Microsoft has fixed 4 critical vulnerabilities

Microsoft's latest security update fixes 55 vulnerabilities, including four critical zero-day flaws – two of which have been actively used in cyberattacks.

What's known

Among the fixes, 22 vulnerabilities allowed remote code execution, and 19 could allow attackers to gain elevated system privileges. Three of them were classified as “Critical”.

Two «zero-days» that are actively exploited:

  • CVE-2025-21 391 – a flaw in Windows Storage that allows attackers to delete files, which can lead to system failures.
  • CVE-2025-21 418 – vulnerability in Windows Ancillary Function Driver that allows hackers to gain complete access to the system.

Two other zero-days disclosed:

  • CVE-2025-21 194 – a security flaw in Microsoft Surface that could allow attackers to bypass UEFI protection, related to the previous PixieFail vulnerability.
  • CVE-2025-21 377 – NTLM hash substitution bug that could allow hackers to steal credentials when a user interacts with a malicious file.

Microsoft recommends that users update their systems immediately to stay protected.

Natasha Kumar

By Natasha Kumar

Natasha Kumar has been a reporter on the news desk since 2018. Before that she wrote about young adolescence and family dynamics for Styles and was the legal affairs correspondent for the Metro desk. Before joining The Times Hub, Natasha Kumar worked as a staff writer at the Village Voice and a freelancer for Newsday, The Wall Street Journal, GQ and Mirabella. To get in touch, contact me through my natasha@thetimeshub.in 1-800-268-7116