Extended Security Updates
The latest Extended Security Updates coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Fixes SQL Server Privilege Escalation Bug: The Real CVE Is 2025-53727, Not 55227
{ "title": "Microsoft Fixes SQL Server Privilege Escalation Bug: The Real CVE Is 2025-53727, Not 55227", "content": "Microsoft has released patches for a critical SQL Server...
Microsoft Fixes High-Impact BitLocker Use-After-Free Vulnerability (CVE-2025-54911)
Microsoft has disclosed a high-severity use-after-free vulnerability in Windows BitLocker, tracked as CVE-2025-54911, that could allow a local attacker to elevate privileges from a standard user...
Excel CVE-2025-54901: Patch Now for Critical Memory Disclosure, Mac Users Wait
Microsoft has released emergency security updates to patch a significant information-disclosure vulnerability in Microsoft Excel, tracked as CVE-2025-54901, that can expose sensitive process memory...
Microsoft’s September 2025 Update for Windows 11 24H2 Fires Urgent Secure Boot Expiration Warning
The September 2025 cumulative update for Windows 11 version 24H2, KB5065426 (OS Build 26100.6584), breaks new ground not for its fixes, but for the urgency of its operational advisory: Microsoft’s...
Windows Defender Firewall Type Confusion Bug Opens Door to SYSTEM-Level Compromise
A severe type confusion vulnerability in the Windows Defender Firewall service, tracked as CVE-2025-54109, could allow an attacker with a low-privilege local account to seize complete SYSTEM control...
Microsoft KB5065426 Patch Stops NDI/OBS Stutter and MSI Missteps for Windows 11 24H2
Microsoft has fixed the aggravating NDI and OBS streaming stutter that plagued content creators for weeks, rolling the remedy into its September 9 cumulative update for Windows 11, version 24H2....
CVE-2025-54093: Windows TCP/IP Race Condition Grants SYSTEM Access – Patch Now
Microsoft has disclosed a local elevation-of-privilege vulnerability in the Windows TCP/IP driver that gives authenticated attackers a clear path to SYSTEM-level control. Tracked as CVE-2025-54093...
No-Reboot PSDirect Fix for Windows 11 Enterprise LTSC 2024 Arrives via Hotpatch KB5066360
Microsoft released a targeted security hotpatch, KB5066360, for Windows 11 Enterprise LTSC 2024 on September 9, 2025, addressing a critical vulnerability in PowerShell Direct (PSDirect) that could...
KB5065431 for Windows 11: Combined SSU/LCU, SMB Auditing, and MSI Repair Fixes
Microsoft’s Patch Tuesday for September 9, 2025 delivers a cumulative security update, KB5065431, for Windows 11 versions 22H2 and 23H2. The update bumps OS builds to 22621.5909 for the feature-off...
Windows HTTP.sys Out-of-Bounds Read Enables Remote DoS — Patch Urgently
A newly referenced vulnerability in the Windows HTTP protocol stack exposes internet-facing servers to remote denial-of-service attacks, forcing administrators to take immediate action even as public...
Microsoft Emergency Patch for RRAS Memory Leak (CVE-2025-53796) — Update Windows VPN Gateways Now
Microsoft has released a critical security update for Windows Routing and Remote Access Service (RRAS) to plug an information disclosure hole that allows attackers to siphon memory contents over the...
Patch Now: Xbox Gaming Services CVE-2024-28916 Lets Low-Privilege Attackers Escalate to SYSTEM
A critical elevation-of-privilege vulnerability in Microsoft’s Xbox Gaming Services component, tracked as CVE-2024-28916, has been patched, but not before a public proof-of-concept demonstrated how...