Headlines
Microsoft issued patches for 120 CVE-rated vulnerabilities, including one actively exploited zero-day vulnerability:
- The one zero-day vulnerability addressed is a privilege elevation issue
- There is a secure feature bypass issue within Windows Kerberos
- Multiple vulnerabilities in LDAP and Remote Desktop Services
- Since March’s Patch Tuesday, Microsoft has also addressed 22 vulnerabilities in Edge.
Quorum Cyber Recommendations
Patching should be completed within your regular cycles and without delay. We do not at this time recommend expedited patching.
Microsoft Release Notes
April 2025 Security Updates – Release Notes – Security Update Guide – Microsoft
Key Vulnerability Details
| Title | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE | CVE-2025-29824 |
| CVSS | 7.8 |
| Reason for Concern | Exploited zero-day vulnerability. Windows 10 devices are not yet patched. Attacker can gain SYSTEM privileges. |
| Mitigations and other Factors | The attacker requires privileges before an exploit can be attempted. |
| Commentary | While this is rated as a ‘Low complexity’ vulnerability, the attacker will need to first compromise a user’s privileges. |
| Threat Intelligence Comment | The Windows Common Log File System Driver Elevation of Privilege Vulnerability (CVE-2025-29824) is a critical zero-day exploit affecting Windows 10 devices, allowing attackers to gain SYSTEM privileges. Despite its low complexity rating, attackers must first compromise user privileges, emphasising the need for immediate patching and enhanced user access controls to mitigate risks. |
| Link | CVE-2025-29824 – Security Update Guide – Microsoft – Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| Title | Windows Kerberos Security Feature Bypass Vulnerability |
| CVE | CVE-2025-29809 |
| CVSS | 7.1 |
| Reason for Concern | Insecure storage of sensitive information in Windows Kerberos allows an authorised attacker to bypass a security feature locally. The patch for Windows 10 devices has not yet been released. |
| Mitigations and other Factors | Local access and low-level privileges are required for exploitation. |
| Commentary | An attacker who successfully exploited this vulnerability could bypass Windows Defender Credential Guard Feature to leak Kerberos Credential. The changes to address this vulnerability updated Virtual Secure Mode components. The policy described in Guidance for blocking rollback of Virtualization-based Security (VBS) related security updates has been updated to account for the latest changes. If you deployed this policy, then you’ll need to redeploy using the updated policy. |
| Threat Intelligence Comment | The Windows Kerberos Security Feature Bypass Vulnerability (CVE-2025-29809) poses a significant threat, allowing attackers with local access and low-level privileges to bypass security features and leak Kerberos credentials. As the patch for Windows 10 devices is pending release, organisations should urgently update Virtual Secure Mode components and redeploy policies to prevent exploitation and protect sensitive information. |
| Link | CVE-2025-29809 – Security Update Guide – Microsoft – Windows Kerberos Security Feature Bypass Vulnerability |
| Title |
| ||
| CVV | CVE-2025-27480 | ||
| CVSS | 8.1 | ||
| Reason for Concern | Vulnerability exists in the popular Remote Desktop Services, and will likely be very common. | ||
| Mitigations and other Factors | Attacker will need to win a race condition before exploitation, making the attack complexity High in the CVSS score. | ||
| Commentary | While Microsoft has listed this as more likely to be exploited, it appears that exploitation is not easy. | ||
| Threat Intelligence Comment | The Windows Remote Desktop Services Remote Code Execution Vulnerability (CVE-2025-27480) is a high-risk issue with an 8.1 CVSS score due to its prevalence in Remote Desktop Services. Although exploitation requires winning a race condition, making it highly complex, Microsoft indicates a high likelihood of exploitation. Organisations should prioritise patching and strengthening RDP security measures to prevent potential remote code execution attacks. | ||
| Link | CVE-2025-27480 – Security Update Guide – Microsoft – Windows Remote Desktop Services Remote Code Execution Vulnerability |
| Title | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE | CVE-2025-27480 |
| CVSS | 7.1 |
| Reason for Concern | Allows remote code execution over the network |
| Mitigations and other Factors | User interaction and low level privileges are required. The attacker must also win a race condition. |
| Commentary | The attack complexity is listed as High and while the attacker requires privileges, a low-level account is all that’s needed. |
| Threat Intelligence Comment | The Windows Hyper-V Remote Code Execution Vulnerability (CVE-2025-27480) is a significant threat that allows remote code execution over the network, with a CVSS score of 7.1. Despite its high attack complexity, requiring user interaction and the attacker to win a race condition, only low-level privileges are needed. Organisations should ensure their Hyper-V environments are patched and implement stringent access controls to mitigate the risk of exploitation. |
| Link | CVE-2025-27491 – Security Update Guide – Microsoft – Windows Hyper-V Remote Code Execution Vulnerability |
| Title | Microsoft Office Remote Code Execution Vulnerability |
| CVE | CVE-2025-27749 |
| CVSS | 7.8 |
| Reason for Concern | The preview pane can be used as an attack vector, meaning very limited user interaction is required. |
| Mitigations and other Factors | An attacker would need to get a compromised file onto your network and convince a user to open it. |
| Commentary | This is common type of attack and has been seen before in other vulnerabilities. That said, it can be quite easy to trick a user into opening a file. |
| Threat Intelligence Comment | The Microsoft Office Remote Code Execution Vulnerability (CVE-2025-27749) poses a severe risk with a CVSS score of 7.8, as it can be exploited via the preview pane with minimal user interaction. Attackers need to introduce a compromised file into the network and convince a user to open it, a common and historically successful attack vector. Organisations should prioritise patching and user awareness training to prevent exploitation through malicious Office files. |
| Link | CVE-2025-27749 – Security Update Guide – Microsoft – Microsoft Office Remote Code Execution Vulnerability |
Additional Releases
Aside from Microsoft, the following vendors have issued updates for significant vulnerabilities:
Adobe – Adobe Security Bulletins and Advisories
Apple – Apple security releases – Apple Support
Cisco – Security Advisories
F5 – New & Updated Articles | MyF5
Fortinet – PSIRT Advisories | FortiGuard Labs
Sophos – Security Advisories | Sophos
Splunk – Splunk Vulnerability Disclosure
WordPress – Security – WordPress News












