Threat Hunting
The latest Threat Hunting coverage — news, analysis, and updates from the WindowsNews.AI desk.
Critical Office Use-After-Free Bug (CVE-2025-53731) Lets Attackers Execute Code—Patch Now, Microsoft Warns
Microsoft’s Security Response Center has published a new advisory, CVE-2025-53731, confirming a critical use-after-free vulnerability in Microsoft Office that can let attackers execute arbitrary...
Uninitialized Resource Bug in Windows RRAS Could Expose Corporate VPN Secrets, Microsoft Urges Patch
Microsoft has disclosed a new information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS), tracked as CVE-2025-53719, that could allow an authenticated attacker to...
Critical MSMQ Type‑Confusion Bug Allows Remote Code Execution, Microsoft Urges Immediate Patching
Microsoft has released a security update addressing CVE-2025-53145, a type confusion vulnerability in Windows Message Queuing (MSMQ) that could allow an authenticated attacker to remotely execute...
CVE-2025-53141: Microsoft Fixes AFD.sys Null Pointer Bug Enabling Local SYSTEM Escalation
{ "title": "CVE-2025-53141: Microsoft Fixes AFD.sys Null Pointer Bug Enabling Local SYSTEM Escalation", "content": "Microsoft has released a security patch for a high‑severity privilege...
CVE-2025-53137: Microsoft’s AFD.sys Patch Stops Local Attackers from Hijacking SYSTEM
A use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), tracked as CVE-2025-53137, hands any local attacker with a toehold on a machine a direct path to SYSTEM...
Microsoft Patches Critical DirectX Kernel Race Condition Exploit (CVE-2025-53135) Threatening Windows Systems
Microsoft has released a security update for a local privilege escalation vulnerability in the Windows DirectX Graphics Kernel, tracked as CVE-2025-53135. The flaw, residing in the dxgkrnl driver,...
New Win32k GRFX Race Condition Lets Attackers Hijack Windows Systems — Patch Now
A race-condition vulnerability in the Windows Win32k GRFX kernel component, assigned CVE-2025-53132, enables local attackers to escalate privileges to SYSTEM and take full control of an unpatched...
CVE-2025-50171: Critical RDP Flaw Allows Spoofing—Patch Now, Warns Microsoft
Microsoft has published details of a new vulnerability in its Remote Desktop Services that could allow an unauthenticated attacker to perform spoofing attacks over a network. Tracked as...
Immediate Patch Urged for Windows Cloud Files Driver Flaw (CVE-2025-50170) That Escalates to SYSTEM
Microsoft has released a security advisory for CVE-2025-50170, a local elevation-of-privilege vulnerability in the Windows Cloud Files Mini Filter Driver (cldflt.sys) that could allow an attacker...
Microsoft Patches Windows RRAS Bug That Leaks Confidential Data Over the Network
Microsoft has released a security update to address a serious information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS) that could allow attackers to extract...
Windows AFD.sys Hit Again: Race Condition CVE-2025-49762 Opens Door to SYSTEM Access
Microsoft has disclosed yet another high-severity vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), this time a race condition tracked as CVE-2025-49762 that allows a...
Microsoft Patches Critical RCE Flaw in IIS Web Deploy – CVE-2025-53772 Threatens Exposed Servers
Microsoft has issued a high-priority security advisory for a deserialization vulnerability in its Web Deploy tool that could give authenticated attackers the ability to execute arbitrary code on...