Network Security
The latest Network Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
MSDTC Integer Overflow Opens Door to Memory Leak—Patch Now, Microsoft Warns
Microsoft has quietly disclosed a new integer overflow vulnerability in the Windows Distributed Transaction Coordinator (MSDTC) that lets attackers siphon sensitive memory contents over the network....
Microsoft Discloses Critical RRAS Heap Overflow (CVE-2025-50164) — Patch Now to Block Remote Code Execution
Microsoft has issued a high-severity security advisory for a heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) that could allow unauthenticated attackers to execute...
RRAS Heap Overflow Crisis: Two High-Severity Flaws Hit Windows Server, PoCs Expected Soon
A pair of heap-based buffer overflow vulnerabilities in Microsoft’s Routing and Remote Access Service (RRAS) are forcing enterprise administrators into emergency patch mode. CVE-2025-33064 and...
Critical RRAS Heap Overflow Exposes Windows Servers to Unauthenticated Remote Code Execution
Microsoft has issued urgent patches for a heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) that allows remote, unauthenticated attackers to execute arbitrary code on...
Microsoft Patches Critical RRAS Heap Overflow CVE-2025-50160 That Exposes VPN Servers to Remote Takeover
Microsoft has released a patch for a critical heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) tracked as CVE-2025-50160, which allows attackers to remotely execute code...
Microsoft Patches Windows RRAS Bug That Leaks Confidential Data Over the Network
Microsoft has released a security update to address a serious information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS) that could allow attackers to extract...
Windows File Explorer NTLM Leak: CVE-2025-50154 Exposes Credentials in Stealthy Attacks
A single unassuming ZIP archive can now become a weapon to steal Windows credentials, thanks to a newly patched flaw in Windows File Explorer. Microsoft's March 11, 2025 Patch Tuesday update fixed a...
Patch Now: Windows RRAS Heap Overflow CVE-2025-49657 Opens Door to Unauthenticated RCE
Microsoft’s July 2025 Patch Tuesday delivered a critical update for a heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS), tracked as CVE-2025-49657. A remote,...
Azure VMs Hit by CVE-2025-53781: Information Disclosure Risk Prompts Urgent Patching
Microsoft has published a security advisory for CVE-2025-53781, warning Azure Virtual Machines users of a critical information disclosure vulnerability that could allow attackers to siphon sensitive...
Microsoft Fixes SQL Server Flaw That Allows Privilege Escalation via SQL Injection
Microsoft’s July 2025 Patch Tuesday release includes a fix for a high-severity SQL injection vulnerability in SQL Server that enables authenticated attackers to escalate privileges and seize...
Azure’s Basic IP Retirement Forces Sophos Firewall to Standard SKU: Deployment Guide & Best Practices
As of September 30, 2025, Microsoft officially retired Basic SKU public IP addresses, and for anyone deploying Sophos Firewall in Azure, the message is clear: you must use Standard SKU public IPs for...
Barracuda SecureEdge Targets Windows SMBs with Azure-Backed SASE and Zero-Trust Access
Barracuda Networks is making a determined push into the SASE market with a platform explicitly tailored for small and mid-sized businesses that live inside the Microsoft ecosystem. SecureEdge, the...