Vulnerability
The latest Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.
Excel zero-day CVE-2025-21387 with 9.8 CVSS exploited in attacks.
CVE-2025-21387: Critical RCE Vulnerability in Microsoft Excel Microsoft has issued an urgent security advisory regarding CVE-2025-21387, a critical Remote Code Execution (RCE) vulnerability affecting...
Excel Zero-Day CVE-2025-21386 Lets Attackers Hijack Systems via Malicious Spreadsheets
CVE-2025-21386: Microsoft Excel Remote Code Execution Vulnerability Microsoft has disclosed a critical security vulnerability (CVE-2025-21386) affecting Excel that could allow remote code execution...
CVE-2025-21359: Critical Windows Kernel Security Vulnerability Explained and Mitigation Steps
Microsoft has issued a critical security alert regarding CVE-2025-21359, a newly discovered vulnerability in the Windows kernel that could allow attackers to execute arbitrary code with system-level...
Patch now: CVE-2025-21201 lets attackers hijack Windows Telephony Server remotely.
CVE-2025-21201: Remote Code Execution Risk in Windows Telephony Server Microsoft has disclosed a critical vulnerability (CVE-2025-21201) affecting Windows Telephony Server, which could allow...
Outlook spoofing flaw CVE-2025-21259 demands immediate patch and config fixes
Microsoft Outlook Vulnerability CVE-2025-21259: Spoofing Risks and Mitigation A newly discovered vulnerability in Microsoft Outlook, tracked as CVE-2025-21259, has raised significant security...
VS Code 1.89.2 patches critical CVE-2025-24039 EoP flaw.
CVE-2025-24039: Elevation of Privilege Threat in Visual Studio Code Microsoft's Visual Studio Code (VS Code), the popular open-source code editor, has been identified with a critical elevation of...
Critical Windows Digest Auth Bug Allows Remote Code Execution with System Privileges
A newly discovered critical vulnerability in Microsoft's implementation of Digest Authentication could allow attackers to execute arbitrary code remotely on affected systems. CVE-2025-21369, rated...
Patch Now: Critical CVE-2025-21206 Bug in Visual Studio Installer Enables RCE
CVE-2025-21206: Critical Visual Studio Installer Vulnerability Explained A newly discovered vulnerability in the Visual Studio Installer, tracked as CVE-2025-21206, has been classified as critical by...
CVE-2023-24932: Critical Secure Boot Vulnerability in Windows 11 - What You Need to Know
Microsoft has disclosed a critical Secure Boot vulnerability (CVE-2023-24932) affecting Windows 11 and Windows Server systems that could allow attackers to bypass security features during the boot...
Microsoft Expands Copilot Bug Bounty Program to Strengthen AI Security
Microsoft has announced a significant expansion of its Copilot Bug Bounty Program, offering increased rewards for security researchers who identify vulnerabilities in its AI-powered assistant. This...
CVE-2025-21253: Critical Spoofing Vulnerability in Microsoft Edge Puts Mobile Users at Risk
CVE-2025-21253: Security Flaw in Microsoft Edge Affects Mobile Users A newly discovered vulnerability in Microsoft Edge, tracked as CVE-2025-21253, has raised significant concerns among cybersecurity...
CVE-2025-21177: Critical SSRF Vulnerability in Microsoft Dynamics 365 Explained
CVE-2025-21177: Understanding the Dynamics 365 Server-Side Request Forgery Vulnerability Microsoft Dynamics 365 administrators are facing a new security challenge with the discovery of...