Cybersecurity
The latest Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.
Critical SharePoint Vulnerability CVE-2025-49701: A Deep Dive into Risks and Mitigation
Critical SharePoint Vulnerability CVE-2025-49701: A Deep Dive into Risks and Mitigation A critical remote code execution (RCE) vulnerability, identified as CVE-2025-49701, has been discovered in...
Urgent Patch Now: Microsoft Word CVE-2025-49703 Allows Full System Takeover via Crafted Documents
Microsoft has confirmed a critical remote code execution (RCE) vulnerability in Microsoft Office Word, tracked as CVE-2025-49703, that could hand full system control to attackers who convince users...
CVE-2025-49698: Microsoft Word 'Use-After-Free' Flaw Exposes Millions to Remote Code Execution
Microsoft has released urgent security patches for a critical vulnerability in Word that could allow attackers to hijack entire systems simply by tricking a user into opening a malicious document....
Microsoft Office Hit by Critical Use-After-Free RCE: CVE-2025-49699 Requires Immediate Patching
Microsoft has confirmed a critical remote code execution vulnerability in its Office productivity suite, tracked as CVE-2025-49699, that stems from a use-after-free memory corruption flaw. The...
Microsoft Office RCE Flaw CVE-2025-49696: What 'Remote' Actually Means — and How to Stay Safe
Microsoft has confirmed a critical security vulnerability in its Office suite that could let attackers execute arbitrary code on a victim's machine simply by tricking them into opening a malicious...
Microsoft Office Users on Alert as CVE-2025-49697 Exposes Systems to Code Execution Attacks
A critical remote code execution vulnerability in Microsoft Office, tracked as CVE-2025-49697, has put enterprise and consumer users on high alert, even as official technical details from Microsoft...
CVE-2025-49693: Microsoft Flags 'More Likely' Exploit for Windows EoP Flaw, Urges Immediate Patching
Microsoft has disclosed a critical elevation-of-privilege vulnerability, CVE-2025-49693, that gives authenticated local attackers a path to SYSTEM-level control by exploiting a double-free memory...
CVE-2025-49685: Critical Windows Search Bug Lets Attackers Seize Admin Control—Patch Immediately
Microsoft has disclosed a critical elevation-of-privilege vulnerability in the Windows Search Service that hands local attackers a direct path to administrative control. Tracked as CVE-2025-49685,...
Microsoft Ships Patches for Critical Office RCE Bug CVE-2025-49695, Including Office for Mac
A dangerous use-after-free vulnerability in Microsoft Office, tracked as CVE-2025-49695, has been patched after attackers could potentially execute malicious code just by tricking users into opening...
Microsoft Patches Improper Access Control Flaw in Windows Storage Driver That Exposes Sensitive Data
Microsoft has confirmed and patched a security vulnerability in the Windows Storage Port Driver that could allow attackers with local access to read sensitive information from a targeted system....
CVE-2025-49683: Critical VHDX Vulnerability Exposes Hyper-V and Cloud to RCE Attacks
A newly patched vulnerability in Microsoft's Virtual Hard Disk version 2 (VHDX) subsystem could allow attackers to execute arbitrary code with elevated privileges, posing severe risks to Hyper-V...
Patch Now: Windows Performance Recorder Vulnerability (CVE-2025-49680) Allows Local Denial-of-Service
Microsoft has released a security update to fix a denial-of-service vulnerability in Windows Performance Recorder (WPR) tracked as CVE-2025-49680. The flaw, caused by improper link resolution, could...