Microsoft released its February 2025 security updates to address 61 vulnerabilities across Windows, Office, SharePoint, Edge, Visual Studio, CBL Mariner, and other products. The bundle included 26 remote code execution flaws and four critical vulnerabilities, with notable high-risk issues affecting Microsoft Dynamics 365 Sales, Microsoft Excel, Windows LDAP, and the Windows DHCP Client Service. Microsoft also published individual advisories for vulnerabilities including CVE-2025-21376 and CVE-2025-21177 as part of the release.
The update cycle also fixed two actively exploited zero-days: CVE-2025-21391 in Windows Storage and CVE-2025-21418 in the Windows Ancillary Function Driver for WinSock. Security guidance accompanying the release urged organizations to prioritize deployment of the February patch bundle because the affected components are widely used across enterprise Windows environments and Microsoft application stacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft made individual Security Update Guide entries available for CVE-2025-21177 and CVE-2025-21376 as part of the February 2025 security update coverage. These entries document the vulnerabilities in Microsoft's advisory system.
Microsoft's February 2025 security updates addressed 61 vulnerabilities across its product portfolio, including 26 remote code execution flaws. The release included fixes for critical issues in Microsoft Dynamics 365 Sales, Microsoft Excel, Windows LDAP, and the Windows DHCP Client Service.
In the February 2025 update cycle, Microsoft identified two vulnerabilities as already being actively exploited: CVE-2025-21391 in Windows Storage and CVE-2025-21418 in the Windows Ancillary Function Driver for WinSock. The advisory urged organizations to deploy the February patch bundle promptly.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.