Vulnerability
The latest Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.
Windows Kernel Zero-Day CVE-2025-21321: Patch All Versions Now
Microsoft has disclosed a critical vulnerability (CVE-2025-21321) in the Windows kernel that could allow attackers to execute arbitrary code with system-level privileges. This zero-day vulnerability...
KB5050009 and KB5050021 patch zero-day exploits but break USB audio and webcams
Overview of January 2025 Patch Tuesday Updates for Windows 11 Microsoft's January 2025 Patch Tuesday has delivered two crucial cumulative updates for Windows 11 users: KB5050009 for version 24H2 and...
CVE-2025-21318: Critical Windows Kernel Vulnerability Threatens Data Security
CVE-2025-21318: New Windows Kernel Vulnerability Exposes Sensitive Data A newly discovered vulnerability in the Windows kernel, tracked as CVE-2025-21318, has raised significant concerns among...
CVE-2025-21314: Critical SmartScreen Spoofing Vulnerability Threatens Windows Security
CVE-2025-21314: SmartScreen Spoofing Vulnerability in Windows Exposed Microsoft Windows faces a significant security threat with the discovery of CVE-2025-21314, a critical SmartScreen spoofing...
All Windows 10/11 systems at risk as Microsoft confirms location data leak via CVE-2025-21301
CVE-2025-21301: Critical Vulnerability in Windows Geolocation Service Microsoft has issued a critical security alert regarding CVE-2025-21301, a newly discovered vulnerability in the Windows...
Patchless Kerberos zero-day CVE-2025-21299 threatens full domain admin takeover
A newly discovered zero-day vulnerability in Microsoft's Kerberos authentication protocol (CVE-2025-21299) poses a severe threat to enterprise networks worldwide. This critical security flaw allows...
Patch Critical AD FS Flaw CVE-2025-21293 Now to Block Domain Takeover
A newly discovered critical vulnerability in Microsoft Active Directory (CVE-2025-21293) has sent shockwaves through the IT security community, with experts warning of potential widespread...
Malformed MSMQ packets crash Windows Servers in new DoS bug CVE-2025-21285
CVE-2025-21285: New DoS Vulnerability in Microsoft Message Queuing A newly discovered vulnerability in Microsoft Message Queuing (MSMQ) has been assigned CVE-2025-21285, posing a significant...
Microsoft issues urgent patch for Windows COM bug CVE-2025-21272 leaking sensitive data
Microsoft's Component Object Model (COM) technology has once again come under scrutiny with the discovery of CVE-2025-21272, a critical information disclosure vulnerability affecting Windows systems....
CVE-2025-21270 zero-day crashes all Windows Server MSMQ with single network packet.
CVE-2025-21270: Major DoS Vulnerability in Microsoft Message Queuing System Microsoft has disclosed a critical vulnerability (CVE-2025-21270) in its Message Queuing (MSMQ) system that could allow...
Critical Windows MapUrlToZone Flaw Allows Remote Code Execution
Microsoft has disclosed a critical security vulnerability (CVE-2025-21268) affecting multiple Windows versions that could allow remote code execution through the MapUrlToZone API. This zero-day flaw...
CVE-2025-21260: Critical Windows Zero-Day Grants SYSTEM Access via Media Files
Microsoft has disclosed a critical elevation of privilege vulnerability (CVE-2025-21260) affecting multiple Windows versions, allowing attackers to gain SYSTEM-level access. This zero-day flaw in the...