Last updated at Tue, 08 Apr 2025 20:30:03 GMT

Microsoft is addressing 121 vulnerabilities this April 2025 Patch Tuesday, which is more than twice as many as last month. Microsoft has evidence of in-the-wild exploitation for just one of the vulnerabilities published today, which is already reflected in CISA KEV. Once again, Microsoft has published zero-day vulnerabilities on Patch Tuesday without evaluating any of them as critical severity at time of publication, so that’s now a seven month unbroken streak. Today also sees the publication of 11 critical remote code execution (RCE) vulnerabilities. 13 browser vulnerabilities have already been published separately this month, and are not included in the total.

CLFS: zero-day EoP

The Windows Common Log File System (CLFS) Driver is firmly back on our radar today with CVE-2025-29824, a zero-day local elevation of privilege vulnerability. First, the good news: the Acknowledgements section credits the Microsoft Threat Intelligence Center, so the exploit was successfully reproduced by Microsoft; the less-good news is that someone other than Microsoft was first to discover the exploit, because otherwise Microsoft wouldn’t be listing CVE-2025-29824 as exploited in the wild. The advisory does not specify what privilege level is achieved upon successful exploitation, but it’ll be SYSTEM, because that’s the prize for all the other CLFS elevation of privilege zero-day vulnerabilities. As usual, some form of less-privileged local access is a pre-requisite, but attack complexity is low, so this is the sort of vulnerability which goes into any standard break-and-enter toolkit. Given the long history of similar vulnerabilities, it would be more surprising if exploit code wasn’t publicly available in the not-too-distant future. Although December 2024 Patch Tuesday seems as though it must have been a very long time ago, any standard calendar will tell us that only 119 days have elapsed since the last zero-day CLFS local elevation of privilege. Rapid7 discussed the history of CLFS zero-day elevation of privilege vulnerabilities at the time. All versions of Windows receive a patch, except for the venerable LTSC Windows 10 1507, which is listed on the advisory as vulnerable, but left out in the cold with no update; the FAQ says to check back later. Windows 10 LTSC 1507 is scheduled for end of servicing on 2025-10-14, so the clock is ticking regardless.

LDAP Server: critical RCE

Although it has been many months since we’ve seen a critical zero-day vulnerability from Microsoft, there is no shortage of critical remote code execution (RCE) vulnerabilities published today. Defenders responsible for an LDAP server — which means almost any organization with a non-trivial Microsoft footprint — should add patching for CVE-2025-26663 to their to-do list. With no privileges required, no need for user interaction, and code execution presumably in the context of the LDAP server itself, successful exploitation would be an attractive shortcut to any attacker. Anyone wondering if today is a re-run of December 2024 Patch Tuesday can take some small solace in the fact that the worst of the trio of LDAP critical RCEs published at the end of last year was likely easier to exploit than today’s example, since today’s CVE-2025-26663 requires that an attacker win a race condition. Despite that, Microsoft still expects that exploitation is more likely.

LDAP Client: critical RCE

If you breathe a sigh of relief when you see LDAP server critical RCE vulnerabilities like CVE-2025-26663, because you’re certain that you don’t have any Windows LDAP servers in your estate, how about LDAP clients? CVE-2025-26670 describes a critical RCE in the LDAP client, although the FAQ confusingly states that exploitation would require an attacker to “send specially crafted requests to a vulnerable LDAP server”; this seems like it might be a data entry error on the advisory FAQ, so keep an eye out for an update to that section of the advisory. Assuming the rest of the advisory is all present and correct, exploitation requires that the attacker win a race condition, which keeps the attack complexity higher than it otherwise would be. While we wait for clarification, it’s still a critical RCE which Microsoft rates as “exploitation more likely”. On that basis, patching is always recommended.

RDS: critical RCEs

The prolific Windows vulnerability pioneers at Kunlun Lab are credited with a pair of critical RCE vulnerabilities in Windows Remote Desktop Services. Although both CVE-2025-27480 and CVE-2025-27482 share a CVSSv3 base score of 8.1, Microsoft has ranked them both as critical using its own proprietary severity ranking scale. Both vulnerabilities require that an attacker win a race condition. If you’ve ever read Microsoft’s guide to deploying the Remote Desktop Gateway role, you probably have some systems to patch.

Hyper-V: critical RCE

Some Microsoft security advisory FAQs provide a satisfying level of detail, whereas others raise more questions than they answer. CVE-2025-27491 is a Hyper-V critical RCE which falls into the second category, since it states that an attacker must be authenticated — no need for elevated privileges — but also that the attacker must send the user a malicious site and convince them to open it, and it’s not at all clear why authentication would be required in that case. Also unusual: the remediation table on the advisory lists several 32-bit versions of Windows as receiving patches, although Hyper-V requires a 64-bit processor and a 64-bit host OS.

