Urgent: Microsoft Rushes to Fix 126 Flaws as Hackers Actively Exploit Critical Windows Vulnerability


# Microsoft Releases Patches for 126 Security Flaws, One Actively Exploited

Microsoft has issued security updates addressing 126 vulnerabilities across its software products, including one actively exploited in the wild. The patches include 11 Critical, 112 Important, and 2 Low severity flaws, spanning privilege escalation (49), remote code execution (34), information disclosure (16), and denial-of-service (14) vulnerabilities.

## Active Exploitation Discovered

The actively exploited vulnerability (CVE-2025-29824) affects the Windows Common Log File System Driver and allows attackers to elevate privileges locally through a use-after-free vulnerability. This marks the sixth such vulnerability in this component exploited since 2022.

“Elevation of privilege flaws in CLFS have become especially popular among ransomware operators over the years,” noted Satnam Narang from Tenable. The vulnerability enables attackers to escalate to SYSTEM-level privileges, potentially installing malware, modifying system settings, and accessing sensitive data.

Concerningly, no patch is currently available for Windows 10 32-bit or 64-bit systems. The U.S. Cybersecurity and Infrastructure Security Agency has added this vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply fixes by April 29, 2025.

## Other Critical Vulnerabilities

Notable fixes include:
– Windows Kerberos security feature bypass (CVE-2025-29809)
– Remote code execution flaws in Windows Remote Desktop Services and LDAP
– Multiple critical remote code execution vulnerabilities in Microsoft Office and Excel
– Critical flaws in Windows TCP/IP and Windows Hyper-V

## Industry-Wide Security Updates

Other major technology vendors releasing security patches recently include Adobe, AWS, Apple, Cisco, Dell, Google, IBM, Mozilla, SAP, and Zoom, highlighting the ongoing industry-wide effort to address cybersecurity vulnerabilities.

Share This Article