HomeUpdatesMicrosoft Patch Tuesday March 2025: Fixes 57 vulnerabilities

Microsoft Patch Tuesday March 2025: Fixes 57 vulnerabilities

Microsoft released the March 2025 Patch Tuesday, which fixes 57 vulnerabilities, including seven zero-days.

Microsoft Patch Tuesday March 2025 vulnerabilities

In the list below, you can see the categories of bugs that are being fixed this month:

• 23 vulnerabilities that allow remote code execution
• 23 vulnerabilities that allow elevation of privilege
• 4 vulnerabilities that allow information disclosure
• 3 vulnerabilities that allow spoofing
• 3 vulnerabilities that allow bypassing security features
• 1 vulnerability that allows Denial of Service attacks

The above numbers do not include Mariner bugs and 10 Microsoft Edge vulnerabilities that were patched a few days ago.

See also: Zygote Injection vulnerability allows code execution on Android

Microsoft Patch Tuesday March 2025: Zero-day vulnerabilities

This month's Patch Tuesday fixes six zero-day vulnerabilities that have already been exploited in attacks and one that has been publicly disclosed. Microsoft classifies a bug as a zero-day when it is publicly disclosed or exploited in attacks and no official patch is available.

Vulnerabilities that have been exploited:

CVE-2025-24983: Windows Win32 Kernel Subsystem – Elevation of Privilege

Microsoft says this vulnerability allows local attackers to gain SYSTEM privilegesafter winning a race condition. Microsoft has not provided details on how the flaw could be exploited in attacks.

CVE-2025-24984: Windows NTFS – Information Disclosure Vulnerability

Microsoft says this vulnerability can be exploited by attackers who have physical access to the device and can insert a malicious USB drive. The exploit allows attackers to read parts of the heap memory and steal information.

CVE-2025-24985: Windows Fast FAT File System Driver – Remote Code Execution

Microsoft's March Patch Tuesday also fixes a zero-day vulnerability that allows remote code execution.

“An attacker could trick a local user on a vulnerable system into installing a specially crafted VHD that would then trigger the vulnerability,” Microsoft explains. The company has not shared details on how the vulnerability could be exploited.

See also: CISA: Advantive VeraCore and Ivanti vulnerabilities in the KEV List

CVE-2025-24991: Windows NTFS – Information Disclosure Vulnerability

Microsoft says that attackers can exploit this flaw to read part of the heap memory and steal information.

Attackers can exploit the flaw by tricking a user into attaching a malicious VHD file.

CVE-2025-24993: Windows NTFS – Remote Code Execution

Microsoft says this vulnerability allows an attacker to execute arbitrary code.

"An attacker could trick a local user on a vulnerable system into installing a specially crafted VHD that would then trigger the vulnerability," Microsoft explains.

CVE-2025-26633: Microsoft Management Console – Security Bypass

"In an email or instant messaging, an attacker could send the targeted user a specially crafted file that is designed to exploit the vulnerability," Microsoft explains.

“In any case, an attacker would have no way to force a user to view content controlled by the attacker. Instead, an attacker would have to convince a user to take action. For example, an attacker could entice a user to either click on a link that directs the user to the attacker's website or send a malicious attachment“.

See also: Learn everything about out-of-bounds write vulnerabilities

As we mentioned earlier, Microsoft's March Patch Tuesday also fixes a zero-day vulnerability that has just been publicly disclosed. It is:

CVE-2025-26630: Microsoft Access – Remote Code Execution

To exploit the vulnerability, a user must be tricked into opening a specially crafted Access file. This can be done through phishing or social engineering attacks.

However, the flaw cannot be exploited through the preview window.

Microsoft Patch Tuesday March 2025: Fixes 57 vulnerabilities

Microsoft Patch Tuesday March 2025: All vulnerabilities fixed:

