CVE-2025-29824
published 2025-04-08CVE-2025-29824: Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
PriorityP188high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2025-04-29
Exploited in the wild
EPSS
13.48%
96.0th percentile
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20978 | 10.0.10240.20978 |
| microsoft | windows_10_1607 | < 10.0.14393.7969 | 10.0.14393.7969 |
| microsoft | windows_10_1809 | < 10.0.17763.7136 | 10.0.17763.7136 |
| microsoft | windows_10_21h2 | < 10.0.19044.5737 | 10.0.19044.5737 |
| microsoft | windows_10_22h2 | < 10.0.19045.5737 | 10.0.19045.5737 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20978 | 10.0.10240.20978 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7969 | 10.0.14393.7969 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.7136 | 10.0.17763.7136 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.5737 | 10.0.19044.5737 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.5737 | 10.0.19045.5737 |
| microsoft | windows_11_22h2 | < 10.0.22621.5189 | 10.0.22621.5189 |
| microsoft | windows_11_23h2 | < 10.0.22631.5189 | 10.0.22631.5189 |
| microsoft | windows_11_24h2 | < 10.0.26100.3775 | 10.0.26100.3775 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.5189 | 10.0.22621.5189 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.5189 | 10.0.22631.5189 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.5189 | 10.0.22631.5189 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.3775 | 10.0.26100.3775 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27670 | 6.1.7601.27670 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.23220 | 6.0.6003.23220 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25423 | 6.2.9200.25423 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22523 | 6.3.9600.22523 |
| microsoft | windows_server_2016 | < 10.0.14393.7969 | 10.0.14393.7969 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.7969 | 10.0.14393.7969 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_oracle9.8CRITICAL
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Common Log File System Driver Elevation of Privilege Vulnerability
vendor_msrc·2025-04-08·CVSS 7.8
CVE-2025-29824 [HIGH] CWE-416 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Description: Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
FAQ: Are the updates for Windows 10 for x64-based Systems and Windows 10 for 32-bit Systems currently available?
Yes. As of April 9, 2025, the security update (5055547) for Windows 10 for x64-based Systems and Windows 10 for 32-bit Systems are available. Customers running Windows 10 should ensure the update is installed to be protected from this vulnerability.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Common Log File System Driver: Wi
CISA
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
cisa·2025-04-08·CVSS 7.8
CVE-2025-29824 [HIGH] CWE-416 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Vulnerability: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Affected: Microsoft Windows
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-29824 ; https://nvd.nist.gov/vuln/detail/CVE-2025-29824
Remediation Due Date: 2025-04-29
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (SciPy) — CVE-2023-29824
vendor_oracle·2025-01-15·CVSS 9.8
CVE-2023-29824 [CRITICAL] Oracle Oracle Analytics Risk Matrix: Analytics Server (SciPy) — CVE-2023-29824
Oracle Oracle Analytics Risk Matrix: Analytics Server (SciPy) vulnerability
CVE: CVE-2023-29824
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
GHSA
GHSA-74mq-6c57-fxpx: Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally
ghsa_unreviewed·2025-04-08
CVE-2025-29824 [HIGH] CWE-416 GHSA-74mq-6c57-fxpx: Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
VulnCheck
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
vulncheck·2025·CVSS 7.8
CVE-2025-29824 [HIGH] CWE-416 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2025-Apr; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-29824; https://www.cisa.gov/sites/default/files/feeds/known_exploit
No detection rules found.
No public exploits indexed.
Bleepingcomputer
The Exploit Doesn't Exist. You Can Still Prove It Works Against You
blogs_bleepingcomputer·2026-06-23
CVE-2025-29824 The Exploit Doesn't Exist. You Can Still Prove It Works Against You
## The Exploit Doesn't Exist. You Can Still Prove It Works Against You
## Picus Security
For thirty years, vulnerability management has run on what now looks like an impossible luxury: a buffer of months between when a vulnerability was found and when someone could figure out how to weaponize it. Triage by severity, schedule the fix, validate, move on.
That generous buffer is what made the entire system work.
AI has stripped out the manual drag that kept weaponization slow. Reading the advisory, finding the path, shaping the chain, testing what works: none of it can afford to move at human speed anymore. Today, the disclosure-to-exploit timeframes run in hours, not months.
