Msrc
The latest Msrc coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Drops Limited Details on CVE-2025-25006 Exchange Spoofing Bug—Here’s How to Protect Your Network
Microsoft has posted a new Exchange Server vulnerability, CVE-2025-25006, with a terse description that points to a spoofing weakness in how the mail server handles special header elements. The...
CVE-2025-25005: The Windows Vulnerability Shrouded in Uncertainty and What Admins Must Do Now
The discovery of a new Windows vulnerability always triggers a scramble for details, but CVE-2025-25005 has presented an unusual challenge: the Microsoft Security Response Center (MSRC) advisory...
Microsoft Discloses Critical PowerPoint Use-After-Free Flaw, CVE-2025-53761, Enabling Local Code Execution
Microsoft has issued a security advisory for a new use-after-free vulnerability in PowerPoint, tracked as CVE-2025-53761, that allows an unauthorized attacker to execute code locally. The flaw, which...
Microsoft Warns of Excel RCE Flaw CVE-2025-53759, Workarounds Provided
A newly disclosed vulnerability in Microsoft Excel, tracked as CVE-2025-53759, allows attackers to execute arbitrary code on a victim’s machine by tricking them into opening a specially crafted...
SharePoint 'ToolShell' Zero-Day Exploited: Critical RCE Patched Amid Active Attacks
Microsoft has released an emergency security update to patch a critical remote code execution (RCE) vulnerability in SharePoint Server that has been actively exploited in the wild. Tracked as...
Visio Under Fire: Microsoft Releases Patch for Use-After-Free Vulnerability CVE-2025-53730
Microsoft has disclosed a new use-after-free vulnerability in Visio, tracked as CVE-2025-53730, that allows an attacker to execute arbitrary code locally when a user opens a maliciously crafted...
CVE-2025-33051: Exchange Server Leak Demands Urgent Patching and Credential Rotation
Microsoft’s June 2025 Patch Tuesday has surfaced CVE-2025-33051, an information disclosure vulnerability in Exchange Server that demands immediate attention from every organization running...
Immediate Patch Needed: CVE-2025-49758 SQL Injection Allows SQL Server Privilege Escalation
Microsoft has released critical security updates for all supported versions of SQL Server to address CVE-2025-49758, a severe SQL injection vulnerability that could allow an authenticated attacker to...
Critical Microsoft Entra ID SAML Exploit Enables Global Administrator Privilege Escalation
Security researchers have sounded the alarm over a newly discovered exploit chain in Microsoft Entra ID, a service formerly known as Azure Active Directory, that enables attackers to seize Global...
CVE-2024-36350: Critical AMD Processor Vulnerability Impacting Windows Systems
The revelation of CVE-2024-36350, a critical hardware vulnerability affecting the store queue of various AMD processors, marks a significant moment for both security professionals and everyday users...
Microsoft’s Security Researchers Recognition 2025: Elevating Global Cyber Defense through Collaboration
Every year, as the digital battlefield expands and cyber threats grow more relentless, the unsung heroes of the technological world—security researchers—step up to meet these challenges head-on....
July 2025 Patch Tuesday: 137 fixes, 41 critical RCE flaws, and SQL Server zero-day
The July 2025 Patch Tuesday brought significant security updates from Microsoft, addressing a total of 137 vulnerabilities across various Windows versions and applications. This comprehensive update...