CyberzSOC

Publication detail
← Back to advisories & guidance

2025-002: Multiple Vulnerabilities in Microsoft Products ↗ source

January 15, 2025 CERT-EU Advisory

Summary

The patches include fixes for critical and important-severity issues that could allow attackers to gain unauthorised access, execute arbitrary code, or elevate privileges. Three vulnerabilities were already being exploited The eight (8) zero-day vulnerabilities resolved in this update are: elevation of privilege vulnerabilities in Windows Hyper-V that were exploited in attacks to gain SYSTEM privileges on Windows devices. An attacker could convince a user to load a malicious file onto a vulnerable system and then convince the user to manipulate the specially crafted file, but not necessarily click or open the malicious file. Manipulating the malicious file could allow an attacker exfiltrated NTLM hashes to a remote server. three remote code execution vulnerabilities in Microsoft Access that could be exploited when opening specially crafted Microsoft Access documents. Microsoft also released fixes for 12 critical vulnerabilities, including: Microsoft Digest Authentication. in the Reliable Multicast Transport driver (RMCAST).

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-21298 9.8 Critical Microsoft Windows 10 Version 1507 Windows OLE Remote Code Execution Vulnerability
CVE-2025-21307 9.8 Critical Microsoft Windows 10 Version 1507 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2025-21311 9.8 Critical Microsoft Windows 11 Version 24H2 Windows NTLM V1 Elevation of Privilege Vulnerability
CVE-2025-21354 8.4 High Microsoft Microsoft 365 Apps for Enterprise Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-21362 8.4 High Microsoft Microsoft 365 Apps for Enterprise Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-21294 8.1 High Microsoft Windows 10 Version 1507 Microsoft Digest Authentication Remote Code Execution Vulnerability
CVE-2025-21297 8.1 High Microsoft Windows Server 2008 R2 Service Pack 1 Windows Remote Desktop Services Remote Code Execution Vulnerability
CVE-2025-21309 8.1 High Microsoft Windows Server 2012 Windows Remote Desktop Services Remote Code Execution Vulnerability
CVE-2025-21186 7.8 High Microsoft Microsoft 365 Apps for Enterprise Microsoft Access Remote Code Execution Vulnerability
CVE-2025-21275 7.8 High Microsoft Windows 10 Version 21H2 Windows App Package Installer Elevation of Privilege Vulnerability
CVE-2025-21333 7.8 High Microsoft Windows Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM p…
CVE-2025-21334 7.8 High Microsoft Windows Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21335 7.8 High Microsoft Windows Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21366 7.8 High Microsoft Microsoft 365 Apps for Enterprise Microsoft Access Remote Code Execution Vulnerability
CVE-2025-21395 7.8 High Microsoft Microsoft 365 Apps for Enterprise Microsoft Access Remote Code Execution Vulnerability
CVE-2025-21308 6.5 Medium Microsoft Windows 10 Version 1507 Windows Themes Spoofing Vulnerability

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.