Microsoft is addressing 121 vulnerabilities this April 2025 Patch Tuesday, which is more than twice as many as last month. Microsoft has evidence of in-the-wild exploitation for just one of the vulnerabilities published today, which is already reflected in CISA KEV. Once again, Microsoft has published zero-day vulnerabilities on Patch Tuesday without evaluating any of them as critical severity at time of publication, so that’s now a seven month unbroken streak. Today also sees the publication of 11 critical remote code execution (RCE) vulnerabilities. 13 browser vulnerabilities have already been published separately this month, and are not included in the total.
CLFS: zero-day EoP
The Windows Common Log File System (CLFS) Driver is firmly back on our radar today with CVE-2025-29824, a zero-day local elevation of privilege vulnerability. First, the good news: the Acknowledgements section credits the Microsoft Threat Intelligence Center, so the exploit was successfully reproduced by Microsoft; the less-good news is that someone other than Microsoft was first to discover the exploit, because otherwise Microsoft wouldn’t be listing CVE-2025-29824 as exploited in the wild.
The advisory does not specify what privilege level is achieved upon successful exploitation, but it’ll be SYSTEM, because that’s the prize for all the other CLFS elevation of privilege zero-day vulnerabilities. As usual, some form of less-privileged local access is a pre-requisite, but attack complexity is low, so this is the sort of vulnerability which goes into any standard break-and-enter toolkit. Given the long history of similar vulnerabilities, it would be more surprising if exploit code wasn’t publicly available in the not-too-distant future.
Although December 2024 Patch Tuesday seems as though it must have been a very long time ago, any standard calendar will tell us that only 119 days have elapsed since the last zero-day CLFS local elevation of privilege. Rapid7 discussed the history of CLFS zero-day elevation of privilege vulnerabilities at the time. All versions of Windows receive a patch, except for the venerable LTSC Windows 10 1507, which is listed on the advisory as vulnerable, but left out in the cold with no update; the FAQ says to check back later. Windows 10 LTSC 1507 is scheduled for end of servicing on 2025-10-14, so the clock is ticking regardless.
LDAP Server: critical RCE
Although it has been many months since we’ve seen a critical zero-day vulnerability from Microsoft, there is no shortage of critical remote code execution (RCE) vulnerabilities published today. Defenders responsible for an LDAP server — which means almost any organization with a non-trivial Microsoft footprint — should add patching for CVE-2025-26663 to their to-do list. With no privileges required, no need for user interaction, and code execution presumably in the context of the LDAP server itself, successful exploitation would be an attractive shortcut to any attacker. Anyone wondering if today is a re-run of December 2024 Patch Tuesday can take some small solace in the fact that the worst of the trio of LDAP critical RCEs published at the end of last year was likely easier to exploit than today’s example, since today’s CVE-2025-26663 requires that an attacker win a race condition. Despite that, Microsoft still expects that exploitation is more likely.
LDAP Client: critical RCE
If you breathe a sigh of relief when you see LDAP server critical RCE vulnerabilities like CVE-2025-26663, because you’re certain that you don’t have any Windows LDAP servers in your estate, how about LDAP clients? CVE-2025-26670 describes a critical RCE in the LDAP client, although the FAQ confusingly states that exploitation would require an attacker to “send specially crafted requests to a vulnerable LDAP server”; this seems like it might be a data entry error on the advisory FAQ, so keep an eye out for an update to that section of the advisory. Assuming the rest of the advisory is all present and correct, exploitation requires that the attacker win a race condition, which keeps the attack complexity higher than it otherwise would be. While we wait for clarification, it’s still a critical RCE which Microsoft rates as “exploitation more likely”. On that basis, patching is always recommended.
RDS: critical RCEs
The prolific Windows vulnerability pioneers at Kunlun Lab are credited with a pair of critical RCE vulnerabilities in Windows Remote Desktop Services. Although both CVE-2025-27480 and CVE-2025-27482 share a CVSSv3 base score of 8.1, Microsoft has ranked them both as critical using its own proprietary severity ranking scale. Both vulnerabilities require that an attacker win a race condition. If you’ve ever read Microsoft’s guide to deploying the Remote Desktop Gateway role, you probably have some systems to patch.
