Live
Azure Virtual Desktop flaw CVE-2025-21416 grants privilege escalation via network, patch now.·MSFT +0.1%CISA adds three actively exploited critical CVEs to KEV catalog, urges immediate patching.·NVDA +0.2%Windows 11's inetpub Folder: A Double-Edged Sword of Security and Vulnerability Post-April 2025 Update·GOOGL +0.5%Unveiling the Role of the inetpub Folder in Windows 11 24H2 Update: A Critical Security Enhancement·AMZN -1.2%CVE-2025-24054: Exploitation of Windows NTLM Hash Leak Vulnerability Highlights Urgent Need for Patch Management·MSFT +0.1%Understanding Microsoft's April 2025 Windows 11 Update: The 'inetpub' Folder and Its Crucial Security Role·NVDA +0.2%Microsoft’s April 2025 Windows 11 update creates empty inetpub folder to block CVE-2025-21204 symlink attacks, but introduces new DoS risks.·GOOGL +0.5%KB5055523 Ends RDP Freeze Nightmare on Windows Server 2025 and 11 24H2·AMZN -1.2%Azure Virtual Desktop flaw CVE-2025-21416 grants privilege escalation via network, patch now.·MSFT +0.1%CISA adds three actively exploited critical CVEs to KEV catalog, urges immediate patching.·NVDA +0.2%Windows 11's inetpub Folder: A Double-Edged Sword of Security and Vulnerability Post-April 2025 Update·GOOGL +0.5%Unveiling the Role of the inetpub Folder in Windows 11 24H2 Update: A Critical Security Enhancement·AMZN -1.2%CVE-2025-24054: Exploitation of Windows NTLM Hash Leak Vulnerability Highlights Urgent Need for Patch Management·MSFT +0.1%Understanding Microsoft's April 2025 Windows 11 Update: The 'inetpub' Folder and Its Crucial Security Role·NVDA +0.2%Microsoft’s April 2025 Windows 11 update creates empty inetpub folder to block CVE-2025-21204 symlink attacks, but introduces new DoS risks.·GOOGL +0.5%KB5055523 Ends RDP Freeze Nightmare on Windows Server 2025 and 11 24H2·AMZN -1.2%

Security Patch

The latest Security Patch coverage — news, analysis, and updates from the WindowsNews.AI desk.

11 stories in view AI assisted desk updated 1:31 AM
Latest Most Read Breaking
Sort
Access Control · Authorization Flaw

Azure Virtual Desktop flaw CVE-2025-21416 grants privilege escalation via network, patch now.

Overview of CVE-2025-21416 A critical security vulnerability, identified as CVE-2025-21416, has been disclosed in Azure Virtual Desktop (AVD), Microsoft's cloud-based remote desktop service. This...

Advertisement
Advanced Persistent Threats · Apt28

CVE-2025-24054: Exploitation of Windows NTLM Hash Leak Vulnerability Highlights Urgent Need for Patch Management

Overview In March 2025, Microsoft addressed a critical security vulnerability, CVE-2025-24054, within its Windows operating system. This flaw, involving the NT LAN Manager (NTLM) authentication...

SE Security Desk·59w ago
Cve-2025-21204 · Cybersecurity

Understanding Microsoft's April 2025 Windows 11 Update: The 'inetpub' Folder and Its Crucial Security Role

Introduction In April 2025, Microsoft released a cumulative update for Windows 11 24H2, identified as KB5055523, which introduced an unexpected yet significant change: the creation of an empty...

SE Security Desk·59w ago
Cve-2025-21204 · Cybersecurity

Microsoft’s April 2025 Windows 11 update creates empty inetpub folder to block CVE-2025-21204 symlink attacks, but introduces new DoS risks.

Introduction Microsoft’s April 2025 cumulative update for Windows 11 introduced a subtle yet critical change that drew significant attention: the automatic creation of an empty "inetpub" folder at...

SE Security Desk·59w ago
Bug Fixes · Enterprise It

KB5055523 Ends RDP Freeze Nightmare on Windows Server 2025 and 11 24H2

Overview Microsoft has addressed a critical issue affecting Remote Desktop Protocol (RDP) sessions on Windows Server 2025 and Windows 11 24H2. Users experienced session freezes shortly after...

SE Security Desk·59w ago
Cve-2025-21204 · Directory Hijacking

Windows April 2025 Update Exposes Critical IIS Vulnerability (CVE-2025-21204)

The April 2025 update for Windows 10 and 11 systems has unexpectedly surfaced dormant IIS components, thrusting the typically hidden inetpub directory into the spotlight and exposing attack vectors...

SE Security Desk·59w ago
Active Directory · Ad Core Services

Windows Server 2025 DCs load wrong firewall profile after reboot, Microsoft offers workaround

Overview Microsoft's latest server operating system, Windows Server 2025, has encountered a significant issue affecting domain controllers (DCs). After a system restart, these servers may fail to...

SE Security Desk·59w ago
Advanced Persistent Threats · Apple Zero-day

Exploitation of Windows NTLM Vulnerability CVE-2025-24054 in Widespread Cyberattacks

Overview In March 2025, Microsoft released a security update addressing a critical vulnerability in the Windows NT LAN Manager (NTLM) authentication protocol, identified as CVE-2025-24054. Despite...

SE Security Desk·59w ago