Microsoft Patch Tuesday: Six zero-days exploited
Microsoft's March 2025 Patch Tuesday addresses multiple vulnerabilities, including six actively exploited zero-days that could enable system compromise.
Japan's IPA (Information-technology Promotion Agency) has issued an advisory regarding Microsoft's March 2025 Patch Tuesday security updates, released March 12, 2025 (Japan Time). The update bundle addresses multiple vulnerabilities across Microsoft products that, if exploited, could lead to application crashes, system compromise, or attacker-controlled devices.
Microsoft has confirmed active exploitation of six vulnerabilities: CVE-2025-24983, CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, and CVE-2025-26633. IPA warns that these exploited vulnerabilities pose an immediate risk of expanding attacks and urges organizations to apply updates immediately.
The security updates are typically delivered automatically through Windows Update. Organizations with centralized update management should reference Microsoft's monthly security bulletin and expedite deployment. IPA notes that applying updates may require system restarts and directs users to their Security Center for detailed guidance on Windows Update procedures.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2024/0312-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free