Live
Critical Windows LSASS Bug Exposes Domain Controllers to Authentication DoS Attacks·MSFT +0.1%Critical Windows Graphics Race Condition (CVE-2025-53807) Hands Out SYSTEM Access—Urgent Patch Guide·NVDA +3.0%CVE-2025-53806: Microsoft Patches RRAS Memory Disclosure Flaw in Windows VPN Servers·GOOGL +1.2%Microsoft Patches Windows Imaging Component Flaw That Could Leak Sensitive Data Through Crafted Images·AMZN +2.9%CVE-2025-49692: Azure Connected Machine Agent Vulnerability Demands Immediate Patching·MSFT +0.1%SQL Server Vulnerability CVE-2025-47997: Patch Now to Block Memory Disclosure Attacks·NVDA +3.0%Microsoft AutoUpdate Vulnerability Lets Attackers Escalate to Root on macOS via Symlink Tricks·GOOGL +1.2%Azure Arc’s Critical Local Privilege Flaw Fixed, But CVE Muddle May Leave Systems Exposed·AMZN +2.9%Critical Windows LSASS Bug Exposes Domain Controllers to Authentication DoS Attacks·MSFT +0.1%Critical Windows Graphics Race Condition (CVE-2025-53807) Hands Out SYSTEM Access—Urgent Patch Guide·NVDA +3.0%CVE-2025-53806: Microsoft Patches RRAS Memory Disclosure Flaw in Windows VPN Servers·GOOGL +1.2%Microsoft Patches Windows Imaging Component Flaw That Could Leak Sensitive Data Through Crafted Images·AMZN +2.9%CVE-2025-49692: Azure Connected Machine Agent Vulnerability Demands Immediate Patching·MSFT +0.1%SQL Server Vulnerability CVE-2025-47997: Patch Now to Block Memory Disclosure Attacks·NVDA +3.0%Microsoft AutoUpdate Vulnerability Lets Attackers Escalate to Root on macOS via Symlink Tricks·GOOGL +1.2%Azure Arc’s Critical Local Privilege Flaw Fixed, But CVE Muddle May Leave Systems Exposed·AMZN +2.9%

Security Advisory

The latest Security Advisory coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 7:57 AM
Latest Most Read Breaking
Sort
Authentication · Cldap

Critical Windows LSASS Bug Exposes Domain Controllers to Authentication DoS Attacks

Microsoft’s latest security advisory for CVE-2025-53809 details a network-exploitable denial-of-service flaw in the Windows Local Security Authority Subsystem Service, the bedrock of authentication...

Advertisement
Azcmagent · Azure Arc

CVE-2025-49692: Azure Connected Machine Agent Vulnerability Demands Immediate Patching

Microsoft has released a security update to address a critical elevation-of-privilege vulnerability (CVE-2025-49692) in the Azure Connected Machine agent, the software component that enables Azure...

SE Security Desk·44w ago
Credential Theft · Cu Update

SQL Server Vulnerability CVE-2025-47997: Patch Now to Block Memory Disclosure Attacks

Microsoft has released patches for a critical information-disclosure vulnerability in SQL Server that could allow an authenticated attacker to read sensitive memory contents over the network. Tracked...

SE Security Desk·44w ago
Cve-2025-55317 · Cybersecurity

Microsoft AutoUpdate Vulnerability Lets Attackers Escalate to Root on macOS via Symlink Tricks

Microsoft has disclosed a fresh local elevation-of-privilege vulnerability in its Microsoft AutoUpdate (MAU) agent that allows an attacker with an existing foothold on a macOS machine to escalate to...

SE Security Desk·44w ago
Azure Arc · Command Injection

Azure Arc’s Critical Local Privilege Flaw Fixed, But CVE Muddle May Leave Systems Exposed

Microsoft has patched a high-severity local elevation-of-privilege vulnerability in Azure Arc, but confusion over the associated CVE identifier could cause dangerous patching delays, security...

SE Security Desk·44w ago
Cve-2025-54907 · Detection

Microsoft Flags Critical Visio Heap Overflow – Urgent Patch for CVE-2025-54907 Underway

Microsoft has confirmed a dangerous heap-based buffer overflow in Microsoft Office Visio that lets attackers execute malicious code simply by convincing a user to open a rigged diagram file. The...

SE Security Desk·44w ago
Asr · Cve-2025-54899

CVE-2025-54899 Exposes Excel to Code Execution Attacks: Patch Deployed for Critical Memory-Safety Bug

Microsoft has released a security update to patch CVE-2025-54899, a memory-safety vulnerability in Excel that can allow attackers to execute arbitrary code on a victim's machine when a malicious...

SE Security Desk·44w ago
Cve · Cve-2025-54894

How to Prioritize Patching with Microsoft’s Confidence Metric: Lessons from CVE-2025-54894

A single metric buried inside every Microsoft Security Response Center (MSRC) advisory could be the difference between a patching strategy that works and one that wastes precious time. Security teams...

SE Security Desk·44w ago
Buffer Overflow · Cve-2025-49657

Critical Windows Server VPN Gateway Flaw Allows Unauthenticated Remote Code Execution — Patch RRAS Now

Microsoft is urging organizations to immediately patch a series of critical heap-based buffer overflow vulnerabilities in Windows Routing and Remote Access Service (RRAS) that can be exploited...

SE Security Desk·44w ago