Hyper-V: critical RCE
Some Microsoft security advisory FAQs provide a satisfying level of detail, whereas others raise more questions than they answer. CVE-2025-27491 is a Hyper-V critical RCE which falls into the second category, since it states that an attacker must be authenticated — no need for elevated privileges — but also that the attacker must send the user a malicious site and convince them to open it, and it’s not at all clear why authentication would be required in that case. Also unusual: the remediation table on the advisory lists several 32-bit versions of Windows as receiving patches, although Hyper-V requires a 64-bit processor and a 64-bit host OS.
Microsoft lifecycle update
In Microsoft product lifecycle news, Dynamics GP 2015 moves past the end of extended support today. The next batch of significant lifecycle status changes are due in July 2025, when SQL Server 2012 ESU program draws to a close.
Summary charts


Elevated amounts of elevation of privilege

Summary tables
Apps vulnerabilities
CVE | Title | Exploited? | Publicly disclosed? | CVSSv3 base score |
---|
CVE-2025-29805 | Outlook for Android Information Disclosure Vulnerability | No | No | 7.5 |
Azure vulnerabilities
CVE | Title | Exploited? | Publicly disclosed? | CVSSv3 base score |
---|
CVE-2025-27489 | Azure Local Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-26628 | Azure Local Cluster Information Disclosure Vulnerability | No | No | 7.3 |
CVE-2025-25002 | Azure Local Cluster Information Disclosure Vulnerability | No | No | 6.8 |
Browser vulnerabilities
CVE | Title | Exploited? | Publicly disclosed? | CVSSv3 base score |
---|
CVE-2025-25000 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | No | No | 8.8 |
CVE-2025-29815 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | No | No | 7.6 |
CVE-2025-29796 | Microsoft Edge for iOS Spoofing Vulnerability | No | No | 4.7 |
CVE-2025-25001 | Microsoft Edge for iOS Spoofing Vulnerability | No | No | 4.3 |
CVE-2025-3074 | Chromium: CVE-2025-3074 Inappropriate implementation in Downloads | No | No | N/A |
CVE-2025-3073 | Chromium: CVE-2025-3073 Inappropriate implementation in Autofill | No | No | N/A |
CVE-2025-3072 | Chromium: CVE-2025-3072 Inappropriate implementation in Custom Tabs | No | No | N/A |
CVE-2025-3071 | Chromium: CVE-2025-3071 Inappropriate implementation in Navigations | No | No | N/A |
CVE-2025-3070 | Chromium: CVE-2025-3070 Insufficient validation of untrusted input in Extensions | No | No | N/A |
CVE-2025-3069 | Chromium: CVE-2025-3069 Inappropriate implementation in Extensions | No | No | N/A |
CVE-2025-3068 | Chromium: CVE-2025-3068 Inappropriate implementation in Intents | No | No | N/A |
CVE-2025-3067 | Chromium: CVE-2025-3067 Inappropriate implementation in Custom Tabs | No | No | N/A |
CVE-2025-3066 | Chromium: CVE-2025-3066 Use after free in Navigations | No | No | N/A |
Developer Tools vulnerabilities
CVE | Title | Exploited? | Publicly disclosed? | CVSSv3 base score |
---|
CVE-2025-26682 | ASP.NET Core and Visual Studio Denial of Service Vulnerability | No | No | 7.5 |
CVE-2025-29802 | Visual Studio Elevation of Privilege Vulnerability | No | No | 7.3 |
CVE-2025-29804 | Visual Studio Elevation of Privilege Vulnerability | No | No | 7.3 |
CVE-2025-20570 | Visual Studio Code Elevation of Privilege Vulnerability | No | No | 6.8 |
Developer Tools SQL Server vulnerabilities
CVE | Title | Exploited? | Publicly disclosed? | CVSSv3 base score |
---|
CVE-2025-29803 | Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Privilege Vulnerability | No | No | 7.3 |
Microsoft Dynamics vulnerabilities
CVE | Title | Exploited? | Publicly disclosed? | CVSSv3 base score |
---|
CVE-2025-29821 | Microsoft Dynamics Business Central Information Disclosure Vulnerability | No | No | 5.5 |
Microsoft Office vulnerabilities
CVE | Title | Exploited? | Publicly disclosed? | CVSSv3 base score |
---|
CVE-2025-29794 | Microsoft SharePoint Remote Code Execution Vulnerability | No | No | 8.8 |
CVE-2025-27747 | Microsoft Word Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-29820 | Microsoft Word Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-29822 | Microsoft OneNote Security Feature Bypass Vulnerability | No | No | 7.8 |
CVE-2025-27745 | Microsoft Office Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-27748 | Microsoft Office Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-27749 | Microsoft Office Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-27746 | Microsoft Office Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-26642 | Microsoft Office Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-27744 | Microsoft Office Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27752 | Microsoft Excel Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-29791 | Microsoft Excel Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-27751 | Microsoft Excel Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-27750 | Microsoft Excel Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-29823 | Microsoft Excel Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-29800 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-29801 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-29816 | Microsoft Word Security Feature Bypass Vulnerability | No | No | 7.5 |
CVE-2025-29792 | Microsoft Office Elevation of Privilege Vulnerability | No | No | 7.3 |
CVE-2025-29793 | Microsoft SharePoint Remote Code Execution Vulnerability | No | No | 7.2 |
System Center vulnerabilities
CVE | Title | Exploited? | Publicly disclosed? | CVSSv3 base score |
---|
CVE-2025-27743 | Microsoft System Center Elevation of Privilege Vulnerability | No | No | 7.8 |
Windows vulnerabilities
CVE | Title | Exploited? | Publicly disclosed? | CVSSv3 base score |
---|
CVE-2025-26678 | Windows Defender Application Control Security Feature Bypass Vulnerability | No | No | 8.4 |
CVE-2025-27482 | Windows Remote Desktop Services Remote Code Execution Vulnerability | No | No | 8.1 |
CVE-2025-26639 | Windows USB Print Driver Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-26675 | Windows Subsystem for Linux Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27729 | Windows Shell Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-29811 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-26666 | Windows Media Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-26674 | Windows Media Remote Code Execution Vulnerability | No | No | 7.8 |
CVE-2025-27728 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27739 | Windows Kernel Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27476 | Windows Digital Media Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27467 | Windows Digital Media Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27730 | Windows Digital Media Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-24058 | Windows DWM Core Library Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27490 | Windows Bluetooth Service Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27731 | Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-24074 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-24073 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-24060 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-24062 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-29812 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-29809 | Windows Kerberos Security Feature Bypass Vulnerability | No | No | 7.1 |
CVE-2025-27491 | Windows Hyper-V Remote Code Execution Vulnerability | No | No | 7.1 |
CVE-2025-27475 | Windows Update Stack Elevation of Privilege Vulnerability | No | No | 7 |
CVE-2025-26649 | Windows Secure Channel Elevation of Privilege Vulnerability | No | No | 7 |
CVE-2025-27492 | Windows Secure Channel Elevation of Privilege Vulnerability | No | No | 7 |
CVE-2025-26640 | Windows Digital Media Elevation of Privilege Vulnerability | No | No | 7 |
CVE-2025-26681 | Win32k Elevation of Privilege Vulnerability | No | No | 6.7 |
CVE-2025-26651 | Windows Local Session Manager (LSM) Denial of Service Vulnerability | No | No | 6.5 |
CVE-2025-26635 | Windows Hello Security Feature Bypass Vulnerability | No | No | 6.5 |
CVE-2025-27735 | Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability | No | No | 6 |
CVE-2025-27736 | Windows Power Dependency Coordinator Information Disclosure Vulnerability | No | No | 5.5 |
CVE-2025-29808 | Windows Cryptographic Services Information Disclosure Vulnerability | No | No | 5.5 |
CVE-2025-26644 | Windows Hello Spoofing Vulnerability | No | No | 5.1 |
Windows Azure vulnerabilities
CVE | Title | Exploited? | Publicly disclosed? | CVSSv3 base score |
---|
CVE-2025-29819 | Windows Admin Center in Azure Portal Information Disclosure Vulnerability | No | No | 6.2 |
Windows ESU vulnerabilities
CVE | Title | Exploited? | Publicly disclosed? | CVSSv3 base score |
---|
CVE-2025-27477 | Windows Telephony Service Remote Code Execution Vulnerability | No | No | 8.8 |
CVE-2025-21205 | Windows Telephony Service Remote Code Execution Vulnerability | No | No | 8.8 |
CVE-2025-21221 | Windows Telephony Service Remote Code Execution Vulnerability | No | No | 8.8 |
CVE-2025-21222 | Windows Telephony Service Remote Code Execution Vulnerability | No | No | 8.8 |
CVE-2025-27481 | Windows Telephony Service Remote Code Execution Vulnerability | No | No | 8.8 |
