Edr
The latest Edr coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2025-53734: Patch Visio Use-After-Free RCE Before Attackers Exploit Document Flaw
Microsoft has released a security update for a use-after-free vulnerability in Microsoft Visio that allows attackers to execute arbitrary code simply by having a victim open a maliciously crafted...
Microsoft Office Buffer Over-Read Bugs Strike Word and Excel: What Enterprises Must Patch Now
Microsoft has rolled out crucial patches for two high-severity buffer over-read vulnerabilities in Microsoft Word and Excel, both enabling local attackers to extract sensitive memory contents. The...
Microsoft Patches Critical Excel Use-After-Free Flaw (CVE-2025-53735) That Executes Code via Malicious Spreadsheets
Microsoft has confirmed a serious use-after-free vulnerability in Microsoft Excel, tracked as CVE-2025-53735, that can allow attackers to execute arbitrary code on a victim’s machine simply by...
CVE-2025-53733: Patch Microsoft Word RCE Now – Numeric Conversion Flaw Exploited
Microsoft has published advisory CVE-2025-53733, warning of a remote code execution vulnerability in Microsoft Word that stems from an incorrect conversion between numeric types during document...
Urgent Patch for CVE-2025-53732: Microsoft Office Heap Overflow Enables Remote Code Execution via Malicious Documents
Microsoft has released a critical security update addressing CVE-2025-53732, a heap-based buffer overflow vulnerability in Microsoft Office that allows remote code execution (RCE) when a user opens a...
Critical Office Use-After-Free Bug (CVE-2025-53731) Lets Attackers Execute Code—Patch Now, Microsoft Warns
Microsoft’s Security Response Center has published a new advisory, CVE-2025-53731, confirming a critical use-after-free vulnerability in Microsoft Office that can let attackers execute arbitrary...
Microsoft Warns of CVE-2025-53726: Windows Push Notification Flaw Grants SYSTEM Access to Local Attackers
Microsoft has published a high-priority security advisory for CVE-2025-53726, a type-confusion vulnerability in the Windows Push Notifications component that allows an authenticated local attacker to...
Patch Now: Windows CDPSvc Use-After-Free Bug (CVE-2025-48000) Grants Attackers SYSTEM Privileges
A use-after-free vulnerability in the Windows Connected Devices Platform Service (CDPSvc) lets any local authenticated attacker gain full SYSTEM control—and the fix landed in Microsoft’s July...
Critical Windows AFD.sys Kernel Flaw (CVE-2025-53718) Exposes Systems to Local Privilege Escalation
Microsoft has issued a high-priority security advisory for a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys). Tracked as CVE-2025-53718, the flaw allows a...
CVE-2025-33057: Microsoft Patches LSASS Null Pointer DoS That Can Crash Domain Controllers
Microsoft has released a security update for a vulnerability that allows an attacker with network access to crash the Local Security Authority Subsystem Service (LSASS) and trigger a...
KB5064010 Hotpatch: Windows 11 Enterprise LTSC 2024 Now Patched Without Reboots
Microsoft has released KB5064010, a hotpatch for Windows 11 Enterprise LTSC 2024 that delivers critical security fixes without requiring a system restart. The update, issued on August 12, 2025,...
Microsoft’s June Patch Fixes Storport Driver Flaw That Could Expose Kernel Memory and Defeat ASLR
Microsoft’s June 2025 Patch Tuesday quietly resolved a local information-disclosure vulnerability in the Windows Storage Port Driver (storport.sys) that could allow authenticated attackers to read...