Patch Tuesday Archive
Patch Tuesday March 2025
Total CVEs
65
Critical
10
Important
54
Exploited
6
Publicly Disclosed
1
All CVEs this month 65
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2025-24035 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop Services | - | - | - |
| CVE-2025-24044 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32 Kernel Subsystem | - | - | - |
| CVE-2025-24043 | WinDbg Remote Code Execution Vulnerability | Important | 7.5 |
.NET | - | - | - |
| CVE-2025-24057 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2025-24070 | ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability | Important | 7 |
ASP.NET Core & Visual Studio | - | - | - |
| CVE-2025-24077 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2025-24078 | Microsoft Word Remote Code Execution Vulnerability | Important | 7 |
Microsoft Office Word | - | - | - |
| CVE-2025-24079 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2025-24080 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2025-24081 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2025-24082 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2025-24083 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2025-24986 | Azure Promptflow Remote Code Execution Vulnerability | Important | 6.5 |
Azure PromptFlow | - | - | - |
| CVE-2025-24987 | Windows USB Video Class System Driver Elevation of Privilege Vulnerability | Important | 6.8 |
Windows USB Video Driver | - | - | - |
| CVE-2025-24988 | Windows USB Video Class System Driver Elevation of Privilege Vulnerability | Important | 6.8 |
Windows USB Video Driver | - | - | - |
| CVE-2025-21180 | Windows exFAT File System Remote Code Execution Vulnerability | Important | 7.8 |
Windows exFAT File System | - | - | - |
| CVE-2025-24995 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Kernel Streaming WOW Thunk Service Driver | - | - | - |
| CVE-2025-24996 | NTLM Hash Disclosure Spoofing Vulnerability | Important | 6.5 |
Windows NTLM | - | - | - |
| CVE-2025-24997 | DirectX Graphics Kernel File Denial of Service Vulnerability | Important | 4.4 |
Windows Kernel Memory | - | - | - |
| CVE-2025-24998 | Visual Studio Elevation of Privilege Vulnerability | Important | 7.3 |
Visual Studio | - | - | - |
| CVE-2025-25003 | Visual Studio Elevation of Privilege Vulnerability | Important | 7.3 |
Visual Studio | - | - | - |
| CVE-2025-25008 | Windows Server Elevation of Privilege Vulnerability | Important | 7.1 |
Microsoft Windows | - | - | - |
| CVE-2025-29807 | Microsoft Dataverse Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Dataverse | - | - | - |
| CVE-2025-29814 | Microsoft Partner Center Elevation of Privilege Vulnerability | Critical | 8.8 |
Microsoft Partner Center | - | - | - |
| CVE-2025-29806 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Important | 6.5 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2025-26683 | Azure Playwright Elevation of Privilege Vulnerability | Critical | 9.8 |
Azure Playwright | - | - | - |
| CVE-2025-21384 | Azure Health Bot Elevation of Privilege Vulnerability | Critical | 8.8 |
Azure Health Bot | - | - | - |
| CVE-2025-21247 | MapUrlToZone Security Feature Bypass Vulnerability | Important | 4.3 |
Windows MapUrlToZone | - | - | - |
| CVE-2025-21199 | Azure Agent Installer for Backup and Site Recovery Elevation of Privilege Vulnerability | Important | 6.7 |
Azure Agent Installer | - | - | - |
| CVE-2025-24045 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop Services | - | - | - |
| CVE-2025-24046 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Streaming Service | - | - | - |
| CVE-2025-24048 | Windows Hyper-V Elevation of Privilege Vulnerability | Important | 7.8 |
Role: Windows Hyper-V | - | - | - |
| CVE-2025-24050 | Windows Hyper-V Elevation of Privilege Vulnerability | Important | 7.8 |
Role: Windows Hyper-V | - | - | - |
| CVE-2025-24051 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2025-24054 | NTLM Hash Disclosure Spoofing Vulnerability | Important | 5.4 |
Windows NTLM | - | - | - |
| CVE-2025-24055 | Windows USB Video Class System Driver Information Disclosure Vulnerability | Important | 4.3 |
Windows USB Video Driver | - | - | - |
| CVE-2025-24056 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Server | - | - | - |
| CVE-2025-24059 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2025-24061 | Windows Mark of the Web Security Feature Bypass Vulnerability | Important | 7.8 |
Windows Mark of the Web (MOTW) | - | - | - |
| CVE-2025-24064 | Windows Domain Name Service Remote Code Execution Vulnerability | Critical | 8.1 |
Role: DNS Server | - | - | - |