The Zero Day Clock , which tracks this in real time, currently averages around 8 hours for 2026 , down from rough
Greynoiseio
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
blogs_greynoiseio·2026-02-02
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Tenable
Patch Tuesday 2025 Year In Review
blogs_tenable·2025-12-10
Patch Tuesday 2025 Year In Review
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
IT threat evolution in Q2 2025. Non-mobile statistics
blogs_securelist·2025-09-05
IT threat evolution in Q2 2025. Non-mobile statistics
Table of Contents
The quarter in numbers
Ransomware
Quarterly trends and highlights
Law enforcement success
Vulnerabilities and attacks
Mass exploitation of a vulnerability in SAP NetWeaver
Attacks via the SimpleHelp remote administration tool
Qilin exploits vulnerabilities in Fortinet
Exploitation of a Windows CLFS vulnerability
The most prolific groups
Number of new variants
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 countries and territories attacked by ransomware Trojans
TOP 10 most common families of ransomware Trojans
Miners
Number of new variants
Number of users attacked by miners
Geography of attacked users
TOP 10 countries and territories attacked by miners
Attacks on macOS
TOP 20 threats to macOS
Geography of threats t
Securelist
Desktop and IoT threat report for Q2 2025
blogs_securelist·2025-09-05
Desktop and IoT threat report for Q2 2025
Table of Contents
- The quarter in numbers
- Ransomware
- Miners
- Attacks on macOS
- IoT threat statistics
- Attacks via web resources
- Local threats
Authors
- AMR
IT threat evolution in Q2 2025. Non-mobile statistics
IT threat evolution in Q2 2025. Mobile statistics
The statistics in this report are based on detection verdicts returned by Kaspersky products unless otherwise stated. The information was provided by Kaspersky users who consented to sharing statistical data.
## The quarter in numbers
In Q2 2025:
- Kaspersky solutions blocked more than 471 million attacks originating from various online resources.
- Web Anti-Virus detected 77 million unique links.
- File Anti-Virus blocked nearly 23 million malicious and potentially unwanted objects.
- There were 1,702 new ransomwar
Securelist
PipeMagic in 2025: How the backdoor operators’ tactics have changed
blogs_securelist·2025-08-18·CVSS 8.8
CVE-2025-29824 [HIGH] PipeMagic in 2025: How the backdoor operators’ tactics have changed
Table of Contents
- Background
- PipeMagic in 2025
- Deployed PE
- Discovered modules
- Post-exploitation
- Takeaways
- IoCs
Authors
- Sergey Lozhkin
- Leonid Bezvershenko
- Kirill Korchemny
- Ilya Savelyev
In April 2025, Microsoft patched 121 vulnerabilities in its products. According to the company, only one of them was being used in real-world attacks at the time the patch was released: CVE-2025-29824. The exploit for this vulnerability was executed by the PipeMagic malware, which we first discovered in December 2022 in a RansomExx ransomware campaign. In September 2024, we encountered it again in attacks on organizations in the Middle East. Notably, it was the same version of PipeMagic as in 2022. We continue to track the malware’s activity. Most recently, in 2025 our solutions pr
Securelist
Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824
blogs_securelist·2025-08-18·CVSS 8.8
[HIGH] Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824
Table of Contents
Background
PipeMagic in 2025
Initial loader
Loader (ChatGPT)
Loader using DLL hijacking
Deployed PE
Discovered modules
Asynchronous communication module
Loader
Injector
Post-exploitation
Takeaways
IoCs
Authors
Sergey Lozhkin
Leonid Bezvershenko
Kirill Korchemny
Ilya Savelyev
In April 2025, Microsoft patched 121 vulnerabilities in its products. According to the company, only one of them was being used in real-world attacks at the time the patch was released: CVE-2025-29824. The exploit for this vulnerability was executed by the PipeMagic malware, which we first discovered in December 2022 in a RansomExx ransomware campaign. In September 2024, we encountered it again in attacks on organizations in the Middle East. Notably, it was the same version of PipeM
Tenable
Microsoft’s June 2025 Patch Tuesday Addresses 65 CVEs (CVE-2025-33053)
blogs_tenable·2025-06-10·CVSS 8.8
[HIGH] Microsoft’s June 2025 Patch Tuesday Addresses 65 CVEs (CVE-2025-33053)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Ransomware gangs join ongoing SAP NetWeaver attacks
blogs_bleepingcomputer·2025-05-14·CVSS 7.8
CVE-2025-31324 [HIGH] Ransomware gangs join ongoing SAP NetWeaver attacks
## Ransomware gangs join ongoing SAP NetWeaver attacks
## Sergiu Gatlan
Ransomware gangs have joined ongoing SAP NetWeaver attacks, exploiting a maximum-severity vulnerability that allows threat actors to gain remote code execution on vulnerable servers.
