Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
CSC zero-day CVE-2025-60705 gives SYSTEM access on Windows 10, 11, and Server.
Microsoft has disclosed a critical elevation of privilege vulnerability in the Windows Client-Side Caching (CSC) service, designated as CVE-2025-60705, affecting the Offline Files functionality that...
CVE-2025-62215: Critical Windows Kernel Privilege Escalation Vulnerability Patched
Microsoft has released an urgent security update addressing CVE-2025-62215, a critical Windows kernel vulnerability that enables local privilege escalation attacks. This race condition flaw in the...
CVE-2025-62213: Critical Windows afd.sys Vulnerability Requires Immediate Patching
Microsoft has issued a critical security alert for CVE-2025-62213, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) that enables local privilege...
Windows 11 KB5068865 Update Enforces RFC 9112 HTTP Chunked Parsing Security
Microsoft's November 2025 cumulative update for Windows 11, KB5068865 (OS Build 22621.6199), introduces a critical security enhancement to the HTTP.sys request parser that enforces RFC 9112...
Windows License Manager Log Bug Exposes Secrets – Patch Now to Stop Local Reconnaissance
Microsoft has quietly patched an information disclosure flaw in the Windows License Manager that could hand local attackers a map of your network's secrets—all from reading log files meant for...
Windows License Manager Bug Exposes System Secrets—Patch Issued for CVE-2025-62209
Microsoft has shipped a security fix for CVE‑2025‑62209, a local information‑disclosure vulnerability in the Windows License Manager that could let attackers harvest sensitive system artifacts...
CVE-2025-60724: Critical GDI+ Heap Overflow Threatens Windows Security
Microsoft has issued an urgent security advisory for CVE-2025-60724, a critical remote code execution vulnerability in the Microsoft Graphics Component (GDI+) that represents one of the most severe...
CVE-2025-60718: Critical Windows Admin Protection Vulnerability Explained
Microsoft has disclosed a significant security vulnerability in its Windows Administrator Protection feature that could allow attackers to bypass security controls and gain elevated privileges on...
CVE-2025-60720: Critical Windows TDI TDX Buffer Overread Vulnerability Exposed
A newly discovered high-severity vulnerability in the Windows kernel's Transport Driver Interface (TDI) translation component has security experts urging immediate attention from system...
CVE-2025-60717: Critical Windows Broadcast DVR UAF Vulnerability Threatens Systems
Microsoft has issued a critical security advisory for CVE-2025-60717, a high-impact use-after-free vulnerability in the Windows Broadcast DVR User Service that poses significant risks to Windows...
CVE-2025-59515: Windows Broadcast DVR Service Vulnerability Opens Door to Full System Takeover—Here’s the Fix
Microsoft has released a security update to fix a local privilege escalation vulnerability in the Windows Broadcast DVR User Service that could allow an attacker to gain full control of an unpatched...
Microsoft Patches High-Risk OLE Vulnerability in Windows – Here’s How to Protect Your System
On November 11, 2025, Microsoft released a security update fixing a critical vulnerability in Windows’ Object Linking and Embedding (OLE) component that could let attackers take over a PC just by...