Skip to main content

Scheduled updates for Microsoft products, including security updates for 57 vulnerabilities, of which six are reported as exploited

Summary

Scheduled updates for Microsoft products, including security updates for 57 vulnerabilities, of which six are reported as exploited

Affected platforms

The following platforms are known to be affected:

The following platforms are also known to be affected:

Threat details

Introduction

Microsoft has released security updates to address 57 vulnerabilities in Microsoft products. Five vulnerabilities are highlighted below, of which two are exploited and three are considered critical.

Vulnerability details

CVE-2025-24983 is a 'use-after-free' vulnerability in Windows and Windows Server with a CVSSv3 score of 7.0. Successful exploitation could allow an attacker to escalate privileges and gain SYSTEM privileges. Microsoft reports that this vulnerability is under exploitation.

CVE-2025-24993 is a 'heap-based buffer overflow' vulnerability in Windows and Windows Server with a CVSSv3 score of 7.8. Successful exploitation could allow an unauthorised attacker to execute code locally. Microsoft reports that this vulnerability is under exploitation.

CVE-2025-24057 is a critical 'heap-based buffer overflow' vulnerability in Microsoft Office, Microsoft 365 Apps, and Office Online Server with a CVSSv3 score of 7.8. The Preview Pane is considered as an attack vector. Successful exploitation could allow an unauthorised attacker to execute arbitrary code (ACE).

CVE-2025-26645 is a critical 'relative path traversal' vulnerability in Remote Desktop Client, Windows App Client for Windows Desktop, Windows and Windows Server with a CVSSv3 score of 8.8 . Successful exploitation could allow an unauthorised attacker to execute code over a network.

CVE-2025-24084 is a critical 'untrusted pointer dereference' vulnerability in Windows and Windows Server with a CVSSv3 score of 8.4 . Successful exploitation could allow an unauthorised attacker to achieve ACE.

Remediation advice

Affected organisations are encouraged to review Microsoft's March 2025 Security Updates and apply the relevant updates as soon as practicable.

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 12 March 2025 3:00 pm