FREE TRIAL
Patch Tuesday

Microsoft Patch Tuesday – April 2025

8 min. read
10/04/2025
By Esben Dochy
Microsoft Patch Tuesday

⚡ TL;DR | Go Straight to the April 202Patch Tuesday Audit Report

Patch Tuesday is once again upon us. As always, our team has put together the monthly Patch Tuesday Report to help you manage your update progress. The audit report gives you a quick and clear overview of your Windows machines and their patching status. The April 2025 edition of Patch Tuesday brings us 121 new fixes, with 11 rated as critical and 1 exploited. We’ve listed the most important changes below.

Windows 10 1507 Patches Delayed

Microsoft has added the following warning to all vulnerabilities this month:

The security update for Windows 10 for x64-based Systems and Windows 10 for 32-bit Systems are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information.

Seemingly there have been some delays in Microsoft’s process specifically for the first Windows 10 version patches. This means any Windows 10 Version 1507 device (OS Build 10240.X) will remain unpatched for now.

April 9 Update

As of April 9, Microsoft has released KB5055547 to provide the patch Tuesday updates for Windows 10 Version 1507.

Windows Common Log File System Driver Elevation of Privilege Vulnerability

The first item is the only exploited vulnerability this month. CVE-2025-29824 has a CVSS base score of 7.8.

The Windows Common Log File System (CLFS) Driver manages high-integrity system and application log data, so a vulnerability in it could allow attackers to compromise critical logging processes or escalate privileges at the kernel level.

Microsoft lists that if exploitation is successful, an attacker could gain SYSTEM privileges.

LDAP Remote Code Execution Vulnerability

Second on the list are CVE-2025-26663 and CVE-2025-26670 both with a CVSS base score of 8.1. While they haven’t been exploited yet, Microsoft does list these as Critical and “More Likely” to be exploited.

In order to exploit the vulnerability an unauthenticated attacker could sequentially send specially crafted requests to a vulnerable LDAP server. This could result in a use after free which could be leveraged to achieve remote code execution.

Windows Remote Desktop Services Remote Code Execution Vulnerability

Similar to last month, there are another two critical vulnerabilities have been fixed for the Windows RDS. CVE-2025-27482 and CVE-2025-27480 have a CVSS base score of 8.1 and with the label “Exploitation More Likely”.

Microsoft only provided the following additional information:

An attacker could successfully exploit this vulnerability by connecting to a system with the Remote Desktop Gateway role, triggering the race condition to create a use-after-free scenario, and then leveraging this to execute arbitrary code.

Run the Patch Tuesday April 2025 Audit

To help manage your update progress, we’ve created the Patch Tuesday Audit that checks if the assets in your network are on the latest patch updates. The report has been color-coded to see which machines are up-to-date and which ones still need to be updated. As always, system administrators are urged to update their environment as soon as possible to ensure all endpoints are secured.

The Lansweeper Patch Tuesday report is automatically added to your Lansweeper Site. Lansweeper Sites is included in all our licenses without any additional cost and allows you to federate all your installations into one single view so all you need to do is look at one report, automatically added every patch Tuesday!

