# Microsoft Patch Tuesday: Six zero-days exploited

Published: 2025-03-11 · Severity: high
Canonical: https://vorant.io/reports/a489e0bc-394b-5032-84d2-50513334c1d5/microsoft-patch-tuesday-six-zero-days-exploited

> Microsoft's March 2025 Patch Tuesday addresses multiple vulnerabilities, including six actively exploited zero-days that could enable system compromise.

Japan's IPA (Information-technology Promotion Agency) has issued an advisory regarding Microsoft's March 2025 Patch Tuesday security updates, released March 12, 2025 (Japan Time). The update bundle addresses multiple vulnerabilities across Microsoft products that, if exploited, could lead to application crashes, system compromise, or attacker-controlled devices.

Microsoft has confirmed active exploitation of six vulnerabilities: CVE-2025-24983, CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, and CVE-2025-26633. IPA warns that these exploited vulnerabilities pose an immediate risk of expanding attacks and urges organizations to apply updates immediately.

The security updates are typically delivered automatically through Windows Update. Organizations with centralized update management should reference Microsoft's monthly security bulletin and expedite deployment. IPA notes that applying updates may require system restarts and directs users to their Security Center for detailed guidance on Windows Update procedures.

## Mentioned in this report

- Vulnerabilities: CVE-2025-24983 (KEV), CVE-2025-24984 (KEV), CVE-2025-24985 (KEV), CVE-2025-24991 (KEV), CVE-2025-24993 (KEV), CVE-2025-26633 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/0312-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a489e0bc-394b-5032-84d2-50513334c1d5/microsoft-patch-tuesday-six-zero-days-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