CVE-2025-26669 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | No | No | 8.8 |
CVE-2025-27740 | Active Directory Certificate Services Elevation of Privilege Vulnerability | No | No | 8.8 |
CVE-2025-27737 | Windows Security Zone Mapping Security Feature Bypass Vulnerability | No | No | 8.6 |
CVE-2025-27480 | Windows Remote Desktop Services Remote Code Execution Vulnerability | No | No | 8.1 |
CVE-2025-26671 | Windows Remote Desktop Services Remote Code Execution Vulnerability | No | No | 8.1 |
CVE-2025-26663 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | No | No | 8.1 |
CVE-2025-26647 | Windows Kerberos Elevation of Privilege Vulnerability | No | No | 8.1 |
CVE-2025-26670 | Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability | No | No | 8.1 |
CVE-2025-27487 | Remote Desktop Client Remote Code Execution Vulnerability | No | No | 8 |
CVE-2025-21204 | Windows Process Activation Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-26648 | Windows Kernel Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27727 | Windows Installer Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-29824 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Yes | No | 7.8 |
CVE-2025-26679 | RPC Endpoint Mapper Service Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27741 | NTFS Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27483 | NTFS Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27733 | NTFS Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-26688 | Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | No | No | 7.8 |
CVE-2025-27484 | Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability | No | No | 7.5 |
CVE-2025-26686 | Windows TCP/IP Remote Code Execution Vulnerability | No | No | 7.5 |
CVE-2025-26680 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | No | No | 7.5 |
CVE-2025-27470 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | No | No | 7.5 |
CVE-2025-21174 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | No | No | 7.5 |
CVE-2025-26652 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | No | No | 7.5 |
CVE-2025-27485 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | No | No | 7.5 |
CVE-2025-27486 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | No | No | 7.5 |
CVE-2025-26668 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | No | No | 7.5 |
CVE-2025-26673 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | No | No | 7.5 |
CVE-2025-27469 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | No | No | 7.5 |
CVE-2025-26641 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | No | No | 7.5 |
CVE-2025-27479 | Kerberos Key Distribution Proxy Service Denial of Service Vulnerability | No | No | 7.5 |
CVE-2025-27473 | HTTP.sys Denial of Service Vulnerability | No | No | 7.5 |
CVE-2025-29810 | Active Directory Domain Services Elevation of Privilege Vulnerability | No | No | 7.5 |
CVE-2025-26665 | Windows upnphost.dll Elevation of Privilege Vulnerability | No | No | 7 |
CVE-2025-27478 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | No | No | 7 |
CVE-2025-21191 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | No | No | 7 |
CVE-2025-27732 | Windows Graphics Component Elevation of Privilege Vulnerability | No | No | 7 |
CVE-2025-26637 | BitLocker Security Feature Bypass Vulnerability | No | No | 6.8 |
CVE-2025-26664 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | No | No | 6.5 |
CVE-2025-26667 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | No | No | 6.5 |
CVE-2025-27474 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | No | No | 6.5 |
CVE-2025-21203 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | No | No | 6.5 |
CVE-2025-26672 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | No | No | 6.5 |
CVE-2025-26676 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | No | No | 6.5 |
CVE-2025-27738 | Windows Resilient File System (ReFS) Information Disclosure Vulnerability | No | No | 6.5 |
CVE-2025-21197 | Windows NTFS Information Disclosure Vulnerability | No | No | 6.5 |
CVE-2025-27471 | Microsoft Streaming Service Denial of Service Vulnerability | No | No | 5.9 |
CVE-2025-27742 | NTFS Information Disclosure Vulnerability | No | No | 5.5 |
CVE-2025-27472 | Windows Mark of the Web Security Feature Bypass Vulnerability | No | No | 5.4 |
Windows ESU Microsoft Office vulnerabilities
CVE | Title | Exploited? | Publicly disclosed? | CVSSv3 base score |
---|
CVE-2025-26687 | Win32k Elevation of Privilege Vulnerability | No | No | 7.5 |
NEVER MISS AN EMERGING THREAT
Be the first to learn about the latest vulnerabilities and cybersecurity news.
Subscribe Now