Microsoft released its March 2025 security updates to address 58 vulnerabilities across Windows, Office, Azure components, Visual Studio, and related enterprise software, including 23 remote code execution flaws and six critical vulnerabilities. The most severe issues affected Microsoft Office, Microsoft Dataverse, Windows Remote Desktop Services, Remote Desktop Client, Windows DNS, and Windows Subsystem for Linux 2, with impacts ranging from remote code execution to privilege escalation.
The update also remediated several vulnerabilities reported as actively exploited, including CVE-2025-24983 in the Windows Win32 Kernel Subsystem, alongside flaws in Microsoft Management Console, Windows NTFS, and the Windows Fast FAT File System Driver. Microsoft said the Dataverse issue CVE-2025-24053 was mitigated automatically and required no customer action, while defenders were urged to deploy the broader patch bundle promptly to reduce exposure across supported Windows client and server environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft issued its March 2025 Patch Tuesday security updates addressing 58 vulnerabilities across its product portfolio, including six critical flaws and 23 remote code execution issues. The updates covered products including Microsoft Office, Dataverse, Windows Remote Desktop Services, Remote Desktop Client, Windows DNS, and Windows Subsystem for Linux 2.
Microsoft stated that the Microsoft Dataverse vulnerability CVE-2025-24053 was automatically remediated by the company and required no customer action. The flaw was included in reporting around the March 2025 security updates.
In conjunction with the March 2025 updates, Microsoft disclosed that several vulnerabilities were being actively exploited, including CVE-2025-24983 in the Windows Win32 Kernel Subsystem as well as flaws affecting Microsoft Management Console, Windows NTFS, and the Windows Fast FAT File System Driver. This marked the vulnerabilities as in-the-wild threats requiring urgent patching.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.