Security Patch
The latest Security Patch coverage — news, analysis, and updates from the WindowsNews.AI desk.
Windows camsvc Race Condition Exploited for SYSTEM Access: Urgent Patch Deployed
A race condition in the Windows Capability Access Management Service (camsvc) allows a local attacker to escalate privileges to SYSTEM, Microsoft confirmed in a July 2025 security advisory. The...
Microsoft Patches Windows Kernel Memory Leak (CVE-2025-53803) That Facilitates Privilege Escalation
Microsoft has released a security update to close a Windows kernel memory disclosure vulnerability that hands attackers a powerful reconnaissance tool for crafting more reliable exploits. Tracked as...
CVE-2025-54902: Excel Out-of-Bounds Read Flaw Could Let Attackers Seize PCs—Mac Updates Still Missing
Microsoft has released a security update for a critical out-of-bounds read vulnerability in Excel that could allow remote code execution—but the patch is not yet available for Mac users. Tracked as...
Critical Windows Server VPN Gateway Flaw Allows Unauthenticated Remote Code Execution — Patch RRAS Now
Microsoft is urging organizations to immediately patch a series of critical heap-based buffer overflow vulnerabilities in Windows Routing and Remote Access Service (RRAS) that can be exploited...
CVE-2025-54099: Windows Winsock Driver Stack Overflow Threatens SYSTEM Access
A stack-based buffer overflow in the Windows Ancillary Function Driver for WinSock (afd.sys) can be exploited by local attackers to seize SYSTEM privileges, Microsoft disclosed in a security...
Microsoft Patches CVE-2025-53798: RRAS Memory Leak Exposes VPN Gateways to Data Theft
Microsoft has released a vendor update to patch CVE-2025-53798, an information-disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS) that allows an attacker to read...
Rockwell Automation FactoryTalk Activation Manager Vulnerability Allows Remote Decryption and Hijacking
Rockwell Automation has issued an urgent security advisory after a critical cryptographic weakness was discovered in its FactoryTalk Activation Manager, a licensing tool deployed across thousands of...
Edge 140 Brings On-Device AI Scareware Blocker and Critical Patch for CVE-2025-53791
Microsoft has equipped Edge 140 with an on-device AI scareware blocker that locally detects and neutralizes browser-based tech support scams, and simultaneously patches a security bypass flaw tracked...
Android's Chrome Toolbar Trickery Fixed: CVE-2025-9865 Patched in Chrome 140, Edge Secured
Google has released a patch for a UI spoofing vulnerability in Chrome that could allow attackers on Android to trick users into believing they are visiting a trusted website. The fix, tracked as...
Microsoft Confirms Windows August 2025 Updates Break Silent MSI Repairs, Trigger UAC Prompts
Microsoft has acknowledged a compatibility regression introduced by the August 12, 2025 cumulative security updates for Windows, which causes unexpected User Account Control (UAC) elevation prompts...
Windows 10’s October 2025 End Sparks Heated Debate: Should Microsoft Open Legacy Drivers?
With the clock ticking down to October 14, 2025, millions of Windows 10 PCs are facing an unprecedented crossroads: upgrade to Windows 11, pay for a temporary safety net, or keep running an...
Delta Electronics Patches XXE Bug in EIP Builder, CISA Warns Critical Manufacturing Operators to Upgrade Now
A newly disclosed vulnerability in Delta Electronics’ EIP Builder engineering tool can allow attackers to exfiltrate sensitive files from industrial engineering workstations, and the U.S....