Vulnerability
The latest Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft confirms CVE-2025-24054 NTLM attacks after March 11 patch.
Overview On March 11, 2025, Microsoft released its Patch Tuesday updates, addressing multiple vulnerabilities across its software suite. Among these, CVE-2025-24054—a Windows NTLM hash disclosure...
Windows 11 April 2025 Update Introduces 'inetpub' Folder: Security Risks and How to Mitigate Them
Windows 11 'inetpub' Folder Security Risks and Mitigations After April 2025 Update Introduction The Windows 11 April 2025 cumulative update (notably KB5055523) has brought attention to an unexpected...
CVE-2025-24054: Exploitation of Windows NTLM Hash Leak Vulnerability Highlights Urgent Need for Patch Management
Overview In March 2025, Microsoft addressed a critical security vulnerability, CVE-2025-24054, within its Windows operating system. This flaw, involving the NT LAN Manager (NTLM) authentication...
Understanding Microsoft's April 2025 Windows 11 Update: The 'inetpub' Folder and Its Crucial Security Role
Introduction In April 2025, Microsoft released a cumulative update for Windows 11 24H2, identified as KB5055523, which introduced an unexpected yet significant change: the creation of an empty...
Understanding the inetpub Folder in Windows 11: Security Benefits and Hidden Risks
For Windows 11 users and IT professionals alike, the operating system's intricate file structure often hides both powerful tools and potential risks. One such element, the inetpub folder, has...
inetpub Folder Auto-Created in April 2025 Update to Block CVE-2025-21204, but Permissions Need Hardening
Introduction With the April 2025 cumulative update (notably KB5055523 for Windows 11 24H2 and corresponding updates for Windows 10), many users have noticed the unexpected creation of the...
Critical Security Alert: Update Your Windows 11 24H2 Install Media to Mitigate High-Severity Vulnerability
Overview The Pakistan Telecommunication Authority (PTA) has issued an urgent cybersecurity advisory concerning a high-severity vulnerability discovered in Microsoft's Windows 11 version 24H2. This...
Windows April 2025 Update Exposes Critical IIS Vulnerability (CVE-2025-21204)
The April 2025 update for Windows 10 and 11 systems has unexpectedly surfaced dormant IIS components, thrusting the typically hidden inetpub directory into the spotlight and exposing attack vectors...
PTA Warns: Outdated Windows 11 24H2 Installation Media Poses Critical Security Risks
A newly issued security advisory from the Pakistan Telecommunication Authority (PTA) has ignited urgent discussions among IT professionals worldwide, revealing that outdated Windows 11 installation...
Windows Server 2025 DCs load wrong firewall profile after reboot, Microsoft offers workaround
Overview Microsoft's latest server operating system, Windows Server 2025, has encountered a significant issue affecting domain controllers (DCs). After a system restart, these servers may fail to...
Exploitation of Windows NTLM Vulnerability CVE-2025-24054 in Widespread Cyberattacks
Overview In March 2025, Microsoft released a security update addressing a critical vulnerability in the Windows NT LAN Manager (NTLM) authentication protocol, identified as CVE-2025-24054. Despite...