing and Remote Access Service (RRAS) | CVE-2025-24051 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important |
| Windows Subsystem for Linux | CVE-2025-24084 | Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability | Critical |
| Windows Telephony Server | CVE-2025-24056 | Windows Telephony Service Remote Code Execution Vulnerability | Important |
| Windows USB Video Driver | CVE-2025-24988 | Windows USB Video Class System Driver Elevation of Privilege Vulnerability | Important |
| Windows USB Video Driver | CVE-2025-24987 | Windows USB Video Class System Driver Elevation of Privilege Vulnerability | Important |
| Windows USB Video Driver | CVE-2025-24055 | Windows USB Video Class System Driver Information Disclosure Vulnerability | Important |
| Windows Win32 Kernel Subsystem | CVE-2025-24044 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | Important |
| Windows Win32 Kernel Subsystem | CVE-2025-24983 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | Important |
Microsoft Patch Tuesday March 2025
Microsoft Patch Tuesday is a practice followed by Microsoft, where on the second Tuesday of each month it releases updates and fixes for its operating systems, programs, and applications. These updates typically include security, performance improvements, and new features.
The purpose of Microsoft Patch Tuesday is to provide Microsoft users with the best possible user experience by fixing issues and ensuring the security of their systems. Security updates help protect systems from security vulnerabilities and malware. These updates fix known security issues and strengthen the resilience of systems against attacks.
Source: www.bleepingcomputer.com