SAP released emergency patches on April 24 to address this NetWeaver Visual Composer unauthenticated file upload security flaw ( CVE-2025-31324 ), days after it was first tagged by cybersecurity company ReliaQuest as targeted in the wild.
Successful exploitation lets threat actors upload malicious files without requiring login credentials, potentially leading to complete system compromise.
Today, in an update to their original advisory, ReliaQuest revealed that the RansomEXX and BianLian ransomware operations have also joined these at
Tenable
Microsoft’s May 2025 Patch Tuesday Addresses 71 CVEs (CVE-2025-32701, CVE-2025-32706, CVE-2025-30400)
blogs_tenable·2025-05-13·CVSS 7.8
[HIGH] Microsoft’s May 2025 Patch Tuesday Addresses 71 CVEs (CVE-2025-32701, CVE-2025-32706, CVE-2025-30400)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Play ransomware exploited Windows logging flaw in zero-day attacks
blogs_bleepingcomputer·2025-05-07·CVSS 7.8
CVE-2025-29824 [HIGH] Play ransomware exploited Windows logging flaw in zero-day attacks
## Play ransomware exploited Windows logging flaw in zero-day attacks
## Sergiu Gatlan
Microsoft linked these attacks to the RansomEXX ransomware gang, saying the attackers installed the PipeMagic backdoor malware, which was used to drop the CVE-2025-29824 exploit, deploy ransomware payloads, and ransom notes after encrypting files.
Since then, Symantec's Threat Hunter Team has also found evidence linking them to the Play ransomware-as-a-service operation, saying the attackers deployed a CVE-2025-29824 zero-day privilege escalation exploit after breaching a U.S. organization's network.
"Although no ransomware payload was deployed in the intrusion, the attackers deployed the Grixba infostealer, which is a custom tool associated with Balloonfly, the attackers behind the Play ransomware o
Qualys
Zero-Day Vulnerability Protection | Detect & Stop Threats | Qualys
blogs_qualys·2025-04-18
Zero-Day Vulnerability Protection | Detect & Stop Threats | Qualys
## Table of Contents
Why Zero-Day Vulnerabilities Demand a New Security Mindset
Understanding Zero-Day Vulnerabilities, Exploits, and Attacks
How Do Zero-Day Attacks Work?
The Zero-Day Lifecycle: From Discovery to Exploitation
Real-World Zero-Day Attacks and Their Impact
Why Zero-Day Vulnerabilities Are So Dangerous
Detecting Zero-Day Vulnerabilities
Challenges in Identifying Zero-Day Vulnerabilities
How Qualys Helps Organizations Manage Zero-Day Risk
Conclusion
Frequently Asked Questions (FAQs)
Executive Summary
Zero-day vulnerabilities pose a significant and growing risk as opportunistic attackers rapidly exploit unknown flaws before fixes are available. These threats can bypass traditional defenses, spread rapidly, and cause widespread disruption across organizations.
To r
Qualys
Zero-Day Vulnerability Protection | Detect & Stop Threats | Qualys
blogs_qualys·2025-04-18
Zero-Day Vulnerability Protection | Detect & Stop Threats | Qualys
#### Table of Contents
- Why Zero-Day Vulnerabilities Demand a New Security Mindset
- Understanding Zero-Day Vulnerabilities, Exploits, and Attacks
- How Do Zero-Day Attacks Work?