| CVE-2025-24066 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2025-24067 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Streaming Service | - | - | - |
| CVE-2025-24071 | Microsoft Windows File Explorer Spoofing Vulnerability | Important | 6.5 |
Windows File Explorer | - | - | - |
| CVE-2025-24072 | Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Local Security Authority Server (lsasrv) | - | - | - |
| CVE-2025-24075 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2025-24076 | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability | Important | 7.3 |
Windows Cross Device Service | - | - | - |
| CVE-2025-24084 | Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability | Critical | 8.4 |
Windows Subsystem for Linux | - | - | - |
| CVE-2025-24983 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | Important | 7 |
Windows Win32 Kernel Subsystem | Yes | - | - |
| CVE-2025-24984 | Windows NTFS Information Disclosure Vulnerability | Important | 4.6 |
Windows NTFS | Yes | - | - |
| CVE-2025-24985 | Windows Fast FAT File System Driver Remote Code Execution Vulnerability | Important | 7.8 |
Windows Fast FAT Driver | Yes | - | Yes |
| CVE-2025-24991 | Windows NTFS Information Disclosure Vulnerability | Important | 5.5 |
Windows NTFS | Yes | - | - |
| CVE-2025-24992 | Windows NTFS Information Disclosure Vulnerability | Important | 5.5 |
Windows NTFS | - | - | - |
| CVE-2025-24993 | Windows NTFS Remote Code Execution Vulnerability | Important | 7.8 |
Windows NTFS | Yes | - | - |
| CVE-2025-24994 | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability | Important | 7.3 |
Windows Cross Device Service | - | - | - |
| CVE-2025-24049 | Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability | Important | 8.4 |
Azure CLI | - | - | - |
| CVE-2025-26627 | Azure Arc Installer Elevation of Privilege Vulnerability | Important | 7 |
Azure Arc | - | - | - |
| CVE-2025-26630 | Microsoft Access Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Access | - | Yes | - |
| CVE-2025-26631 | Visual Studio Code Elevation of Privilege Vulnerability | Important | 7.3 |
Visual Studio Code | - | - | - |
| CVE-2025-26633 | Microsoft Management Console Security Feature Bypass Vulnerability | Important | 7 |
Microsoft Management Console | Yes | - | - |
| CVE-2025-26643 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 5.4 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2025-26645 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 8.8 |
Remote Desktop Client | - | - | - |
| CVE-2025-26634 | Windows Core Messaging Elevation of Privileges Vulnerability | Important | 7.5 |
Windows Core Messaging | - | - | - |
| CVE-2025-24053 | Microsoft Dataverse Elevation of Privilege Vulnerability | Critical | 7.2 |
Microsoft Dataverse | - | - | - |
| CVE-2025-29795 | Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2025-26629 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 28 | 4 |
| Remote Code Execution | 25 | 6 |
| Information Disclosure | 4 | - |
| Spoofing | 4 | - |
| Security Feature Bypass | 3 | - |
| Denial of Service | 1 | - |
Affected Products 43
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Office | 4 | - |
| Windows NTFS | 4 | 3 |
| Microsoft Edge (Chromium-based) | 3 | - |
| Microsoft Office Excel | 3 | - |
| Microsoft Office Word | 3 | - |
| Windows USB Video Driver | 3 | - |
| Microsoft Dataverse | 2 | - |
| Microsoft Streaming Service | 2 | - |
| Role: Windows Hyper-V | 2 | - |
| Visual Studio | 2 | - |
| Windows Cross Device Service | 2 | - |
| Windows NTLM | 2 | - |
| Windows Remote Desktop Services | 2 | - |
| Windows Win32 Kernel Subsystem | 2 | 1 |
| .NET | 1 | - |
| ASP.NET Core & Visual Studio | 1 | - |
| Azure Agent Installer | 1 | - |
| Azure Arc | 1 | - |
| Azure CLI | 1 | - |
| Azure Health Bot | 1 | - |
| Azure Playwright | 1 | - |
| Azure PromptFlow | 1 | - |
| Kernel Streaming WOW Thunk Service Driver | 1 | - |
| Microsoft Local Security Authority Server (lsasrv) | 1 | - |
| Microsoft Management Console | 1 | 1 |
| Microsoft Office Access | 1 | - |
| Microsoft Partner Center | 1 | - |
| Microsoft Windows | 1 | - |
| Remote Desktop Client | 1 | - |
| Role: DNS Server | 1 | - |
| Visual Studio Code | 1 | - |
| Windows Common Log File System Driver | 1 | - |
| Windows Core Messaging | 1 | - |
| Windows Fast FAT Driver | 1 | 1 |
| Windows File Explorer | 1 | - |
| Windows Kernel Memory | 1 | - |
| Windows Kernel-Mode Drivers | 1 | - |
| Windows MapUrlToZone | 1 | - |
| Windows Mark of the Web (MOTW) | 1 | - |
| Windows Routing and Remote Access Service (RRAS) | 1 | - |
| Windows Subsystem for Linux | 1 | - |
| Windows Telephony Server | 1 | - |
| Windows exFAT File System | 1 | - |