Get the latest tech news

Microsoft fixes actively exploited Windows CLFS zero-day


For April 2025 Patch Tuesday, Microsoft delivers fixes for 120+ vulnerabilities, including a zero-day (CVE-2025-29824) under active attack.

We don’t know how widespread the attacks involving the exploitation of this vulnerability are, we know only that Microsoft Threat Intelligence Center has been credited with reporting the flaw. And since no user interaction is involved, these bugs are wormable,” says Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative. Aside from implementing the offered security updates, users would do well to either make RDP unreachable from the internet or reachable only from trusted IP addresses.

Get the Android app

Or read this on r/technology

Read more on:

Photo of Microsoft

Microsoft

Photo of Day

Day

Photo of Microsoft fixes

Microsoft fixes

Related news:

News photo

Carmack defends AI tools after Quake fan calls Microsoft AI demo “disgusting”

News photo

Microsoft: Windows CLFS zero-day exploited by ransomware gang

News photo

Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws