Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2025-59192: Critical Windows Storport Vulnerability Requires Immediate Patching
Microsoft has issued an urgent security advisory for CVE-2025-59192, a critical buffer over-read vulnerability in the Windows Storport.sys storage driver that could allow local attackers to escalate...
Critical MapUrlToZone flaw CVE-2025-59208 lets attackers fake URL trust for phishing.
Microsoft's Windows security infrastructure faces a significant vulnerability with CVE-2025-59208, a security feature bypass in the MapUrlToZone URL classification logic that could allow attackers to...
CVE-2025-59203: Windows State Repository Vulnerability Patched - What You Need to Know
Microsoft has addressed a significant security vulnerability in the Windows State Repository API Server that could have allowed attackers to access sensitive file information without proper...
CVE-2025-59253 Windows Search DoS Vulnerability: Complete Patch Guide
Microsoft has addressed a critical local Denial-of-Service vulnerability in Windows Search, designated CVE-2025-59253, through its latest security updates. This vulnerability affects multiple Windows...
CVE-2025-59278: Critical Windows Local Privilege Escalation Vulnerability Patched
Microsoft has urgently addressed a critical local privilege escalation vulnerability designated CVE-2025-59278 that affects multiple Windows operating systems. This security flaw in the Windows...
CVE-2025-59230: Critical RasMan Privilege Escalation Vulnerability in Windows
Microsoft's October 2025 security updates addressed a critical local privilege escalation vulnerability in the Remote Access Connection Manager (RasMan) service, tracked as CVE-2025-59230, that could...
CVE-2025-59244: Critical NTLM Spoofing Vulnerability Threatens Windows Security
Microsoft has confirmed a critical NTLM spoofing vulnerability designated CVE-2025-59244 that could allow attackers to harvest authentication credentials and move laterally through Windows networks....
CVE-2025-59205 grants SYSTEM-level access via Windows Graphics flaw—apply security update now
Microsoft has issued an urgent security advisory for CVE-2025-59205, a critical elevation-of-privilege vulnerability affecting the Windows Graphics Component that could allow attackers to gain...
CVE-2025-59209 Windows Push Notification Vulnerability: Complete Patch Guide
Microsoft has addressed a critical information disclosure vulnerability in Windows Push Notification Core, designated as CVE-2025-59209, that could allow low-privileged local attackers to access...
Deploy May 2025 updates now to fix Windows Search DoS flaw CVE-2025-59198
Microsoft has disclosed a critical denial-of-service vulnerability in Windows Search, designated CVE-2025-59198, that could allow low-privileged local users to crash the Windows Search service and...
CVE-2025-59191: Critical Windows CDPSvc Privilege Escalation Vulnerability
A critical security vulnerability in Windows' Connected Devices Platform Service (CDPSvc) has been identified, posing significant risks to millions of Windows systems worldwide. Designated as...
CVE-2025-59184 Exposes Windows HA Services to Local Data Leakage
Microsoft has disclosed a significant security vulnerability affecting Windows High Availability Services, the critical subsystem that underpins Storage Spaces Direct (S2D) and related clustering...