- The Zero-Day Lifecycle: From Discovery to Exploitation
- Real-World Zero-Day Attacks and Their Impact
- Why Zero-Day Vulnerabilities Are So Dangerous
- Detecting Zero-Day Vulnerabilities
- Challenges in Identifying Zero-Day Vulnerabilities
- How Qualys Helps Organizations Manage Zero-Day Risk
- Conclusion
- Frequently Asked Questions (FAQs)
Executive Summary
Zero-day vulnerabilities pose a significant and growing risk as opportunistic attackers rapidly exploit unknown flaws before fixes are available. These threats can bypass traditional defenses, spread rapidly, and cause widespread disruption across organi
Checkpoint
14th April – Threat Intelligence Report
blogs_checkpoint·2025-04-14
CVE-2024-50623 14th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 14th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th April, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The United States Office of the Comptroller of the Currency (OCC), an independent bureau of the Department of the Treasury, has suffered a significant security breach. Threat actors have gained access to the bureau’s email messages for a period of a year and a half. According to the agency’s disclosure, the messages included
Krebs
Patch Tuesday, April 2025 Edition
blogs_krebs·2025-04-09·CVSS 8.1
CVE-2025-29824 [HIGH] Patch Tuesday, April 2025 Edition
Microsoft today released updates to plug at least 121 security holes in its Windows operating systems and software, including one vulnerability that is already being exploited in the wild. Eleven of those flaws earned Microsoft’s most-dire “critical” rating, meaning malware or malcontents could exploit them with little to no interaction from Windows users.
The zero-day flaw already seeing exploitation is CVE-2025-29824, a local elevation of privilege bug in the Windows Common Log File System (CLFS) driver. Microsoft rates it as “important,” but as Chris Goettl from Ivanti points out, risk-based prioritization warrants treating it as critical.
This CLFS component of Windows is no stranger to Patch Tuesday: According to Tenable’s Satnam Narang, since 2022 Microsoft has patched 32 CLFS vuln
Krebs
Patch Tuesday, April 2025 Edition
blogs_krebs·2025-04-09·CVSS 8.1
CVE-2025-29824 [HIGH] Patch Tuesday, April 2025 Edition
Microsoft today released updates to plug at least 121 security holes in its Windows operating systems and software, including one vulnerability that is already being exploited in the wild. Eleven of those flaws earned Microsoft’s most-dire “critical” rating, meaning malware or malcontents could exploit them with little to no interaction from Windows users.
The zero-day flaw already seeing exploitation is CVE-2025-29824 , a local elevation of privilege bug in the Windows Common Log File System (CLFS) driver. Microsoft rates it as “important,” but as Chris Goettl from Ivanti points out, risk-based prioritization warrants treating it as critical.
This CLFS component of Windows is no stranger to Patch Tuesday: According to Tenable’s Satnam Narang , since 2022 Microsoft has patched 32 CLFS vu
Qualys
Microsoft and Adobe Patch Tuesday, April 2025 Security Update Review | Qualys
blogs_qualys·2025-04-08
Microsoft and Adobe Patch Tuesday, April 2025 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for April 2025
- Adobe Patches for April 2025
- Zero-day Vulnerabilities Patched in April Patch Tuesday Edition
- Critical Severity Vulnerabilities Patched in April Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response withPatch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
Microsoft’s April 2025 Patch Tuesday has arrived, delivering critical security updates and fixes across the various products, features, and roles. Here’s a quick breakdown of what you need to know.
## Microsoft Patch Tuesday for April 2025
In this m
Tenable
Microsoft’s April 2025 Patch Tuesday Addresses 121 CVEs (CVE-2025-29824)
blogs_tenable·2025-04-08·CVSS 7.8
[HIGH] Microsoft’s April 2025 Patch Tuesday Addresses 121 CVEs (CVE-2025-29824)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Microsoft: Windows CLFS zero-day exploited by ransomware gang
blogs_bleepingcomputer·2025-04-08·CVSS 7.8
[HIGH] Microsoft: Windows CLFS zero-day exploited by ransomware gang
## Microsoft: Windows CLFS zero-day exploited by ransomware gang
## Sergiu Gatlan
While the company has issued security updates for impacted Windows versions, it delayed releasing patches for systems running Windows 10 LTSB 2015 and said they would be released as soon as possible.
"The targets include organizations in the information technology (IT) and real estate sectors of the United States, the financial sector in Venezuela, a Spanish software company, and the retail sector in Saudi Arabia," Microsoft revealed today .
"Customers running Windows 11, version 24H2 are not affected by the observed exploitation, even if the vulnerability was present. Microsoft urges customers to apply these updates as soon as possible."
Microsoft linked these attacks to the RansomEXX ransomware gang, w
Bleepingcomputer
Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws
blogs_bleepingcomputer·2025-04-08·CVSS 7.8
[HIGH] Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws
## Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws
## Lawrence Abrams
49 Elevation of Privilege Vulnerabilities
9 Security Feature Bypass Vulnerabilities
31 Remote Code Execution Vulnerabilities
17 Information Disclosure Vulnerabilities
14 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The above numbers do not include Mariner flaws and 13 Microsoft Edge vulnerabilities fixed earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5055523 & KB5055528 cumulative updates and the Windows 10 KB5055518 update .
## One actively exploited zero-days
This month's Patch Tuesday fixes one actively exploited zero-day. Microsoft classifies a zero-day flaw as publicly disclos
Qualys
Microsoft and Adobe Patch Tuesday, April 2025 Security Update Review
blogs_qualys·2025-04-08
Microsoft and Adobe Patch Tuesday, April 2025 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for April 2025
Adobe Patches for April 2025
Zero-day Vulnerabilities Patched in April Patch Tuesday Edition
Critical Severity Vulnerabilities Patched in April Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response withPatch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
Microsoft’s April 2025 Patch Tuesday has arrived, delivering critical security updates and fixes across the various products, features, and roles. Here’s a quick breakdown of what you need to know.
## Microsoft Patch Tuesday for April 2025
In this month’s Patch
Securelist
Dark market overview and predictions for 2025
blogs_securelist·2024-12-16
Dark market overview and predictions for 2025
Table of Contents
- Review of last year’s predictions
- Our predictions for 2025
Authors
- Alexander Zabrovsky
- Sergey Lozhkin
## Review of last year’s predictions
### The number of services providing AV evasion for malware (cryptors) will increase
We continuously monitor underground markets for the emergence of new “cryptors,” which are tools specifically designed to obfuscate the code within malware samples. The primary purpose of these tools is to render the code undetectable by security software. In 2024, our expert observations indicate that commercial advertising for these cryptors have indeed gained momentum. Cryptor developers are introducing novel techniques to evade detection by security solutions, incorporating these advances into their malware offerings.
Pricing for the
Securelist
Dark web threats and dark market predictions for 2024
blogs_securelist·2024-01-17
Dark web threats and dark market predictions for 2024
Table of Contents
- An overview of last year’s predictions
- Our predictions for 2024
Authors
- Sergey Lozhkin
- Anna Pavlovskaya
- Kaspersky Security Services
## An overview of last year’s predictions
1. ### Increase in personal data leaks; corporate email at risk
A data leakage is a broad term encompassing various types of information that become publicly available, or published for sale on the dark web or other shadow web sites. Leaked information may include internal corporate documents, databases, personal and work login credentials, and other types of data.
Last year, we predicted that personal data and corporate email would increasingly be at risk, and the prediction proved largely accurate. In 2023, for instance, there was a significant rise in posts offering login credentia
Securelist
StripedFly: Perennially flying under the radar
blogs_securelist·2023-10-26
StripedFly: Perennially flying under the radar
Table of Contents
- Introduction
- How it started
- The infection
- Persistence
- Bitbucket repository
- The TOR
- The modules
- ThunderCrypt
- EternalBlue
- Conclusion
- Indicators of compromise
Authors
- Sergey Belov
- Vilen Kamalov
- Sergey Lozhkin
## Introduction
It’s just another cryptocurrency miner… Nobody would even suspect the mining malware was merely a mask, masquerading behind an intricate modular framework that supports both Linux and Windows. It comes equipped with a built-in TOR network tunnel for communication with command servers, along with update and delivery functionality through trusted services such as GitLab, GitHub, and Bitbucket, all using custom encrypted archives. The amount of effort that went into creating the framework is truly remarkable, and its disclo
Securelist
DoubleFinger delivers GreetingGhoul cryptocurrency stealer
blogs_securelist·2023-06-12
DoubleFinger delivers GreetingGhoul cryptocurrency stealer
Table of Contents
- Introduction
- DoubleFinger stage 1
- DoubleFinger stage 2
- DoubleFinger stage 3
- DoubleFinger stage 4
- DoubleFinger stage 5
- GreetingGhoul & Remcos
- Victims & Attribution
- Conclusion
- Indicators of compromise
Authors
- GReAT
- Sergey Lozhkin
## Introduction
Stealing cryptocurrencies is nothing new. For example, the Mt. Gox exchange was robbed of many bitcoins back in the beginning of 2010s. Attackers such as those behind the Coinvault ransomware were after your Bitcoin wallets, too. Since then, stealing cryptocurrencies has continued to occupy cybercriminals.
One of the latest additions to this phenomenon is the multi-stage DoubleFinger loader delivering a cryptocurrency stealer. DoubleFinger is deployed on the target machine, when the victim opens a mali
Securelist
Kaspersky report on Luna and Black Basta ransomware
blogs_securelist·2022-07-20
Kaspersky report on Luna and Black Basta ransomware
Table of Contents
- Introduction
- Luna: brand-new ransomware written in Rust
- Black Basta
- Black Basta for Linux
- Black Basta targets
- Conclusion
Authors
- Marc Rivero
- Jornt van der Wiel
- Dmitry Galov
- Sergey Lozhkin
## Introduction
In our crimeware reporting service, we analyze the latest crime-related trends we come across. If we look back at what we covered last month, we will see that ransomware (surprise, surprise!) definitely stands out. In this blog post, we provide several excerpts from last month’s reports on new ransomware strains.
## Luna: brand-new ransomware written in Rust
Last month, our Darknet Threat Intelligence active monitoring system notified us of a new advertisement on a darknet ransomware forum.
As one can see from the advertisement, the malware is
Crowdstrike
April 2025 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] April 2025 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Recorded Future
Rate My Rizz: Elevating Cyber Resilience Beyond Compliance
blogs_recorded_future
Rate My Rizz: Elevating Cyber Resilience Beyond Compliance
# Rate My Rizz
RSA is always a good opportunity to reconnect with industry friends—2025 was no exception. Beneath the marketing avalanche of “AI-enabled everything,” one theme stuck out in conversations with CISOs and defensive leaders: the mounting time and energy spent on cyber audits, reporting, and remediation.
These Enterprise Risk Management (ERM) and Governance, Risk, and Compliance (GRC) efforts are especially demanding in regulated industries. But with mandates like NIS2 and DORA taking effect in Europe—and domestic frameworks like SOX, SOC2, and CMMC still in play—security leaders are spending more time with audit committees than ever before.
## Compliance Theater: Starring the Risk Register
In enterprises, defensive resource allocations are often adjudicated by committees an
Recorded Future
Rate My Rizz: Elevating Cyber Resilience Beyond Compliance
blogs_recorded_future
Rate My Rizz: Elevating Cyber Resilience Beyond Compliance
## Rate My Rizz
RSA is always a good opportunity to reconnect with industry friends—2025 was no exception. Beneath the marketing avalanche of “AI-enabled everything,” one theme stuck out in conversations with CISOs and defensive leaders: the mounting time and energy spent on cyber audits, reporting, and remediation.
These Enterprise Risk Management (ERM) and Governance, Risk, and Compliance (GRC) efforts are especially demanding in regulated industries. But with mandates like NIS2 and DORA taking effect in Europe—and domestic frameworks like SOX , SOC2 , and CMMC still in play—security leaders are spending more time with audit committees than ever before.
## Compliance Theater: Starring the Risk Register
In enterprises, defensive resource allocations are often adjudicated by committees
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29824https://www.vicarius.io/vsociety/posts/cve-2025-29824-windows-common-log-file-system-driver-elevation-of-privilege-vulnerability-detection-scripthttps://www.vicarius.io/vsociety/posts/cve-2025-29824-windows-common-log-file-system-driver-elevation-of-privilege-vulnerability-mitigation-scripthttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-29824
2025-04-08
Published
2025-04-08
Added to CISA KEV
Exploited in the wild