CyberzSOC

Publication detail
← Back to advisories & guidance

2025-017: Critical Vulnerabilitites in Microsoft Products ↗ source

April 11, 2025 CERT-EU Advisory

Summary

It is recommended updating as soon as possible, prioritising critical devices and public facing This advisory describes some notable vulnerabilities addressed by the April 2025 Patch Tuesday. The vulnerability CVE-2025-29824, with a CVSS score of 7.8, is a user-after-free vulnerability in the Windows Common Log File System (CLFS) that can be exploited by attackers to elevate their privileges to SYSTEM on previously compromised Windows machines. This vulnerability is The vulnerabilities CVE-2025-26663 and CVE-2025-26670, both with a CVSS score of 8.1, are unauthenticated Remote Code Execution (RCE) vulnerabilities caused by user-after-free weaknesses in the Windows Lightweight Directory Access Protocol (LDAP). To be exploitable, they require an attacker to win a race condition via specially crafted requests sequentially sent The vulnerabilities CVE-2025-27480 and CVE-2025-27482, both with a CVSS score of 8.1, are RCE vulnerabilities in Windows Remote Desktop Services (RDP). To exploit them, an attacker must first connect to a system with the Remote Desktop Gateway role and trigger a race condition to create an exploitable use-after-free scenario.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-26663 8.1 High Microsoft Windows 10 Version 1809 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
CVE-2025-26670 8.1 High Microsoft Windows 10 Version 1809 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
CVE-2025-27480 8.1 High Microsoft Windows Server 2019 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
CVE-2025-27482 8.1 High Microsoft Windows Server 2019 Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
CVE-2025-27745 7.8 High Microsoft Microsoft Office 2019 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-27748 7.8 High Microsoft Microsoft 365 Apps for Enterprise Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-27749 7.8 High Microsoft Microsoft Office 2019 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-27752 7.8 High Microsoft Microsoft 365 Apps for Enterprise Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-29791 7.8 High Microsoft Microsoft Office 2019 Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-29824 7.8 High Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileg…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.