Microsoft has released security patches to address multiple vulnerabilities in their software and products.
Microsoft has released security patches to address multiple vulnerabilities in their software and products. The vulnerabilities that have been classified as Critical in severity are listed in the table below. For the full list of security patches released by Microsoft, please refer to
CRITICAL VULNERABILITIES
Microsoft Teams Elevation of Privilege Vulnerability
Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
Azure SQL Database Elevation of Privilege Vulnerability
Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
Azure Service Bus Remote Code Execution Vulnerability
Azure SRE Agent Elevation of Privilege Vulnerability
Azure Active Directory Elevation of Privilege Vulnerability
wifi: nl80211: free RNR data on MBSSID mismatch
wifi: mt76: mt7915: guard HE capability lookups
wifi: cfg80211: validate PMSR FTM preamble range
wifi: cfg80211: bound element ID read when checking non-inheritance
wifi: carl9170: fix buffer overflow in rx_stream failover path
wifi: ath6kl: fix use-after-free in aggr_reset_state()
watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
userfaultfd: prevent registration of special VMAs
tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
super: fix emergency thaw deadlock on frozen block devices
sctp: don't free the ASCONF's own transport in DEL-IP processing
rbd: Reset positive result codes to zero in object map update path
pppoe: reload header pointer after dev_hard_header()
phonet: pep: fix use-after-free in pep_get_sb()
net: slip: serialize receive against buffer reallocation
net/sched: act_tunnel_key: Defer dst_release to RCU callback
net/iucv: fix use-after-free of a severed iucv_path
media: ti: vpe: unwind v4l2 device registration on probe error
media: stm32: dcmi: unregister notifier on probe failure
media: saa7134: Fix a possible memory leak in saa7134_video_init1
media: rtl2832: fix use-after-free in rtl2832_remove()
media: pci: dm1105: Free allocated workqueue
libceph: remove debugfs files before client teardown
iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
iommu/amd: Bound the early ACPI HID map
intel_th: fix MSC output device reference leak
ila: reload IPv6 header after pskb_may_pull in checksum adjust
hwmon: occ: validate poll response sensor blocks
hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
geneve: require CAP_NET_ADMIN in the device netns for changelink
ftrace: Add global mutex to serialize trace_parser access
firewire: net: Fix fragmented datagram reassembly
drop_monitor: fix size calculations for 64-bit attributes
drm/amd/display: set new_stream to NULL after release
drm/amd/display: Fix ISM dc_lock deadlock during suspend
bpf: Fix UAF in sock clone early bailouts
ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
Windows iSCSI Target Service Remote Code Execution Vulnerability
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
Microsoft QUIC Remote Code Execution Vulnerability
Microsoft 365 Admin Center Elevation of Privilege Vulnerability
LoongArch: Move jump_label_init() before parse_early_param()
KVM: nVMX: Hide shadow VMCS right after VMCLEAR
Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
Microsoft Teams Elevation of Privilege Vulnerability
Microsoft Office SharePoint Spoofing Vulnerability
Kata Containers: Config Path Annotation Arbitrary File Loading
Azure Logic Apps Information Disclosure Vulnerability
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Copilot Cowork Elevation of Privilege Vulnerability
ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
Azure Confidential Ledger Remote Code Execution Vulnerability
Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Windows GDI+ Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
Windows DHCP Server Remote Code Execution Vulnerability
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
Azure Entra ID Spoofing Vulnerability
Application Insights Profiler Elevation of Privilege Vulnerability
Azure SQL Managed Instance Elevation of Privilege Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
Windows Key Guard Elevation of Privilege Vulnerability
Windows GDI+ Elevation of Privilege Vulnerability
Microsoft Office Word Remote Code Execution Vulnerability
Microsoft Office Word Remote Code Execution Vulnerability
Microsoft Office Word Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Graphics Component Remote Code Execution Vulnerability
Microsoft Office Graphics Component Remote Code Execution Vulnerability
Microsoft Office Graphics Component Remote Code Execution Vulnerability
Microsoft Office Graphics Component Remote Code Execution Vulnerability
Microsoft Office Graphics Component Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Azure SQL Database Elevation of Privilege Vulnerability
Microsoft Teams Spoofing Vulnerability
Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
