# Microsoft Patches Six Actively Exploited Zero-Days

Published: 2025-03-11 · Severity: high
Canonical: https://vorant.io/reports/a489e0bc-394b-5032-84d2-50513334c1d5/microsoft-patches-six-actively-exploited-zero-days

> IPA warns that Microsoft's March 2025 patch Tuesday fixes six actively exploited Windows vulnerabilities, urging immediate updates.

Japan's IPA issued an advisory highlighting Microsoft's March 2025 monthly security updates, which address multiple vulnerabilities across Windows products. Microsoft has confirmed that six of these flaws—CVE-2025-24983, CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, and CVE-2025-26633—are being actively exploited in the wild, raising concerns of increased attacker activity targeting unpatched systems.

Successful exploitation of these vulnerabilities could allow attackers to crash applications, gain elevated privileges, or take control of affected machines. IPA urges both individual users and organizations to apply the security updates immediately via Windows Update, noting that some patches may require a system restart. The advisory does not name any specific threat actor, campaign, or malware associated with the exploitation, focusing instead on the urgency of patch deployment given confirmed active exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2025-24983 (KEV), CVE-2025-24984 (KEV), CVE-2025-24985 (KEV), CVE-2025-24991 (KEV), CVE-2025-24993 (KEV), CVE-2025-26633 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/0312-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a489e0bc-394b-5032-84d2-50513334c1d5/microsoft-patches-six-actively-exploited-zero-days.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
