Microsoft Patches Six Actively Exploited Zero-Days
IPA warns that Microsoft's March 2025 patch Tuesday fixes six actively exploited Windows vulnerabilities, urging immediate updates.
Japan's IPA issued an advisory highlighting Microsoft's March 2025 monthly security updates, which address multiple vulnerabilities across Windows products. Microsoft has confirmed that six of these flaws—CVE-2025-24983, CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, and CVE-2025-26633—are being actively exploited in the wild, raising concerns of increased attacker activity targeting unpatched systems.
Successful exploitation of these vulnerabilities could allow attackers to crash applications, gain elevated privileges, or take control of affected machines. IPA urges both individual users and organizations to apply the security updates immediately via Windows Update, noting that some patches may require a system restart. The advisory does not name any specific threat actor, campaign, or malware associated with the exploitation, focusing instead on the urgency of patch deployment given confirmed active exploitation.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2024/0312-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free