Headlines
Microsoft issued patches for 63 CVE-rated vulnerabilities.
- Two vulnerabilities have been reported as Zero Day.
- There are several vulnerabilities published for Excel.
- Two additional vulnerabilities were publicly known prior to being patched.
- One vulnerability with a Critical rating.
Quorum Cyber Recommendations
Patching should be completed within your regular cycles and without delay. We do not at this time recommend expedited patching.
Microsoft Release Notes
February 2025 Security Updates – Release Notes – Security Update Guide – Microsoft
Key Vulnerability Details
| Title | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE | CVE-2025-21418 |
| CVSS | 7.8 |
| Reason for Concern | Reported as a Zero Day |
| Mitigations and other Factors | According to the CVSS scoring method, local access and authentication are both required for exploitation. |
| Commentary | Microsoft have not published how the vulnerability was exploited or who the target was. |
| Threat Intelligence Comment | A critical Use-After-Free vulnerability in the Windows Ancillary Function Driver for WinSock allows local attackers to escalate privileges to SYSTEM level, affecting multiple Windows versions. With a CVSS score of 7.8, it poses significant risks for system compromise and lateral movement. Immediate patching is essential due to active exploitation by threat actors. |
| Link | CVE-2025-21418 – Security Update Guide – Microsoft – Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| Title | Windows Storage Elevation of Privilege Vulnerability |
| CVE | CVE-2025-21391 |
| CVSS | 7.1 |
| Reason for Concern | Reported as a Zero Day |
| Mitigations and other Factors | According to the CVSS scoring method, local access and authentication are both required for exploitation |
| Commentary | Successful exploitation could allow an attacker to delete files on a target system but would not allow disclosure of information. |
| Threat Intelligence Comment | A local privilege escalation vulnerability in Windows Storage services allows attackers to delete targeted files, disrupting system availability. Affecting various Windows versions, it has a CVSS score of 7.1 and poses high risks to system integrity and availability. Active exploitation in the wild underscores the urgency for immediate patching. |
| Link | CVE-2025-21391 – Security Update Guide – Microsoft – Windows Storage Elevation of Privilege Vulnerability |
| Title | Microsoft Surface Security Feature Bypass Vulnerability |
| CVV | CVE-2025-21194 |
| CVSS | 9.8 |
| Reason for Concern | This vulnerability was publicly disclosed prior to patching. |
| Mitigations and other Factors | Successful exploitation of this vulnerability requires that an attacker will need to first gain access to the restricted network before running an attack as well as multiple other conditions, such as specific application behaviour, user actions (a restart is required), manipulation of parameters passed to a function, and impersonation of an integrity level token. |
| Commentary | While the consequences of exploitation are potentially damaging (compromise of the hypervisor and secure kernel), exploitation of the vulnerability appears to be very difficult |
| Threat Intelligence Comment | A security feature bypass vulnerability affects various Microsoft Surface devices, with a CVSS score of 7.1. Requiring an adjacent network and user interaction, the vulnerability poses high risks to confidentiality, integrity, and availability by potentially allowing unauthorised access and data modification. No public proof-of-concept or exploitation evidence currently exists, but the risk remains significant in shared or public network environments. |
| Link | CVE-2025-21194 – Security Update Guide – Microsoft – Microsoft Surface Security Feature Bypass Vulnerability |
| Title | NTLM Hash Disclosure Spoofing Vulnerability |
| CVE | CVE-2025-21377 |
| CVSS | 6.5 |
| Reason for Concern | Publicly disclosed vulnerability with an easy exploit method. Very similar to a Zero Day vulnerability from November 2024’s release. |
| Mitigations and other Factors | User interaction is required for exploitation. |
| Commentary | A user would need to interact with a file, generally received by email. Microsoft state that any interaction with the file could trigger the exploit. The vulnerability targets NTLMv2 hashes. |
| Threat Intelligence Comment | An NTLM Hash Disclosure Spoofing Vulnerability in multiple Microsoft Windows versions allows network-based attacks with low complexity, requiring user interaction but no privileges. With a CVSS score of 6.5, it poses a medium risk by potentially exposing NTLM hashes, leading to spoofing and further attacks. Although no public proof-of-concept exists, exploitation has been reported. A patch is available from Microsoft as of February 11, 2025, and should be applied immediately to mitigate the risk. |
| Link | CVE-2025-21377 – Security Update Guide – Microsoft – NTLM Hash Disclosure Spoofing Vulnerability |
| Title | Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability |
| CVE | CVE-2025-21198 |
| CVSS | 9.0 |
| Reason for Concern | Critical rating, can allow for code execution. |
| Mitigations and other Factors | Access to an adjacent network is required for exploitation. |
| Commentary | While this carries a Critical rating, it appears to be a relatively difficult vulnerability to exploit. |
| Threat Intelligence Comment | A remote code execution vulnerability in Microsoft HPC Pack 2016 and 2019 can be exploited from an adjacent network, requiring low privileges and no user interaction. With a severe impact on confidentiality, integrity, and availability, successful exploitation could lead to unauthorised code execution and system compromise across HPC environments. No public proof-of-concept or evidence of exploitation currently exists, but the risk to critical computational tasks and network infrastructure remains significant. |
| Link | CVE-2025-21198 – Security Update Guide – Microsoft – Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability |
Additional Releases
Aside from Microsoft, the following vendors have issued updates for significant vulnerabilities:
- Ivanti Critical updates February Security Update | Ivanti
- SAP Multiple Vulnerabilities including High rated SAP Security Patch Day – February 2025
- Fortinet firewall bypass Fortinet discloses second firewall auth bypass patched in January












