Kaspersky ID:
KLA81543
Дата обнаружения:
11/03/2025
Обновлено:
13/03/2025

Описание

Multiple vulnerabilities were found in Microsoft Products (Extended Security Update). Malicious users can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions, spoof user interface, gain privileges, obtain sensitive information, cause denial of service.

Below is a complete list of vulnerabilities:

  1. Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
  2. External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
  3. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
  4. Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
  5. Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
  6. Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
  7. Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.
  8. Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.
  9. Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
  10. Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
  11. Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
  12. Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
  13. Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.
  14. Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
  15. Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
  16. Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
  17. Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
  18. An elevation of privilege vulnerability can be exploited remotely to gain privileges.
  19. Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
  20. Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.
  21. Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

Первичный источник обнаружения

Связанные продукты

Список CVE

  • CVE-2024-9157
    unknown
  • CVE-2025-21180
    high
  • CVE-2025-21247
    warning
  • CVE-2025-24035
    high
  • CVE-2025-24044
    high
  • CVE-2025-24045
    high
  • CVE-2025-24051
    high
  • CVE-2025-24054
    high
  • CVE-2025-24055
    warning
  • CVE-2025-24056
    high
  • CVE-2025-24059
    high
  • CVE-2025-24064
    high
  • CVE-2025-24071
    high
  • CVE-2025-24072
    high
  • CVE-2025-24983
    high
  • CVE-2025-24984
    warning
  • CVE-2025-24985
    high
  • CVE-2025-24987
    high
  • CVE-2025-24988
    high
  • CVE-2025-24991
    high
  • CVE-2025-24992
    high
  • CVE-2025-24993
    high
  • CVE-2025-24996
    high
  • CVE-2025-26633
    high
  • CVE-2025-26645
    high

Список KB

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Confirm changes?
Your message has been sent successfully.