Headlines

Microsoft issued patches for 161 Common Vulnerability and Exposure (CVE)-rated vulnerabilities. Please note:

  • This is the largest number of CVE-rated vulnerabilities since 2017
  • There are three zero-day vulnerabilities, all of which are found in Hyper-V, and which allow for privilege escalation
  • Microsoft has not disclosed how these vulnerabilities were exploited but it is assumed that the attackers already had access to the target networks
  • There are also several vulnerabilities that were publicly known prior to patching
  • There are Critical rated vulnerabilities affecting NTLMv1, Windows OLE, and Windows RMCAST.

Quorum Cyber Recommendations

Patching should be completed within your regular cycles and without delay. We do not at this time recommend expedited patching.

Microsoft Release Notes

January 2025 Security Updates – Release Notes – Security Update Guide – Microsoft

Key Vulnerability Details

TitleWindows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
CVECVE-2025-21333 CVE-2025-21334 CVE-2025-21335
CVSS7.8
Reason for ConcernZero day with public exploit.
Mitigations and other FactorsWhile it is not known how these were exploited, it is likely that the attacker had prior access to the target devices, and this has not been used for initial ingress.
CommentaryThis has been added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerability Catalog.
Threat Intelligence CommentThis flaw allows attackers to gain SYSTEM-level privileges, leading to full control over the affected system. Successful exploitation enables attackers to execute arbitrary code, install malware, exfiltrate data, and create new accounts with full user rights without user interaction. The vulnerability has been exploited in the wild and has been added to the CISA Known Exploited Vulnerability Catalog, further emphasising its severity and the urgency for remediation.
LinkCVE-2025-21333 – Security Update Guide – Microsoft – Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

 

TitleWindows NTLM V1 Elevation of Privilege Vulnerability
CVECVE-2025-21333
CVSS9.8
Reason for ConcernCritical-rated vulnerability. Remotely exploitable over the internet. The attack complexity is Low because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.
Mitigations and other FactorsIt is possible to mitigate the vulnerability. Microsoft’s guidance notes state the following: Set the LmCompatabilityLvl to its maximum value (5) for all machines. This will prevent the usage of the older NTLMv1 protocol, while still allowing NTLMv2.
CommentaryWhile the criticality level is high and exploitation appears to be straightforward, this can be mitigated as only NTLMv1 is affected.
Threat Intelligence CommentWe are bringing this vulnerability to your attention due to its critical nature and the ease with which it can be exploited. The low attack complexity significantly increases the risk of widespread exploitation. Attackers could leverage it to gain a foothold within your network, leading to data breaches, significant financial loss, and reputational damage.
LinkCVE-2025-21311 – Security Update Guide – Microsoft – Windows NTLM V1 Elevation of Privilege Vulnerability

 

TitleWindows OLE Remote Code Execution Vulnerability
CVECVE-2025-21298
CVSS9.8
Reason for ConcernCritical rated vulnerability with a relatively simple exploit.
Mitigations and other FactorsMicrosoft has recommended the following as a mitigation: To help protect against this vulnerability, we recommend users read email messages in plain text format.
CommentaryIn an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted email to the victim. Exploitation of the vulnerability might involve either a victim opening a specially crafted email with an affected version of Microsoft Outlook software, or a victim’s Outlook application displaying a preview of a specially crafted email. This could result in the attacker executing remote code on the victim’s machine.
Threat Intelligence CommentWe are alerting you to this vulnerability due to its critical nature and the simplicity of its exploit. The method of attack – via email – makes it particularly concerning as email is a common vector for phishing and other malicious activities. The ease of exploitation combined with the widespread use of Microsoft Outlook significantly increases the risk to your organisation. Attackers could quickly gain control over vulnerable systems, leading to significant financial, operational, and reputational damage.
LinkCVE-2025-21298 – Security Update Guide – Microsoft – Windows OLE Remote Code Execution Vulnerability 

 

TitleWindows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerabilit
CVECVE-2025-21307
CVSS9.8
Reason for ConcernAn unauthenticated attacker could exploit the vulnerability by sending specially crafted packets to a Windows Pragmatic General Multicast (PGM) open socket on the server, without any interaction from the user.
Mitigations and other FactorsMicrosoft’s release notes state the following: This vulnerability is only exploitable if there is a programme listening on a Pragmatic General Multicast (PGM) port. If PGM is installed or enabled but no programmes are actively listening as a receiver, then this vulnerability is not exploitable. PGM does not authenticate requests, so it is recommended to protect access to any open ports at the network level (e.g. with a firewall). It is not recommended to expose a PGM receiver to the public internet.
CommentaryWhile exploitation initially appears to be easy, it is also relatively easy to mitigate against a potential attack.
Threat Intelligence CommentWe are alerting you to this vulnerability due to its critical nature and the potential for remote code execution without user interaction. The ease with which this vulnerability can be exploited makes it particularly dangerous, especially if PGM is enabled and actively listening on open ports. Given the critical severity and the fact that no user interaction is needed, attackers could quickly exploit vulnerable systems, leading to significant financial, operational, and reputational damage.
LinkCVE-2025-21307 – Security Update Guide – Microsoft – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

 

TitleMicrosoft Excel Remote Code Execution Vulnerability
CVECVE-2025-21354 CVE-2025-21362
CVSS8.4
Reason for ConcernRelatively easy exploit (user needs to open an Excel document and view it via an email preview)
Mitigations and other FactorsThis relies on a phishing-based attack method with user interaction as a factor. Your users will therefore need to open a compromised file.
CommentaryThis is a fairly common type of vulnerability in Excel and is not unique to this patch release, however, any vulnerability of this type should be taken seriously.
Threat Intelligence CommentWe are alerting you to these vulnerabilities due to their high severity and the common nature of phishing-based attacks. While not unique to this patch release, vulnerabilities of this type are frequently exploited by attackers to gain unauthorised access and execute malicious code. Given the reliance on user interaction, phishing attacks can be highly effective, and the consequences of a successful exploit can be significant, leading to financial loss, operational disruption, and reputational damage.
LinkCVE-2025-21354 – Security Update Guide – Microsoft – Microsoft Excel Remote Code Execution Vulnerability

Additional Releases

Aside from Microsoft, the following vendors have issued updates for significant vulnerabilities:

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content