Patch Tuesday April 2025 CVE Codes & Titles

CVE NumberCVE Title
CVE-2025-29824Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-29823Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-29822Microsoft OneNote Security Feature Bypass Vulnerability
CVE-2025-29821Microsoft Dynamics Business Central Information Disclosure Vulnerability
CVE-2025-29820Microsoft Word Remote Code Execution Vulnerability
CVE-2025-29819Windows Admin Center in Azure Portal Information Disclosure Vulnerability
CVE-2025-29816Microsoft Word Security Feature Bypass Vulnerability
CVE-2025-29812DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-29811Windows Mobile Broadband Driver Elevation of Privilege Vulnerability
CVE-2025-29810Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2025-29809Windows Kerberos Security Feature Bypass Vulnerability
CVE-2025-29808Windows Cryptographic Services Information Disclosure Vulnerability
CVE-2025-29805Outlook for Android Information Disclosure Vulnerability
CVE-2025-29804Visual Studio Elevation of Privilege Vulnerability
CVE-2025-29803Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Privilege Vulnerability
CVE-2025-29802Visual Studio Elevation of Privilege Vulnerability
CVE-2025-29801Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
CVE-2025-29800Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
CVE-2025-29794Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2025-29793Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2025-29792Microsoft Office Elevation of Privilege Vulnerability
CVE-2025-29791Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-27752Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-27751Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-27750Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-27749Microsoft Office Remote Code Execution Vulnerability
CVE-2025-27748Microsoft Office Remote Code Execution Vulnerability
CVE-2025-27747Microsoft Word Remote Code Execution Vulnerability
CVE-2025-27746Microsoft Office Remote Code Execution Vulnerability
CVE-2025-27745Microsoft Office Remote Code Execution Vulnerability
CVE-2025-27744Microsoft Office Elevation of Privilege Vulnerability
CVE-2025-27743Microsoft System Center Elevation of Privilege Vulnerability
CVE-2025-27742NTFS Information Disclosure Vulnerability
CVE-2025-27741NTFS Elevation of Privilege Vulnerability
CVE-2025-27740Active Directory Certificate Services Elevation of Privilege Vulnerability
CVE-2025-27739Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-27738Windows Resilient File System (ReFS) Information Disclosure Vulnerability
CVE-2025-27737Windows Security Zone Mapping Security Feature Bypass Vulnerability
CVE-2025-27736Windows Power Dependency Coordinator Information Disclosure Vulnerability
CVE-2025-27735Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
CVE-2025-27733NTFS Elevation of Privilege Vulnerability
CVE-2025-27732Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-27731Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability
CVE-2025-27730Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-27729Windows Shell Remote Code Execution Vulnerability
CVE-2025-27728Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2025-27727Windows Installer Elevation of Privilege Vulnerability
CVE-2025-27492Windows Secure Channel Elevation of Privilege Vulnerability
CVE-2025-27491Windows Hyper-V Remote Code Execution Vulnerability
CVE-2025-27490Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2025-27489Azure Local Elevation of Privilege Vulnerability
CVE-2025-27487Remote Desktop Client Remote Code Execution Vulnerability
CVE-2025-27486Windows Standards-Based Storage Management Service Denial of Service Vulnerability
CVE-2025-27485Windows Standards-Based Storage Management Service Denial of Service Vulnerability
CVE-2025-27484Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
CVE-2025-27483NTFS Elevation of Privilege Vulnerability
CVE-2025-27482Windows Remote Desktop Services Remote Code Execution Vulnerability
CVE-2025-27481Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-27480Windows Remote Desktop Services Remote Code Execution Vulnerability
CVE-2025-27479Kerberos Key Distribution Proxy Service Denial of Service Vulnerability
CVE-2025-27478Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
CVE-2025-27477Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-27476Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-27475Windows Update Stack Elevation of Privilege Vulnerability
CVE-2025-27474Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-27473HTTP.sys Denial of Service Vulnerability
CVE-2025-27472Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2025-27471Microsoft Streaming Service Denial of Service Vulnerability
CVE-2025-27470Windows Standards-Based Storage Management Service Denial of Service Vulnerability
CVE-2025-27469Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVE-2025-27467Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-26688Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
CVE-2025-26687Win32k Elevation of Privilege Vulnerability
CVE-2025-26686Windows TCP/IP Remote Code Execution Vulnerability
CVE-2025-26682ASP.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2025-26681Win32k Elevation of Privilege Vulnerability
CVE-2025-26680Windows Standards-Based Storage Management Service Denial of Service Vulnerability
CVE-2025-26679RPC Endpoint Mapper Service Elevation of Privilege Vulnerability
CVE-2025-26678Windows Defender Application Control Security Feature Bypass Vulnerability
CVE-2025-26676Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-26675Windows Subsystem for Linux Elevation of Privilege Vulnerability
CVE-2025-26674Windows Media Remote Code Execution Vulnerability
CVE-2025-26673Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVE-2025-26672Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-26671Windows Remote Desktop Services Remote Code Execution Vulnerability
CVE-2025-26670Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
CVE-2025-26669Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-26668Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-26667Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-26666Windows Media Remote Code Execution Vulnerability
CVE-2025-26665Windows upnphost.dll Elevation of Privilege Vulnerability
CVE-2025-26664Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-26663Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2025-26652Windows Standards-Based Storage Management Service Denial of Service Vulnerability
CVE-2025-26651Windows Local Session Manager (LSM) Denial of Service Vulnerability
CVE-2025-26649Windows Secure Channel Elevation of Privilege Vulnerability
CVE-2025-26648Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-26647Windows Kerberos Elevation of Privilege Vulnerability
CVE-2025-26644Windows Hello Spoofing Vulnerability
CVE-2025-26642Microsoft Office Remote Code Execution Vulnerability
CVE-2025-26641Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2025-26640Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-26639Windows USB Print Driver Elevation of Privilege Vulnerability
CVE-2025-26637BitLocker Security Feature Bypass Vulnerability
CVE-2025-26635Windows Hello Security Feature Bypass Vulnerability
CVE-2025-26628Azure Local Cluster Information Disclosure Vulnerability
CVE-2025-25002Azure Local Cluster Information Disclosure Vulnerability
CVE-2025-24074Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-24073Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-24062Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-24060Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-24058Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-21222Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21221Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21205Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21204Windows Process Activation Elevation of Privilege Vulnerability
CVE-2025-21203Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-21197Windows NTFS Information Disclosure Vulnerability
CVE-2025-21191Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
CVE-2025-21174Windows Standards-Based Storage Management Service Denial of Service Vulnerability
CVE-2025-20570Visual Studio Code Elevation of Privilege Vulnerability
NO CREDIT CARD REQUIRED

Ready to get started?
You’ll be up and running in no time.

Explore all our features, free for 14 days.