Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
January 2025 Patch Tuesday: 159 Security Fixes and Critical Updates for Windows
Microsoft has released its first Patch Tuesday of 2025, addressing a staggering 159 security vulnerabilities across Windows and related products. This massive update includes 23 critical-rated fixes,...
Microsoft Patches Critical Windows Lua Buffer Over-Read Vulnerability (CVE-2021-45985)
CVE-2021-45985 is a critical heap-based buffer over-read vulnerability affecting the Lua scripting language implementation in certain Windows components. This security flaw, discovered in late 2021,...
Windows Telephony RCE flaw CVE-2025-21409 rated critical, patch now
A newly discovered critical vulnerability in Windows Telephony, tracked as CVE-2025-21409, poses a severe threat to systems running Microsoft Windows. This remote code execution (RCE) flaw could...
Emergency Patch for Critical Windows RCE Flaw CVE-2025-21238 Issued
A newly discovered critical vulnerability in Windows, tracked as CVE-2025-21238, has raised alarms across the cybersecurity community. This flaw, affecting the Windows Telephony Service, could allow...
Windows Emergency Patch Out for Actively Exploited Telephony Service RCE
A newly discovered critical vulnerability in Windows Telephony Service (CVE-2025-21417) exposes systems to remote code execution (RCE) attacks, putting millions of Windows devices at risk. This...
CVE-2025-21311: Critical NTLMv1 Vulnerability Puts Windows Systems at Risk
A newly discovered critical vulnerability in Microsoft's NTLMv1 authentication protocol (CVE-2025-21311) has security experts urging immediate action from Windows administrators worldwide. This flaw,...
Microsoft issues emergency patch for critical CVE-2025-21332 Windows URL zone flaw
A newly discovered critical vulnerability, CVE-2025-21332, has sent shockwaves through the Windows security community. This flaw, affecting the MapUrlToZone function in Windows, could allow attackers...
CVE-2025-21313: Critical SAM Vulnerability Threatens Windows Authentication
Microsoft has disclosed a significant security vulnerability affecting the Windows Security Account Manager (SAM), designated as CVE-2025-21313, which could allow attackers to launch...
New Windows Server Kerberos bug (CVE-2025-21218) enables remote DoS attacks with CVSS 9.1 rating.
The cybersecurity landscape has been shaken by the discovery of CVE-2025-21218, a critical vulnerability in Microsoft's Kerberos implementation that could allow attackers to cause widespread...
Microsoft patches critical Windows CSC flaw granting SYSTEM privileges
Microsoft has disclosed a critical elevation of privilege vulnerability (CVE-2025-21378) affecting the Windows Client Side Caching (CSC) service, posing significant risks to unpatched systems. This...
Microsoft Warns of SYSTEM-Level Access via CVE-2025-21372 in Windows Brokering File System
CVE-2025-21372: Critical Elevation of Privilege Vulnerability in Microsoft Brokering File System Microsoft has disclosed a serious elevation of privilege vulnerability (CVE-2025-21372) affecting the...
CVE-2025-21370: Critical VBS Flaw Lets Attackers Escalate to SYSTEM Access
CVE-2025-21370: Critical VBS Vulnerability Exposes Windows Security Flaws A newly discovered vulnerability, tracked as CVE-2025-21370, has sent shockwaves through the cybersecurity community,...