Microsoft Monthly Security Update (April 2025)
Release Date: 9 Apr 2025
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
Microsoft has released monthly security update for their products:
Vulnerable Product | Risk Level | Impacts | Notes |
Windows | ![]() | Remote Code Execution Information Disclosure Elevation of Privilege Denial of Service Security Restriction Bypass Spoofing | CVE-2025-29824 is being exploited in the wild. This vulnerability allows local attackers to gain SYSTEM privileges on the device/system. |
Extended Security Updates (ESU) | ![]() | Remote Code Execution Information Disclosure Elevation of Privilege Denial of Service Security Restriction Bypass | CVE-2025-29824 is being exploited in the wild. This vulnerability allows local attackers to gain SYSTEM privileges on the device/system. |
Microsoft Office | ![]() | Elevation of Privilege Remote Code Execution Security Restriction Bypass | |
System Center | ![]() | Elevation of Privilege | |
Browser | ![]() | Spoofing Remote Code Execution | |
Microsoft Dynamics | ![]() | Information Disclosure | |
Azure | ![]() | Information Disclosure Elevation of Privilege | |
Developer Tools | ![]() | Elevation of Privilege Denial of Service | |
SQL Server | ![]() | Elevation of Privilege | |
Apps | ![]() | Information Disclosure |
Number of 'Extremely High Risk' product(s): 0
Number of 'High Risk' product(s): 0
Number of 'Medium Risk' product(s): 10
Number of 'Low Risk' product(s): 0
Evaluation of overall 'Risk Level': Medium Risk
Impact
- Elevation of Privilege
- Remote Code Execution
- Denial of Service
- Security Restriction Bypass
- Spoofing
- Information Disclosure
System / Technologies affected
- Windows
- Extended Security Updates (ESU)
- Microsoft Office
- System Center
- Browser
- Microsoft Dynamics
- Azure
- Developer Tools
- SQL Server
- Apps
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Apply fixes issued by the vendor.
沒有留言:
發佈留言