Microsoft has released its February 2025 Patch Tuesday updates, addressing 55 security vulnerabilities, including four zero-day flaws, with two actively exploited in real-world attacks.

This month’s patch also fixes three critical remote code execution (RCE) vulnerabilities, making them among the most severe issues addressed.

Here’s a breakdown of the patched vulnerabilities:

  • 19 Elevation of Privilege flaws
  • 2 Security Feature Bypass flaws
  • 22 Remote Code Execution flaws
  • 1 Information Disclosure flaw
  • 9 Denial of Service flaws
  • 3 Spoofing flaws

These figures do not include an additional critical Microsoft Dynamics 365 Sales elevation of privilege vulnerability or 10 Microsoft Edge vulnerabilities, which were patched separately on February 6.

READ
CISA Warns Medusa Ransomware Has Hit Over 300 Critical Infrastructure Organizations