Edr
The latest Edr coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Patches Windows Installer Flaw Allowing SYSTEM-Level Elevation
Microsoft has fixed a high-impact elevation-of-privilege vulnerability in Windows Installer that could allow a locally authorized attacker to gain SYSTEM-level privileges on unpatched systems....
MSDTC Integer Overflow Opens Door to Memory Leak—Patch Now, Microsoft Warns
Microsoft has quietly disclosed a new integer overflow vulnerability in the Windows Distributed Transaction Coordinator (MSDTC) that lets attackers siphon sensitive memory contents over the network....
Microsoft Patches Critical RRAS Heap Overflow CVE-2025-50160 That Exposes VPN Servers to Remote Takeover
Microsoft has released a patch for a critical heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) tracked as CVE-2025-50160, which allows attackers to remotely execute code...
Windows File Explorer NTLM Leak: CVE-2025-50154 Exposes Credentials in Stealthy Attacks
A single unassuming ZIP archive can now become a weapon to steal Windows credentials, thanks to a newly patched flaw in Windows File Explorer. Microsoft's March 11, 2025 Patch Tuesday update fixed a...
Windows AFD.sys Hit Again: Race Condition CVE-2025-49762 Opens Door to SYSTEM Access
Microsoft has disclosed yet another high-severity vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), this time a race condition tracked as CVE-2025-49762 that allows a...
Microsoft Discloses Critical PowerPoint Use-After-Free Flaw, CVE-2025-53761, Enabling Local Code Execution
Microsoft has issued a security advisory for a new use-after-free vulnerability in PowerPoint, tracked as CVE-2025-53761, that allows an unauthorized attacker to execute code locally. The flaw, which...
Microsoft Warns of Excel RCE Flaw CVE-2025-53759, Workarounds Provided
A newly disclosed vulnerability in Microsoft Excel, tracked as CVE-2025-53759, allows attackers to execute arbitrary code on a victim’s machine by tricking them into opening a specially crafted...
SharePoint 'ToolShell' Zero-Day Exploited: Critical RCE Patched Amid Active Attacks
Microsoft has released an emergency security update to patch a critical remote code execution (RCE) vulnerability in SharePoint Server that has been actively exploited in the wild. Tracked as...
CVE-2025-53741: Microsoft Issues Emergency Excel Patch to Stop Remote Code Execution via Heap Overflow
Microsoft has disclosed a critical heap-based buffer overflow vulnerability in Excel, tracked as CVE-2025-53741, that can give attackers the ability to remotely execute code on a vulnerable machine...
Visio Under Fire: Microsoft Releases Patch for Use-After-Free Vulnerability CVE-2025-53730
Microsoft has disclosed a new use-after-free vulnerability in Visio, tracked as CVE-2025-53730, that allows an attacker to execute arbitrary code locally when a user opens a maliciously crafted...
Microsoft Patches Zero-Click LDAPNightmare Exploits That Crash Domain Controllers (CVE-2024-49112/49113)
SafeBreach Labs researchers dropped a bombshell at DEF CON with a zero-click exploit chain that weaponizes Windows LDAP protocol handling to crash Domain Controllers or, in the worst case, execute...
Huntress and Microsoft Partner to Bolster SMB Cybersecurity
Huntress and Microsoft have announced a strategic partnership designed to significantly enhance cybersecurity defenses for small and medium-sized businesses (SMBs). This collaboration addresses the...