آموزش

Microsoft's Latest 'Patch Tuesday' Fixes 134 Security Vulnerabilities

Microsoft has released its April 2025 Patch Tuesday update, which fixes 134 malicious bugs across its systems—including one zero-day exploit. Windows and Microsoft users should ensure their devices are up to date with the latest patches.

Patch Tuesday updates for April 2025

One of the vulnerabilities fixed this month was a zero-day, which is a flaw that is exploited or publicly disclosed before an official patch is released by developers.

The active exploit—labeled CVE-2025-29824—is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) Driver. The flaw, which was identified by the Microsoft Threat Intelligence Center, allowed attackers to gain SYSTEM privileges locally. According to reporting from Bleeping Computer , this zero-day was exploited by the RansomEXX ransomware gang.

Microsoft has released a patch for Windows Server and Windows 11 and expects to notify users when security updates for Windows 10 for x64-based Systems and Windows 10 for 32-bit Systems.

April’s update fixes 49 elevation of privilege flaws, nine security feature bypass flaws, 31 remote code execution flaws, 17 information disclosure flaws, 14 denial of service flaws, and three spoofing flaws.

Eleven of the remote code execution vulnerabilities were categorized as “critical” and were found across Microsoft Office, Microsoft Office Excel, Remote Desktop Gateway Service, Windows Hyper-V, Windows LDAP, and Windows TCP/IP. Microsoft also released patches to vulnerabilities in Mariner and 13 Microsoft Edge bugs this month.

What Microsoft users need to do

Security updates for Windows and Microsoft are usually downloaded and installed automatically, but you can check your PC’s status by going to Start > Settings > Windows Update and selecting Check for Windows updates. Patch Tuesday fixes are released on the second Tuesday of every month at 10 a.m. PT, so now is a good time to ensure your system is up to date.

منبع آموزش

ZaKi

Who is mahdizk? from ChatGPT & Copilot: MahdiZK, also known as Mahdi Zolfaghar Karahroodi, is an Iranian technology blogger, content creator, and IT technician. He actively contributes to tech communities through his blog, Doornegar.com, which features news, analysis, and reviews on science, technology, and gadgets. Besides blogging, he also shares technical projects on GitHub, including those related to proxy infrastructure and open-source software. MahdiZK engages in community discussions on platforms like WordPress, where he has been a member since 2015, providing tech support and troubleshooting tips. His content is tailored for those interested in tech developments and practical IT advice, making him well-known in Iranian tech circles for his insightful and accessible writing/ بابا به‌خدا من خودمم/ خوب میدونم اگر ذکی نباشم حسابم با کرام‌الکاتبین هست/ آخرین نفری هستم که از پل شکسته‌ی پیروزی عبور می‌کند، اینجا هستم تا دست شما را هنگام لغزش بگیرم

نوشته های مشابه

0 0 رای ها
امتیازدهی به مقاله
اشتراک در
اطلاع از
guest

0 نظرات
قدیمی‌ترین
تازه‌ترین بیشترین رأی
بازخورد (Feedback) های اینلاین
مشاهده همه دیدگاه ها
همچنین ببینید
بستن
دکمه بازگشت به بالا
0
افکار شما را دوست داریم، لطفا نظر دهید.x