Headlines
Microsoft issued patches for 161 Common Vulnerability and Exposure (CVE)-rated vulnerabilities. Please note:
- This is the largest number of CVE-rated vulnerabilities since 2017
- There are three zero-day vulnerabilities, all of which are found in Hyper-V, and which allow for privilege escalation
- Microsoft has not disclosed how these vulnerabilities were exploited but it is assumed that the attackers already had access to the target networks
- There are also several vulnerabilities that were publicly known prior to patching
- There are Critical rated vulnerabilities affecting NTLMv1, Windows OLE, and Windows RMCAST.
Quorum Cyber Recommendations
Patching should be completed within your regular cycles and without delay. We do not at this time recommend expedited patching.
Microsoft Release Notes
January 2025 Security Updates – Release Notes – Security Update Guide – Microsoft
Key Vulnerability Details
| Title | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
| CVE | CVE-2025-21333 CVE-2025-21334 CVE-2025-21335 |
| CVSS | 7.8 |
| Reason for Concern | Zero day with public exploit. |
| Mitigations and other Factors | While it is not known how these were exploited, it is likely that the attacker had prior access to the target devices, and this has not been used for initial ingress. |
| Commentary | This has been added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerability Catalog. |
| Threat Intelligence Comment | This flaw allows attackers to gain SYSTEM-level privileges, leading to full control over the affected system. Successful exploitation enables attackers to execute arbitrary code, install malware, exfiltrate data, and create new accounts with full user rights without user interaction. The vulnerability has been exploited in the wild and has been added to the CISA Known Exploited Vulnerability Catalog, further emphasising its severity and the urgency for remediation. |
| Link | CVE-2025-21333 – Security Update Guide – Microsoft – Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
| Title | Windows NTLM V1 Elevation of Privilege Vulnerability |
| CVE | CVE-2025-21333 |
| CVSS | 9.8 |
| Reason for Concern | Critical-rated vulnerability. Remotely exploitable over the internet. The attack complexity is Low because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component. |
| Mitigations and other Factors | It is possible to mitigate the vulnerability. Microsoft’s guidance notes state the following: Set the LmCompatabilityLvl to its maximum value (5) for all machines. This will prevent the usage of the older NTLMv1 protocol, while still allowing NTLMv2. |
| Commentary | While the criticality level is high and exploitation appears to be straightforward, this can be mitigated as only NTLMv1 is affected. |
| Threat Intelligence Comment | We are bringing this vulnerability to your attention due to its critical nature and the ease with which it can be exploited. The low attack complexity significantly increases the risk of widespread exploitation. Attackers could leverage it to gain a foothold within your network, leading to data breaches, significant financial loss, and reputational damage. |
| Link | CVE-2025-21311 – Security Update Guide – Microsoft – Windows NTLM V1 Elevation of Privilege Vulnerability |
| Title | Windows OLE Remote Code Execution Vulnerability |
| CVE | CVE-2025-21298 |
| CVSS | 9.8 |
| Reason for Concern | Critical rated vulnerability with a relatively simple exploit. |
| Mitigations and other Factors | Microsoft has recommended the following as a mitigation: To help protect against this vulnerability, we recommend users read email messages in plain text format. |
| Commentary | In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted email to the victim. Exploitation of the vulnerability might involve either a victim opening a specially crafted email with an affected version of Microsoft Outlook software, or a victim’s Outlook application displaying a preview of a specially crafted email. This could result in the attacker executing remote code on the victim’s machine. |
| Threat Intelligence Comment | We are alerting you to this vulnerability due to its critical nature and the simplicity of its exploit. The method of attack – via email – makes it particularly concerning as email is a common vector for phishing and other malicious activities. The ease of exploitation combined with the widespread use of Microsoft Outlook significantly increases the risk to your organisation. Attackers could quickly gain control over vulnerable systems, leading to significant financial, operational, and reputational damage. |
| Link | CVE-2025-21298 – Security Update Guide – Microsoft – Windows OLE Remote Code Execution Vulnerability |
| Title | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerabilit |
| CVE | CVE-2025-21307 |
| CVSS | 9.8 |
| Reason for Concern | An unauthenticated attacker could exploit the vulnerability by sending specially crafted packets to a Windows Pragmatic General Multicast (PGM) open socket on the server, without any interaction from the user. |
| Mitigations and other Factors | Microsoft’s release notes state the following: This vulnerability is only exploitable if there is a programme listening on a Pragmatic General Multicast (PGM) port. If PGM is installed or enabled but no programmes are actively listening as a receiver, then this vulnerability is not exploitable. PGM does not authenticate requests, so it is recommended to protect access to any open ports at the network level (e.g. with a firewall). It is not recommended to expose a PGM receiver to the public internet. |
| Commentary | While exploitation initially appears to be easy, it is also relatively easy to mitigate against a potential attack. |
| Threat Intelligence Comment | We are alerting you to this vulnerability due to its critical nature and the potential for remote code execution without user interaction. The ease with which this vulnerability can be exploited makes it particularly dangerous, especially if PGM is enabled and actively listening on open ports. Given the critical severity and the fact that no user interaction is needed, attackers could quickly exploit vulnerable systems, leading to significant financial, operational, and reputational damage. |
| Link | CVE-2025-21307 – Security Update Guide – Microsoft – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
| Title | Microsoft Excel Remote Code Execution Vulnerability |
| CVE | CVE-2025-21354 CVE-2025-21362 |
| CVSS | 8.4 |
| Reason for Concern | Relatively easy exploit (user needs to open an Excel document and view it via an email preview) |
| Mitigations and other Factors | This relies on a phishing-based attack method with user interaction as a factor. Your users will therefore need to open a compromised file. |
| Commentary | This is a fairly common type of vulnerability in Excel and is not unique to this patch release, however, any vulnerability of this type should be taken seriously. |
| Threat Intelligence Comment | We are alerting you to these vulnerabilities due to their high severity and the common nature of phishing-based attacks. While not unique to this patch release, vulnerabilities of this type are frequently exploited by attackers to gain unauthorised access and execute malicious code. Given the reliance on user interaction, phishing attacks can be highly effective, and the consequences of a successful exploit can be significant, leading to financial loss, operational disruption, and reputational damage. |
| Link | CVE-2025-21354 – Security Update Guide – Microsoft – Microsoft Excel Remote Code Execution Vulnerability |
Additional Releases
Aside from Microsoft, the following vendors have issued updates for significant vulnerabilities:
- Ivanti Zero Day Ivanti warns of new Connect Secure flaw used in zero-day attacks
- SAP Multiple Vulnerabilities including Critical rated SAP Security Patch Day – January 2025
- Fortinet Zero Day Fortinet warns of auth bypass zero-day exploited to hijack firewalls












