• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

Microsoft Patch Tuesday, September 2025 Version – Krebs on Safety

Admin by Admin
September 10, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Microsoft Corp. at this time issued safety updates to repair greater than 80 vulnerabilities in its Home windows working techniques and software program. There are not any identified “zero-day” or actively exploited vulnerabilities on this month’s bundle from Redmond, which however contains patches for 13 flaws that earned Microsoft’s most-dire “vital” label. In the meantime, each Apple and Google not too long ago launched updates to repair zero-day bugs of their units.

Microsoft assigns safety flaws a “vital” score when malware or miscreants can exploit them to achieve distant entry to a Home windows system with little or no assist from customers. Among the many extra regarding vital bugs quashed this month is CVE-2025-54918. The issue right here resides with Home windows NTLM, or NT LAN Supervisor, a set of code for managing authentication in a Home windows community surroundings.

Redmond charges this flaw as “Exploitation Extra Seemingly,” and though it’s listed as a privilege escalation vulnerability, Kev Breen at Immersive says this one is definitely exploitable over the community or the Web.

“From Microsoft’s restricted description, it seems that if an attacker is ready to ship specifically crafted packets over the community to the goal machine, they’d have the power to achieve SYSTEM-level privileges on the goal machine,” Breen mentioned. “The patch notes for this vulnerability state that ‘Improper authentication in Home windows NTLM permits a licensed attacker to raise privileges over a community,’ suggesting an attacker could already must have entry to the NTLM hash or the consumer’s credentials.”

Breen mentioned one other patch — CVE-2025-55234, a 8.8 CVSS-scored flaw affecting the Home windows SMB shopper for sharing information throughout a community — is also listed as privilege escalation bug however is likewise remotely exploitable. This vulnerability was publicly disclosed previous to this month.

“Microsoft says that an attacker with community entry would be capable to carry out a replay assault in opposition to a goal host, which may consequence within the attacker gaining extra privileges, which may result in code execution,” Breen famous.

CVE-2025-54916 is an “vital” vulnerability in Home windows NTFS — the default filesystem for all fashionable variations of Home windows — that may result in distant code execution. Microsoft likewise thinks we’re greater than prone to see exploitation of this bug quickly: The final time Microsoft patched an NTFS bug was in March 2025 and it was already being exploited within the wild as a zero-day.

“Whereas the title of the CVE says ‘Distant Code Execution,’ this exploit is just not remotely exploitable over the community, however as a substitute wants an attacker to both have the power to run code on the host or to persuade a consumer to run a file that will set off the exploit,” Breen mentioned. “That is generally seen in social engineering assaults, the place they ship the consumer a file to open as an attachment or a hyperlink to a file to obtain and run.”

Essential and distant code execution bugs are likely to steal all of the limelight, however Tenable Senior Workers Analysis Engineer Satnam Narang notes that almost half of all vulnerabilities fastened by Microsoft this month are privilege escalation flaws that require an attacker to have gained entry to a goal system first earlier than making an attempt to raise privileges.

“For the third time this yr, Microsoft patched extra elevation of privilege vulnerabilities than distant code execution flaws,” Narang noticed.

On Sept. 3, Google fastened two flaws that had been detected as exploited in zero-day assaults, together with CVE-2025-38352, an elevation of privilege within the Android kernel, and CVE-2025-48543, additionally an elevation of privilege drawback within the Android Runtime element.

Additionally, Apple not too long ago patched its seventh zero-day (CVE-2025-43300) of this yr. It was a part of an exploit chain used together with a vulnerability within the WhatsApp (CVE-2025-55177) instantaneous messenger to hack Apple units. Amnesty Worldwide stories that the 2 zero-days have been utilized in “a complicated spy ware marketing campaign” over the previous 90 days. The difficulty is fastened in iOS 18.6.2, iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, and macOS Ventura 13.7.8.

The SANS Web Storm Heart has a clickable breakdown of every particular person repair from Microsoft, listed by severity and CVSS rating. Enterprise Home windows admins concerned in testing patches earlier than rolling them out ought to regulate askwoody.com, which frequently has the thin on wonky updates.

AskWoody additionally reminds us that we’re now simply two months out from Microsoft discontinuing free safety updates for Home windows 10 computer systems. For these considering safely extending the lifespan and usefulness of those older machines, take a look at final month’s Patch Tuesday protection for just a few pointers.

As ever, please don’t neglect to again up your knowledge (if not your total system) at common intervals, and be happy to hold forth within the feedback for those who expertise issues putting in any of those fixes.

Tags: EditionKrebsMicrosoftPatchSecuritySeptemberTuesday
Admin

Admin

Next Post
I Reviewed 8 Finest Applicant Monitoring Programs for 2025

I Reviewed 8 Finest Applicant Monitoring Programs for 2025

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

High 10 Greatest Cloud Penetration Testing Firms in 2025

High 10 Greatest Cloud Penetration Testing Firms in 2025

September 11, 2025
iPhone 17 Air leak may need revealed the mannequin’s largest flaw

iPhone 17 Air leak may need revealed the mannequin’s largest flaw

July 19, 2025

Trending.

The right way to Defeat Imagawa Tomeji

The right way to Defeat Imagawa Tomeji

September 28, 2025
How you can open the Antechamber and all lever places in Blue Prince

How you can open the Antechamber and all lever places in Blue Prince

April 14, 2025
Satellite tv for pc Navigation Methods Going through Rising Jamming and Spoofing Assaults

Satellite tv for pc Navigation Methods Going through Rising Jamming and Spoofing Assaults

March 26, 2025
Exporting a Material Simulation from Blender to an Interactive Three.js Scene

Exporting a Material Simulation from Blender to an Interactive Three.js Scene

August 20, 2025
AI Girlfriend Chatbots With No Filter: 9 Unfiltered Digital Companions

AI Girlfriend Chatbots With No Filter: 9 Unfiltered Digital Companions

May 18, 2025

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

The philosophical puzzle of rational synthetic intelligence | MIT Information

The philosophical puzzle of rational synthetic intelligence | MIT Information

January 31, 2026
6 Finest Recruiting Automation Instruments I Evaluated for 2026

6 Finest Recruiting Automation Instruments I Evaluated for 2026

January 31, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved