Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Microsoft’s Massive Patch Tuesday Release Is ‘Ominous’ Sign For 2025: Researcher

CRN by CRN
January 16, 2025
Home News
Share on FacebookShare on Twitter


The 159 new CVEs (Common Vulnerabilities and Exposures) is the ‘largest number of CVEs addressed in any single month since at least 2017,’ writes Trend Micro’s Dustin Childs.

Microsoft disclosed updates Tuesday that fix 11 critical vulnerabilities while addressing the largest number of new CVEs (Common Vulnerabilities and Exposures) seen in a monthly patch release in years, according to a Trend Micro researcher.

The tech giant fixed 159 new CVEs as part of its monthly release of software bug fixes, unofficially known as “Patch Tuesday.”

[Related: 10 Major Ransomware Attacks And Data Breaches In 2024]

That quantity of newly disclosed vulnerabilities is “largest number of CVEs addressed in any single month since at least 2017,” wrote Dustin Childs, head of threat awareness for Trend Micro’s Zero Day Initiative, in a post Tuesday.

It’s also “more than double the usual amount of CVEs fixed in January,” Childs said.

Notably, “this comes on the heels of a record number of December patches and could be an ominous sign for patch levels in 2025,” he wrote.

CRN has reached out to Microsoft for comment.

As usual, the patches address vulnerabilities that affect numerous Microsoft product segments including Windows, Office, Azure, Hyper-V, SharePoint Server, .NET, Visual Studio, Remote Desktop Services, BitLocker and the Windows Virtual Trusted Platform Module.

Three of the flaws are listed by Microsoft as having been exploited—all of which are privilege escalation vulnerabilities impacting Windows Hyper-V. The flaws are tracked at CVE-2025-21333, CVE-2025-21334 and CVE-2025-21335.

The vulnerabilities “all have the same description,” Childs wrote. “An authenticated user could use these to execute code with SYSTEM privileges.”

Ultimately, “if you are running Hyper-V, make sure these patches are at the top of your list for testing and deployment,” he wrote.



Source link

Tags: CyberattacksCybersecurityVulnerabilities
CRN

CRN

Next Post
Five HPE GreenLake Game Changers: A Look At Pay-Per-Use Cloud Service Improvements

Five HPE GreenLake Game Changers: A Look At Pay-Per-Use Cloud Service Improvements

Recommended.

AT&T Receives Frost & Sullivan’s 2026 US Public Safety Solutions Company of the Year Recognition for Excellence in Mission-Critical Connectivity

AT&T Receives Frost & Sullivan’s 2026 US Public Safety Solutions Company of the Year Recognition for Excellence in Mission-Critical Connectivity

April 8, 2026
Self-Spreading ‘GlassWorm’ Infects VS Code Extensions in Widespread Supply Chain Attack

Self-Spreading ‘GlassWorm’ Infects VS Code Extensions in Widespread Supply Chain Attack

October 24, 2025

Trending.

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

March 24, 2026
How Ceros Gives Security Teams Visibility and Control in Claude Code

How Ceros Gives Security Teams Visibility and Control in Claude Code

March 19, 2026
Supermicro onthult DCBBS® met nieuwe NVIDIA Vera Rubin NVL72-, HGX Rubin NVL8- en Vera CPU-systemen, ontworpen om de marktintroductietijd van klanten te versnellen

Supermicro onthult DCBBS® met nieuwe NVIDIA Vera Rubin NVL72-, HGX Rubin NVL8- en Vera CPU-systemen, ontworpen om de marktintroductietijd van klanten te versnellen

March 18, 2026
Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers

Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers

April 3, 2026
Openreach Taps Google Cloud AI to Accelerate High-Speed Internet Access and Cut Carbon

Openreach Taps Google Cloud AI to Accelerate High-Speed Internet Access and Cut Carbon

March 25, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio