Microsoft’s February 2025 Patch Tuesday fixes multiple vulnerabilities, including critical RCE and privilege escalation flaws. Users and organizations should update immediately to stay protected.
All about the vulnerability
The February update addressed:
- 25 Remote Code Execution flaws
- 14 Elevation of Privilege vulnerabilities
- 6 Denial of Service issues
- 4 Security Feature Bypass flaws
- 2 Spoofing vulnerabilities
- 1 Information Disclosure vulnerability
Microsoft Patch Tuesday – February 2025
This update addresses 61+ vulnerabilities, including critical and important flaws:
Critical Vulnerabilities:
- CVE-2025-21376: Remote code execution via LDAP protocol.
- CVE-2025-21379: RCE risk via crafted DHCP packets.
- CVE-2025-21381, 21386, 21387: Excel vulnerabilities allowing code execution via malicious files.
- CVE-2025-21406, 21407: RCE vulnerabilities in Windows Telephony Service.
Exploited in the Wild:
- CVE-2023-24932: Secure Boot bypass risk.
- CVE-2025-21391: Elevated privileges for attackers.
- CVE-2025-21418: SYSTEM privileges gained via exploit.
Other Notable Fixes:
- Visual Studio RCE (CVE-2025-21176, 21178): Immediate updates needed for RCE risks.
- Azure Network Watcher Elevation of Privilege (CVE-2025-21188): Update for Azure cloud admins.
- Microsoft Office RCE (CVE-2025-21392, 21397): Fix for Office document exploit risks.
Here’s a table of 61 vulnerabilities addressed in Microsoft’s February 2025 Patch Tuesday, based on the provided data and search results.
CVE ID | Title | Impact | Severity | Exploited |
---|---|---|---|---|
CVE-2025-21376 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Remote Code Execution | Critical | No |
CVE-2025-21379 | DHCP Client Service Remote Code Execution Vulnerability | Remote Code Execution | Critical | No |
CVE-2025-21381 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | Critical | No |
CVE-2023-24932 | Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | Important | Yes |
CVE-2025-21176 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21178 | Visual Studio Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21188 | Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21206 | Visual Studio Installer Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21351 | Windows Active Directory Domain Services API Denial of Service Vulnerability | Denial of Service | Important | No |
CVE-2025-21352 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | Denial of Service | Important | No |
CVE-2025-21368 | Microsoft Digest Authentication Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21369 | Microsoft Digest Authentication Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21375 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21383 | Microsoft Excel Information Disclosure Vulnerability | Information Disclosure | Important | No |
CVE-2025-21182 | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21183 | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21391 | Windows Storage Elevation of Privilege Vulnerability | Elevation of Privilege | Important | Yes |
CVE-2025-21418 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | Important | Yes |
CVE-2025-21419 | Windows Setup Files Cleanup Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21420 | Windows Disk Cleanup Tool Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2023-32002 | Node.js Module._load() Policy Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-24036 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-24039 | Visual Studio Code Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21259 | Microsoft Outlook Spoofing Vulnerability | Spoofing | Important | No |
CVE-2025-21194 | Microsoft Surface Security Feature Bypass Vulnerability | Security Feature Bypass | Important | No |
CVE-2025-21208 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21406 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21407 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21410 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21190 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21200 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21201 | Windows Telephony Server Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21198 | Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21337 | Windows NTFS Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21347 | Windows Deployment Services Denial of Service Vulnerability | Denial of Service | Important | No |
CVE-2025-21349 | Windows Remote Desktop Configuration Service Tampering Vulnerability | Tampering | Important | No |
CVE-2025-21350 | Windows Kerberos Denial of Service Vulnerability | Denial of Service | Important | No |
CVE-2025-21358 | Windows Core Messaging Elevation of Privileges Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21359 | Windows Kernel Security Feature Bypass Vulnerability | Security Feature Bypass | Important | No |
CVE-2025-21367 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21371 | Windows Telephony Service Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21377 | NTLM Hash Disclosure Spoofing Vulnerability | Spoofing | Important | No |
CVE-2025-21386 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21387 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21390 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21392 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21394 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21397 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21400 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Remote Code Execution | Important | No |
CVE-2025-21179 | DHCP Client Service Denial of Service Vulnerability | Denial of Service | Important | No |
CVE-2025-21181 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Denial of Service | Important | No |
CVE-2025-21184 | Windows Core Messaging Elevation of Privileges Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21212 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | Denial of Service | Important | No |
CVE-2025-21216 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | Denial of Service | Important | No |
CVE-2025-21254 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | Denial of Service | Important | No |
CVE-2025-21322 | Microsoft PC Manager Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21414 | Windows Core Messaging Elevation of Privileges Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-21373 | Windows Installer Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
CVE-2025-24042 | Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability | Elevation of Privilege | Important | No |
With two vulnerabilities actively exploited, delaying updates could leave systems vulnerable to threats.
Microsoft stresses the need to install the latest servicing stack updates (ADV990001) for smooth patch deployment.
How to Update:
- Windows Update: Go to Settings > Update & Security > Windows Update.
- Microsoft Update Catalog: Download individual patches for offline installation.
- WSUS: For enterprise environments.
The February 2025 Patch Tuesday highlights the growing complexity of cybersecurity threats. IT teams must act quickly to deploy these critical patches and stay vigilant against phishing and other exploits targeting unpatched systems.
Follow Us on: Twitter, Instagram, Facebook to get the latest security news!
Leave A Comment