Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
CSC zero-day CVE-2025-60705 gives SYSTEM access on Windows 10, 11, and Server.
Microsoft has disclosed a critical elevation of privilege vulnerability in the Windows Client-Side Caching (CSC) service, designated as CVE-2025-60705, affecting the Offline Files functionality that...
CVE-2025-62210: Critical XSS Spoofing Vulnerability in Dynamics 365 Field Service
Microsoft has issued an urgent security advisory for CVE-2025-62210, a high-severity cross-site scripting (XSS) and spoofing vulnerability affecting Dynamics 365 Field Service version 8.7. This...
CVE-2025-59510: Critical Windows RRAS Vulnerability Requires Immediate Patching
Microsoft has disclosed a significant security vulnerability in Windows Routing and Remote Access Service (RRAS) that could allow local attackers to cause denial-of-service conditions on affected...
CVE-2025-30398: Critical Nuance PowerScribe 360 Vulnerability Exposes Patient Data
A critical security vulnerability in Nuance PowerScribe 360, identified as CVE-2025-30398, has exposed healthcare organizations to significant patient data breaches through unauthenticated API...
CVE-2025-62453: Microsoft AI tools bypass flaw demands immediate patch
Microsoft has disclosed a significant security vulnerability affecting GitHub Copilot and Visual Studio Code that could allow attackers to bypass security protections through improper validation of...
CVE-2025-60721: Critical Windows Administrator Protection Vulnerability Explained
Microsoft has disclosed a significant security vulnerability in its newly introduced Windows Administrator Protection feature, designated as CVE-2025-60721, which carries a high-severity rating and...
CVE-2025-62214: Visual Studio AI Prompt Bug Enables Code Execution
Microsoft has issued a critical security advisory for Visual Studio developers, warning of CVE-2025-62214, a sophisticated AI prompt injection vulnerability that could lead to remote code execution....
CVE-2025-62215: Critical Windows Kernel Privilege Escalation Vulnerability Patched
Microsoft has released an urgent security update addressing CVE-2025-62215, a critical Windows kernel vulnerability that enables local privilege escalation attacks. This race condition flaw in the...
CVE-2025-62213: Critical Windows afd.sys Vulnerability Requires Immediate Patching
Microsoft has issued a critical security alert for CVE-2025-62213, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) that enables local privilege...