Headlines

Microsoft issued patches for 63 CVE-rated vulnerabilities. 

  • Two vulnerabilities have been reported as Zero Day. 
  • There are several vulnerabilities published for Excel. 
  • Two additional vulnerabilities were publicly known prior to being patched. 
  • One vulnerability with a Critical rating. 

Quorum Cyber Recommendations

Patching should be completed within your regular cycles and without delay. We do not at this time recommend expedited patching.

Microsoft Release Notes

February 2025 Security Updates – Release Notes – Security Update Guide – Microsoft 

Key Vulnerability Details

TitleWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability  
CVECVE-2025-21418 
CVSS7.8
Reason for ConcernReported as a Zero Day
Mitigations and other FactorsAccording to the CVSS scoring method, local access and authentication are both required for exploitation. 
CommentaryMicrosoft have not published how the vulnerability was exploited or who the target was. 
Threat Intelligence CommentA critical Use-After-Free vulnerability in the Windows Ancillary Function Driver for WinSock allows local attackers to escalate privileges to SYSTEM level, affecting multiple Windows versions. With a CVSS score of 7.8, it poses significant risks for system compromise and lateral movement. Immediate patching is essential due to active exploitation by threat actors. 
LinkCVE-2025-21418 – Security Update Guide – Microsoft – Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 

 

TitleWindows Storage Elevation of Privilege Vulnerability  
CVECVE-2025-21391 
CVSS7.1
Reason for ConcernReported as a Zero Day
Mitigations and other FactorsAccording to the CVSS scoring method, local access and authentication are both required for exploitation
CommentarySuccessful exploitation could allow an attacker to delete files on a target system but would not allow disclosure of information.
Threat Intelligence CommentA local privilege escalation vulnerability in Windows Storage services allows attackers to delete targeted files, disrupting system availability. Affecting various Windows versions, it has a CVSS score of 7.1 and poses high risks to system integrity and availability. Active exploitation in the wild underscores the urgency for immediate patching. 
LinkCVE-2025-21391 – Security Update Guide – Microsoft – Windows Storage Elevation of Privilege Vulnerability 

 

TitleMicrosoft Surface Security Feature Bypass Vulnerability
CVVCVE-2025-21194 
CVSS9.8
Reason for ConcernThis vulnerability was publicly disclosed prior to patching. 
Mitigations and other FactorsSuccessful exploitation of this vulnerability requires that an attacker will need to first gain access to the restricted network before running an attack as well as multiple other conditions, such as specific application behaviour, user actions (a restart is required), manipulation of parameters passed to a function, and impersonation of an integrity level token. 
CommentaryWhile the consequences of exploitation are potentially damaging (compromise of the hypervisor and secure kernel), exploitation of the vulnerability appears to be very difficult 
Threat Intelligence CommentA security feature bypass vulnerability affects various Microsoft Surface devices, with a CVSS score of 7.1. Requiring an adjacent network and user interaction, the vulnerability poses high risks to confidentiality, integrity, and availability by potentially allowing unauthorised access and data modification. No public proof-of-concept or exploitation evidence currently exists, but the risk remains significant in shared or public network environments. 
LinkCVE-2025-21194 – Security Update Guide – Microsoft – Microsoft Surface Security Feature Bypass Vulnerability 

 

TitleNTLM Hash Disclosure Spoofing Vulnerability  
CVECVE-2025-21377 
CVSS6.5
Reason for ConcernPublicly disclosed vulnerability with an easy exploit methodVery similar to a Zero Day vulnerability from November 2024’s release. 
Mitigations and other FactorsUser interaction is required for exploitation. 
CommentaryA user would need to interact with a file, generally received by emailMicrosoft state that any interaction with the file could trigger the exploitThe vulnerability targets NTLMv2 hashes. 
Threat Intelligence CommentAn NTLM Hash Disclosure Spoofing Vulnerability in multiple Microsoft Windows versions allows network-based attacks with low complexity, requiring user interaction but no privileges. With a CVSS score of 6.5, it poses a medium risk by potentially exposing NTLM hashes, leading to spoofing and further attacks. Although no public proof-of-concept exists, exploitation has been reported. A patch is available from Microsoft as of February 11, 2025, and should be applied immediately to mitigate the risk. 
LinkCVE-2025-21377 – Security Update Guide – Microsoft – NTLM Hash Disclosure Spoofing Vulnerability 

 

TitleMicrosoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability 
CVECVE-2025-21198 
CVSS9.0
Reason for ConcernCritical rating, can allow for code execution. 
Mitigations and other FactorsAccess to an adjacent  network is required for exploitation. 
CommentaryWhile this carries a Critical rating, it appears to be a relatively difficult vulnerability to exploit. 
Threat Intelligence CommentA remote code execution vulnerability in Microsoft HPC Pack 2016 and 2019 can be exploited from an adjacent network, requiring low privileges and no user interaction. With a severe impact on confidentiality, integrity, and availability, successful exploitation could lead to unauthorised code execution and system compromise across HPC environments. No public proof-of-concept or evidence of exploitation currently exists, but the risk to critical computational tasks and network infrastructure remains significant. 
LinkCVE-2025-21198 – Security Update Guide – Microsoft – Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability 

Additional Releases

Aside from Microsoft, the following vendors have issued updates for significant vulnerabilities:

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content