

Multiple IBM Products Vulnerabilities
January 24, 2025
Multiple Fortinet Products Vulnerabilities
January 24, 2025
Multiple IBM Products Vulnerabilities
January 24, 2025
Multiple Fortinet Products Vulnerabilities
January 24, 2025Severity
High
Analysis Summary
CVE-2025-21296 CVSS:7.5
Microsoft Windows could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free flaw in the BranchCache component.
CVE-2025-21294 CVSS:8.1
Microsoft Windows could allow a remote attacker to execute arbitrary code on the system, caused by a flaw in the Digest Authentication component.
CVE-2025-21291 CVSS:8.8
Microsoft Windows could allow a remote attacker to execute arbitrary code on the system, caused by a double free flaw in the Direct Show component.
CVE-2025-21276 CVSS:7.5
Microsoft Windows is vulnerable to a denial of service, caused by a flaw in the MapUrlToZone component.
CVE-2025-21273 CVSS:8.8
Microsoft Windows could allow a remote attacker to execute arbitrary code on the system, caused by a heap-based buffer overflow in the Telephony Service component.
CVE-2025-21292 CVSS:8.8
Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the Search Service component.
CVE-2025-21224 CVSS:8.1
Microsoft Windows Line Printer Daemon (LPD) Service could allow a remote attacker to execute arbitrary code on the system when winning a race condition.
CVE-2025-21297 CVSS:8.1
Microsoft Windows could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free flaw in the Remote Desktop Services component.
Impact
- Code Execution
Indicators of Compromise
CVE
CVE-2025-21296
CVE-2025-21294
CVE-2025-21291
CVE-2025-21276
CVE-2025-21273
CVE-2025-21292
CVE-2025-21224
CVE-2025-21297
Affected Vendors
Affected Products
- Microsoft Windows Server 2022
- Microsoft Windows 10 Version 1809 - 10.0.17763.0
- Microsoft Windows Server 2019 - 10.0.17763.0
- Microsoft Windows Server 2019 (Server Core installation) - 10.0.17763.0
- Microsoft Windows Server 2022 - 10.0.20348.0
- Microsoft Windows Server 2025 (Server Core installation) - 10.0.26100.0
- Microsoft Windows 11 version 22H3 - 10.0.22631.0
- Microsoft Windows Server 2012 R2 - 6.3.9600.0
- Microsoft Windows Server 2012 R2 (Server Core installation) - 6.3.9600.0
- Microsoft Windows 11 Version 23H2 - 10.0.22631.0
- Microsoft Windows Server 2012 - 6.2.9200.0
- Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation) - 6.1.7601.0
Remediation
Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.