2025年4月9日星期三

Microsoft Monthly Security Update (April 2025)

Microsoft Monthly Security Update (April 2025)

Release Date: 9 Apr 2025

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
WindowsMedium Risk Medium RiskRemote Code Execution
Information Disclosure
Elevation of Privilege
Denial of Service
Security Restriction Bypass
Spoofing
CVE-2025-29824 is being exploited in the wild. This vulnerability allows local attackers to gain SYSTEM privileges on the device/system.
Extended Security Updates (ESU)Medium Risk Medium RiskRemote Code Execution
Information Disclosure
Elevation of Privilege
Denial of Service
Security Restriction Bypass
CVE-2025-29824 is being exploited in the wild. This vulnerability allows local attackers to gain SYSTEM privileges on the device/system.
Microsoft OfficeMedium Risk Medium RiskElevation of Privilege
Remote Code Execution
Security Restriction Bypass
 
System CenterMedium Risk Medium RiskElevation of Privilege 
BrowserMedium Risk Medium RiskSpoofing
Remote Code Execution
 
Microsoft DynamicsMedium Risk Medium RiskInformation Disclosure 
AzureMedium Risk Medium RiskInformation Disclosure
Elevation of Privilege
 
Developer ToolsMedium Risk Medium RiskElevation of Privilege
Denial of Service
 
SQL ServerMedium Risk Medium RiskElevation of Privilege 
AppsMedium Risk Medium RiskInformation Disclosure 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 10

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Elevation of Privilege
  • Remote Code Execution
  • Denial of Service
  • Security Restriction Bypass
  • Spoofing
  • Information Disclosure

System / Technologies affected

  • Windows
  • Extended Security Updates (ESU)
  • Microsoft Office
  • System Center
  • Browser
  • Microsoft Dynamics
  • Azure
  • Developer Tools
  • SQL Server
  • Apps

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

思科產品多個漏洞

思科產品多個漏洞 發佈日期: 2025年05月09日 風險: 中度風險 類型: 保安軟件及應用設備 - 保安軟件及應用設備 於思科產品發現多個漏...