Microsoft lifecycle update

In Microsoft product lifecycle news, Dynamics GP 2015 moves past the end of extended support today. The next batch of significant lifecycle status changes are due in July 2025, when SQL Server 2012 ESU program draws to a close.

Summary charts

A bar chart showing the distribution of vulnerabilities by affected component for Microsoft Patch Tuesday  April 2025.
A bar chart showing the distribution of vulnerabilities by affected component for Microsoft Patch Tuesday April 2025.
Elevated amounts of elevation of privilege
A heatmap showing the distribution of vulnerabilities by impact and affected component for Microsoft Patch Tuesday April 2025.

Summary tables

Apps vulnerabilities

CVE Title Exploited? Publicly disclosed? CVSSv3 base score
CVE-2025-29805 Outlook for Android Information Disclosure Vulnerability No No 7.5

Azure vulnerabilities

CVE Title Exploited? Publicly disclosed? CVSSv3 base score
CVE-2025-27489 Azure Local Elevation of Privilege Vulnerability No No 7.8
CVE-2025-26628 Azure Local Cluster Information Disclosure Vulnerability No No 7.3
CVE-2025-25002 Azure Local Cluster Information Disclosure Vulnerability No No 6.8

Browser vulnerabilities

CVE Title Exploited? Publicly disclosed? CVSSv3 base score
CVE-2025-25000 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability No No 8.8
CVE-2025-29815 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability No No 7.6
CVE-2025-29796 Microsoft Edge for iOS Spoofing Vulnerability No No 4.7
CVE-2025-25001 Microsoft Edge for iOS Spoofing Vulnerability No No 4.3
CVE-2025-3074 Chromium: CVE-2025-3074 Inappropriate implementation in Downloads No No N/A
CVE-2025-3073 Chromium: CVE-2025-3073 Inappropriate implementation in Autofill No No N/A
CVE-2025-3072 Chromium: CVE-2025-3072 Inappropriate implementation in Custom Tabs No No N/A
CVE-2025-3071 Chromium: CVE-2025-3071 Inappropriate implementation in Navigations No No N/A
CVE-2025-3070 Chromium: CVE-2025-3070 Insufficient validation of untrusted input in Extensions No No N/A
CVE-2025-3069 Chromium: CVE-2025-3069 Inappropriate implementation in Extensions No No N/A
CVE-2025-3068 Chromium: CVE-2025-3068 Inappropriate implementation in Intents No No N/A
CVE-2025-3067 Chromium: CVE-2025-3067 Inappropriate implementation in Custom Tabs No No N/A
CVE-2025-3066 Chromium: CVE-2025-3066 Use after free in Navigations No No N/A

Developer Tools vulnerabilities

CVE Title Exploited? Publicly disclosed? CVSSv3 base score
CVE-2025-26682 ASP.NET Core and Visual Studio Denial of Service Vulnerability No No 7.5
CVE-2025-29802 Visual Studio Elevation of Privilege Vulnerability No No 7.3
CVE-2025-29804 Visual Studio Elevation of Privilege Vulnerability No No 7.3
CVE-2025-20570 Visual Studio Code Elevation of Privilege Vulnerability No No 6.8

Developer Tools SQL Server vulnerabilities

CVE Title Exploited? Publicly disclosed? CVSSv3 base score
CVE-2025-29803 Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Privilege Vulnerability No No 7.3

Microsoft Dynamics vulnerabilities

CVE Title Exploited? Publicly disclosed? CVSSv3 base score
CVE-2025-29821 Microsoft Dynamics Business Central Information Disclosure Vulnerability No No 5.5

Microsoft Office vulnerabilities

CVE Title Exploited? Publicly disclosed? CVSSv3 base score
CVE-2025-29794 Microsoft SharePoint Remote Code Execution Vulnerability No No 8.8
CVE-2025-27747 Microsoft Word Remote Code Execution Vulnerability No No 7.8
CVE-2025-29820 Microsoft Word Remote Code Execution Vulnerability No No 7.8
CVE-2025-29822 Microsoft OneNote Security Feature Bypass Vulnerability No No 7.8
CVE-2025-27745 Microsoft Office Remote Code Execution Vulnerability No No 7.8
CVE-2025-27748 Microsoft Office Remote Code Execution Vulnerability No No 7.8
CVE-2025-27749 Microsoft Office Remote Code Execution Vulnerability No No 7.8
CVE-2025-27746 Microsoft Office Remote Code Execution Vulnerability No No 7.8
CVE-2025-26642 Microsoft Office Remote Code Execution Vulnerability No No 7.8
CVE-2025-27744 Microsoft Office Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27752 Microsoft Excel Remote Code Execution Vulnerability No No 7.8
CVE-2025-29791 Microsoft Excel Remote Code Execution Vulnerability No No 7.8
CVE-2025-27751 Microsoft Excel Remote Code Execution Vulnerability No No 7.8
CVE-2025-27750 Microsoft Excel Remote Code Execution Vulnerability No No 7.8
CVE-2025-29823 Microsoft Excel Remote Code Execution Vulnerability No No 7.8
CVE-2025-29800 Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability No No 7.8
CVE-2025-29801 Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability No No 7.8
CVE-2025-29816 Microsoft Word Security Feature Bypass Vulnerability No No 7.5
CVE-2025-29792 Microsoft Office Elevation of Privilege Vulnerability No No 7.3
CVE-2025-29793 Microsoft SharePoint Remote Code Execution Vulnerability No No 7.2

System Center vulnerabilities

CVE Title Exploited? Publicly disclosed? CVSSv3 base score
CVE-2025-27743 Microsoft System Center Elevation of Privilege Vulnerability No No 7.8

Windows vulnerabilities

CVE Title Exploited? Publicly disclosed? CVSSv3 base score
CVE-2025-26678 Windows Defender Application Control Security Feature Bypass Vulnerability No No 8.4
CVE-2025-27482 Windows Remote Desktop Services Remote Code Execution Vulnerability No No 8.1
CVE-2025-26639 Windows USB Print Driver Elevation of Privilege Vulnerability No No 7.8
CVE-2025-26675 Windows Subsystem for Linux Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27729 Windows Shell Remote Code Execution Vulnerability No No 7.8
CVE-2025-29811 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability No No 7.8
CVE-2025-26666 Windows Media Remote Code Execution Vulnerability No No 7.8
CVE-2025-26674 Windows Media Remote Code Execution Vulnerability No No 7.8
CVE-2025-27728 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27739 Windows Kernel Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27476 Windows Digital Media Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27467 Windows Digital Media Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27730 Windows Digital Media Elevation of Privilege Vulnerability No No 7.8
CVE-2025-24058 Windows DWM Core Library Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27490 Windows Bluetooth Service Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27731 Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability No No 7.8
CVE-2025-24074 Microsoft DWM Core Library Elevation of Privilege Vulnerability No No 7.8
CVE-2025-24073 Microsoft DWM Core Library Elevation of Privilege Vulnerability No No 7.8
CVE-2025-24060 Microsoft DWM Core Library Elevation of Privilege Vulnerability No No 7.8
CVE-2025-24062 Microsoft DWM Core Library Elevation of Privilege Vulnerability No No 7.8
CVE-2025-29812 DirectX Graphics Kernel Elevation of Privilege Vulnerability No No 7.8
CVE-2025-29809 Windows Kerberos Security Feature Bypass Vulnerability No No 7.1
CVE-2025-27491 Windows Hyper-V Remote Code Execution Vulnerability No No 7.1
CVE-2025-27475 Windows Update Stack Elevation of Privilege Vulnerability No No 7
CVE-2025-26649 Windows Secure Channel Elevation of Privilege Vulnerability No No 7
CVE-2025-27492 Windows Secure Channel Elevation of Privilege Vulnerability No No 7
CVE-2025-26640 Windows Digital Media Elevation of Privilege Vulnerability No No 7
CVE-2025-26681 Win32k Elevation of Privilege Vulnerability No No 6.7
CVE-2025-26651 Windows Local Session Manager (LSM) Denial of Service Vulnerability No No 6.5
CVE-2025-26635 Windows Hello Security Feature Bypass Vulnerability No No 6.5
CVE-2025-27735 Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability No No 6
CVE-2025-27736 Windows Power Dependency Coordinator Information Disclosure Vulnerability No No 5.5
CVE-2025-29808 Windows Cryptographic Services Information Disclosure Vulnerability No No 5.5
CVE-2025-26644 Windows Hello Spoofing Vulnerability No No 5.1

Windows Azure vulnerabilities

CVE Title Exploited? Publicly disclosed? CVSSv3 base score
CVE-2025-29819 Windows Admin Center in Azure Portal Information Disclosure Vulnerability No No 6.2

Windows ESU vulnerabilities

CVE Title Exploited? Publicly disclosed? CVSSv3 base score
CVE-2025-27477 Windows Telephony Service Remote Code Execution Vulnerability No No 8.8
CVE-2025-21205 Windows Telephony Service Remote Code Execution Vulnerability No No 8.8
CVE-2025-21221 Windows Telephony Service Remote Code Execution Vulnerability No No 8.8
CVE-2025-21222 Windows Telephony Service Remote Code Execution Vulnerability No No 8.8
CVE-2025-27481 Windows Telephony Service Remote Code Execution Vulnerability No No 8.8
CVE-2025-26669 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability No No 8.8
CVE-2025-27740 Active Directory Certificate Services Elevation of Privilege Vulnerability No No 8.8
CVE-2025-27737 Windows Security Zone Mapping Security Feature Bypass Vulnerability No No 8.6
CVE-2025-27480 Windows Remote Desktop Services Remote Code Execution Vulnerability No No 8.1
CVE-2025-26671 Windows Remote Desktop Services Remote Code Execution Vulnerability No No 8.1
CVE-2025-26663 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability No No 8.1
CVE-2025-26647 Windows Kerberos Elevation of Privilege Vulnerability No No 8.1
CVE-2025-26670 Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability No No 8.1
CVE-2025-27487 Remote Desktop Client Remote Code Execution Vulnerability No No 8
CVE-2025-21204 Windows Process Activation Elevation of Privilege Vulnerability No No 7.8
CVE-2025-26648 Windows Kernel Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27727 Windows Installer Elevation of Privilege Vulnerability No No 7.8
CVE-2025-29824 Windows Common Log File System Driver Elevation of Privilege Vulnerability Yes No 7.8
CVE-2025-26679 RPC Endpoint Mapper Service Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27741 NTFS Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27483 NTFS Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27733 NTFS Elevation of Privilege Vulnerability No No 7.8
CVE-2025-26688 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability No No 7.8
CVE-2025-27484 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability No No 7.5
CVE-2025-26686 Windows TCP/IP Remote Code Execution Vulnerability No No 7.5
CVE-2025-26680 Windows Standards-Based Storage Management Service Denial of Service Vulnerability No No 7.5
CVE-2025-27470 Windows Standards-Based Storage Management Service Denial of Service Vulnerability No No 7.5
CVE-2025-21174 Windows Standards-Based Storage Management Service Denial of Service Vulnerability No No 7.5
CVE-2025-26652 Windows Standards-Based Storage Management Service Denial of Service Vulnerability No No 7.5
CVE-2025-27485 Windows Standards-Based Storage Management Service Denial of Service Vulnerability No No 7.5
CVE-2025-27486 Windows Standards-Based Storage Management Service Denial of Service Vulnerability No No 7.5
CVE-2025-26668 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability No No 7.5
CVE-2025-26673 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability No No 7.5
CVE-2025-27469 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability No No 7.5
CVE-2025-26641 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability No No 7.5
CVE-2025-27479 Kerberos Key Distribution Proxy Service Denial of Service Vulnerability No No 7.5
CVE-2025-27473 HTTP.sys Denial of Service Vulnerability No No 7.5
CVE-2025-29810 Active Directory Domain Services Elevation of Privilege Vulnerability No No 7.5
CVE-2025-26665 Windows upnphost.dll Elevation of Privilege Vulnerability No No 7
CVE-2025-27478 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability No No 7
CVE-2025-21191 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability No No 7
CVE-2025-27732 Windows Graphics Component Elevation of Privilege Vulnerability No No 7
CVE-2025-26637 BitLocker Security Feature Bypass Vulnerability No No 6.8
CVE-2025-26664 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability No No 6.5
CVE-2025-26667 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability No No 6.5
CVE-2025-27474 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability No No 6.5
CVE-2025-21203 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability No No 6.5
CVE-2025-26672 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability No No 6.5
CVE-2025-26676 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability No No 6.5
CVE-2025-27738 Windows Resilient File System (ReFS) Information Disclosure Vulnerability No No 6.5
CVE-2025-21197 Windows NTFS Information Disclosure Vulnerability No No 6.5
CVE-2025-27471 Microsoft Streaming Service Denial of Service Vulnerability No No 5.9
CVE-2025-27742 NTFS Information Disclosure Vulnerability No No 5.5
CVE-2025-27472 Windows Mark of the Web Security Feature Bypass Vulnerability No No 5.4

Windows ESU Microsoft Office vulnerabilities

CVE Title Exploited? Publicly disclosed? CVSSv3 base score
CVE-2025-26687 Win32k Elevation of Privilege Vulnerability No No 7.5