TagsCVE IDCVE TitleSeverity
.NETCVE-2025-24043WinDbg Remote Code Execution VulnerabilityImportant
ASP.NET Core & Visual StudioCVE-2025-24070ASP.NET Core and Visual Studio Elevation of Privilege VulnerabilityImportant
Azure Agent InstallerCVE-2025-21199Azure Agent Installer for Backup and Site Recovery Elevation of Privilege VulnerabilityImportant
Azure ArcCVE-2025-26627Azure Arc Installer Elevation of Privilege VulnerabilityImportant
Azure CLICVE-2025-24049Azure Command Line Integration (CLI) Elevation of Privilege VulnerabilityImportant
Azure PromptFlowCVE-2025-24986Azure Promptflow Remote Code Execution VulnerabilityImportant
Kernel Streaming WOW Thunk Service DriverCVE-2025-24995Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityImportant
Microsoft Local Security Authority Server (lsasrv)CVE-2025-24072Microsoft Local Security Authority (LSA) Server Elevation of Privilege VulnerabilityImportant
Microsoft Management ConsoleCVE-2025-26633Microsoft Management Console Security Feature Bypass VulnerabilityImportant
Microsoft OfficeCVE-2025-24083Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2025-26629Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2025-24080Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2025-24057Microsoft Office Remote Code Execution VulnerabilityCritical
Microsoft Office AccessCVE-2025-26630Microsoft Access Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-24081Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-24082Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-24075Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office WordCVE-2025-24077Microsoft Word Remote Code Execution VulnerabilityImportant
Microsoft Office WordCVE-2025-24078Microsoft Word Remote Code Execution VulnerabilityImportant
Microsoft Office WordCVE-2025-24079Microsoft Word Remote Code Execution VulnerabilityImportant
Microsoft Streaming ServiceCVE-2025-24046Kernel Streaming Service Driver Elevation of Privilege VulnerabilityImportant
Microsoft Streaming ServiceCVE-2025-24067Kernel Streaming Service Driver Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2025-25008Windows Server Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2024-9157Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading VulnerabilityImportant
Remote Desktop ClientCVE-2025-26645Remote Desktop Client Remote Code Execution VulnerabilityCritical
Role: DNS ServerCVE-2025-24064Windows Domain Name Service Remote Code Execution VulnerabilityCritical
Role: Windows Hyper-VCVE-2025-24048Windows Hyper-V Elevation of Privilege VulnerabilityImportant
Role: Windows Hyper-VCVE-2025-24050Windows Hyper-V Elevation of Privilege VulnerabilityImportant
Visual StudioCVE-2025-24998Visual Studio Elevation of Privilege VulnerabilityImportant
Visual StudioCVE-2025-25003Visual Studio Elevation of Privilege VulnerabilityImportant
Visual Studio CodeCVE-2025-26631Visual Studio Code Elevation of Privilege VulnerabilityImportant
Windows Common Log File System DriverCVE-2025-24059Windows Common Log File System Driver Elevation of Privilege VulnerabilityImportant
Windows Cross Device ServiceCVE-2025-24994Microsoft Windows Cross Device Service Elevation of Privilege VulnerabilityImportant
Windows Cross Device ServiceCVE-2025-24076Microsoft Windows Cross Device Service Elevation of Privilege VulnerabilityImportant
Windows exFAT File SystemCVE-2025-21180Windows exFAT File System Remote Code Execution VulnerabilityImportant
Windows Fast FAT DriverCVE-2025-24985Windows Fast FAT File System Driver Remote Code Execution VulnerabilityImportant
Windows File ExplorerCVE-2025-24071Microsoft Windows File Explorer Spoofing VulnerabilityImportant
Windows Kernel MemoryCVE-2025-24997DirectX Graphics Kernel File Denial of Service VulnerabilityImportant
Windows Kernel-Mode DriversCVE-2025-24066Kernel Streaming Service Driver Elevation of Privilege VulnerabilityImportant
Windows MapUrlToZoneCVE-2025-21247MapUrlToZone Security Feature Bypass VulnerabilityImportant
Windows Mark of the Web (MOTW)CVE-2025-24061Windows Mark of the Web Security Feature Bypass VulnerabilityImportant
Windows NTFSCVE-2025-24993Windows NTFS Remote Code Execution VulnerabilityImportant
Windows NTFSCVE-2025-24984Windows NTFS Information Disclosure VulnerabilityImportant
Windows NTFSCVE-2025-24992Windows NTFS Information Disclosure VulnerabilityImportant
Windows NTFSCVE-2025-24991Windows NTFS Information Disclosure VulnerabilityImportant
Windows NTLMCVE-2025-24996NTLM Hash Disclosure Spoofing VulnerabilityImportant
Windows NTLMCVE-2025-24054NTLM Hash Disclosure Spoofing VulnerabilityImportant
Windows Remote Desktop ServicesCVE-2025-24035Windows Remote Desktop Services Remote Code Execution VulnerabilityCritical
Windows Remote Desktop ServicesCVE-2025-24045Windows Remote Desktop Services Remote Code Execution VulnerabilityCritical
Windows Routing and Remote Access Service (RRAS)CVE-2025-24051Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Subsystem for LinuxCVE-2025-24084Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution VulnerabilityCritical
Windows Telephony ServerCVE-2025-24056Windows Telephony Service Remote Code Execution VulnerabilityImportant
Windows USB Video DriverCVE-2025-24988Windows USB Video Class System Driver Elevation of Privilege VulnerabilityImportant
Windows USB Video DriverCVE-2025-24987Windows USB Video Class System Driver Elevation of Privilege VulnerabilityImportant
Windows USB Video DriverCVE-2025-24055Windows USB Video Class System Driver Information Disclosure VulnerabilityImportant
Windows Win32 Kernel SubsystemCVE-2025-24044Windows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityImportant
Windows Win32 Kernel SubsystemCVE-2025-24983Windows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityImportant

Microsoft Patch Tuesday March 2025

Microsoft Patch Tuesday is a practice followed by Microsoft, where on the second Tuesday of each month it releases updates and fixes for its operating systems, programs, and applications. These updates typically include security, performance improvements, and new features.

The purpose of Microsoft Patch Tuesday is to provide Microsoft users with the best possible user experience by fixing issues and ensuring the security of their systems. Security updates help protect systems from security vulnerabilities and malware. These updates fix known security issues and strengthen the resilience of systems against attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS