Wtorek poprawek firmy Microsoft z kwietnia 2025 r. obejmuje aktualizacje zabezpieczeń dla 134 luk, w tym jedną aktywnie wykorzystywaną lukę typu zero-day.

Wtorek poprawek naprawia również jedenaście luk „krytycznych”, wszystkie luki umożliwiające zdalne wykonanie kodu.

Liczba błędów w każdej kategorii luk jest wymieniona poniżej:

  • 49 luk umożliwiających podniesienie uprawnień
  • 9 luk umożliwiających ominięcie funkcji bezpieczeństwa
  • 31 luk umożliwiających zdalne wykonanie kodu
  • 17 luk umożliwiających ujawnienie informacji
  • 14 luk umożliwiających odmowę usługi
  • 3 luki umożliwiające podszywanie się

W tym miesiącu Patch Tuesday naprawia jedną aktywnie wykorzystywaną lukę typu zero-day.

Aktywnie wykorzystywana luka typu zero-day w dzisiejszych aktualizacjach to:

CVE-2025-29824 – Luka w zabezpieczeniach umożliwiająca podniesienie uprawnień sterownika systemu plików dziennika systemu Windows Common Log

Firma Microsoft twierdzi, że ta luka umożliwia lokalnym atakującym uzyskanie uprawnień SYSTEM na urządzeniu/

„Aktualizacja zabezpieczeń dla systemu Windows 10 dla systemów opartych na architekturze x64 i systemu Windows 10 dla systemów 32-bitowych nie jest natychmiast dostępna” — wyjaśnił Microsoft.

„Aktualizacje zostaną wydane tak szybko, jak to możliwe, a gdy będą dostępne, klienci zostaną powiadomieni za pośrednictwem rewizji tych informacji CVE”.

Firma Microsoft twierdzi, że poprawki nie są dostępne dla systemu Windows 10 LTSB 2015 i zostaną wydane w przyszłości.

TagCVE IDCVE opisKrytyczność
Active Directory Domain ServicesCVE-2025-29810Active Directory Domain Services Elevation of Privilege VulnerabilityWysoka
ASP.NET CoreCVE-2025-26682ASP.NET Core and Visual Studio Denial of Service VulnerabilityWysoka
Azure LocalCVE-2025-27489Azure Local Elevation of Privilege VulnerabilityWysoka
Azure Local ClusterCVE-2025-26628Azure Local Cluster Information Disclosure VulnerabilityWysoka
Azure Local ClusterCVE-2025-25002Azure Local Cluster Information Disclosure VulnerabilityWysoka
Azure Portal Windows Admin CenterCVE-2025-29819Windows Admin Center in Azure Portal Information Disclosure VulnerabilityWysoka
Dynamics Business CentralCVE-2025-29821Microsoft Dynamics Business Central Information Disclosure VulnerabilityWysoka
Microsoft AutoUpdate (MAU)CVE-2025-29800Microsoft AutoUpdate (MAU) Elevation of Privilege VulnerabilityWysoka
Microsoft AutoUpdate (MAU)CVE-2025-29801Microsoft AutoUpdate (MAU) Elevation of Privilege VulnerabilityWysoka
Microsoft Edge (Chromium-based)CVE-2025-3073Chromium: CVE-2025-3073 Inappropriate implementation in AutofillNieokreślona
Microsoft Edge (Chromium-based)CVE-2025-3068Chromium: CVE-2025-3068 Inappropriate implementation in IntentsNieokreślona
Microsoft Edge (Chromium-based)CVE-2025-3074Chromium: CVE-2025-3074 Inappropriate implementation in DownloadsNieokreślona
Microsoft Edge (Chromium-based)CVE-2025-3067Chromium: CVE-2025-3067 Inappropriate implementation in Custom TabsNieokreślona
Microsoft Edge (Chromium-based)CVE-2025-3071Chromium: CVE-2025-3071 Inappropriate implementation in NavigationsNieokreślona
Microsoft Edge (Chromium-based)CVE-2025-3072Chromium: CVE-2025-3072 Inappropriate implementation in Custom TabsNieokreślona
Microsoft Edge (Chromium-based)CVE-2025-3070Chromium: CVE-2025-3070 Insufficient validation of untrusted input in ExtensionsNieokreślona
Microsoft Edge (Chromium-based)CVE-2025-3069Chromium: CVE-2025-3069 Inappropriate implementation in ExtensionsNieokreślona
Microsoft Edge (Chromium-based)CVE-2025-25000Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityWysoka
Microsoft Edge (Chromium-based)CVE-2025-29815Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityWysoka
Microsoft Edge (Chromium-based)CVE-2025-25001Microsoft Edge for iOS Spoofing VulnerabilityNiska
Microsoft Edge (Chromium-based)CVE-2025-3066Chromium: CVE-2025-3066 Use after free in NavigationsNieokreślona
Microsoft Edge for iOSCVE-2025-29796Microsoft Edge for iOS Spoofing VulnerabilityNiska
Microsoft OfficeCVE-2025-27745Microsoft Office Remote Code Execution VulnerabilityKrytyczna
Microsoft OfficeCVE-2025-27744Microsoft Office Elevation of Privilege VulnerabilityWysoka
Microsoft OfficeCVE-2025-26642Microsoft Office Remote Code Execution VulnerabilityWysoka
Microsoft OfficeCVE-2025-29792Microsoft Office Elevation of Privilege VulnerabilityWysoka
Microsoft OfficeCVE-2025-29791Microsoft Excel Remote Code Execution VulnerabilityKrytyczna
Microsoft OfficeCVE-2025-27748Microsoft Office Remote Code Execution VulnerabilityKrytyczna
Microsoft OfficeCVE-2025-27746Microsoft Office Remote Code Execution VulnerabilityWysoka
Microsoft OfficeCVE-2025-27749Microsoft Office Remote Code Execution VulnerabilityKrytyczna
Microsoft Office ExcelCVE-2025-27751Microsoft Excel Remote Code Execution VulnerabilityWysoka
Microsoft Office ExcelCVE-2025-27750Microsoft Excel Remote Code Execution VulnerabilityWysoka
Microsoft Office ExcelCVE-2025-29823Microsoft Excel Remote Code Execution VulnerabilityWysoka
Microsoft Office ExcelCVE-2025-27752Microsoft Excel Remote Code Execution VulnerabilityKrytyczna
Microsoft Office OneNoteCVE-2025-29822Microsoft OneNote Security Feature Bypass VulnerabilityWysoka
Microsoft Office SharePointCVE-2025-29794Microsoft SharePoint Remote Code Execution VulnerabilityWysoka
Microsoft Office SharePointCVE-2025-29793Microsoft SharePoint Remote Code Execution VulnerabilityWysoka
Microsoft Office WordCVE-2025-27747Microsoft Word Remote Code Execution VulnerabilityWysoka
Microsoft Office WordCVE-2025-29816Microsoft Word Security Feature Bypass VulnerabilityWysoka
Microsoft Office WordCVE-2025-29820Microsoft Word Remote Code Execution VulnerabilityWysoka
Microsoft Streaming ServiceCVE-2025-27471Microsoft Streaming Service Denial of Service VulnerabilityWysoka
Microsoft Virtual Hard DriveCVE-2025-26688Microsoft Virtual Hard Disk Elevation of Privilege VulnerabilityWysoka
OpenSSH for WindowsCVE-2025-27731Microsoft OpenSSH for Windows Elevation of Privilege VulnerabilityWysoka
Outlook for AndroidCVE-2025-29805Outlook for Android Information Disclosure VulnerabilityWysoka
Remote Desktop ClientCVE-2025-27487Remote Desktop Client Remote Code Execution VulnerabilityWysoka
Remote Desktop Gateway ServiceCVE-2025-27482Windows Remote Desktop Services Remote Code Execution VulnerabilityKrytyczna
Remote Desktop Gateway ServiceCVE-2025-27480Windows Remote Desktop Services Remote Code Execution VulnerabilityKrytyczna
RPC Endpoint Mapper ServiceCVE-2025-26679RPC Endpoint Mapper Service Elevation of Privilege VulnerabilityWysoka
System CenterCVE-2025-27743Microsoft System Center Elevation of Privilege VulnerabilityWysoka
Visual StudioCVE-2025-29802Visual Studio Elevation of Privilege VulnerabilityWysoka
Visual StudioCVE-2025-29804Visual Studio Elevation of Privilege VulnerabilityWysoka
Visual Studio CodeCVE-2025-20570Visual Studio Code Elevation of Privilege VulnerabilityWysoka
Visual Studio Tools for Applications and SQL Server Management StudioCVE-2025-29803Visual Studio Tools for Applications and SQL Server Management Studio Elevation of Privilege VulnerabilityWysoka
Windows Active Directory Certificate ServicesCVE-2025-27740Active Directory Certificate Services Elevation of Privilege VulnerabilityWysoka
Windows BitLockerCVE-2025-26637BitLocker Security Feature Bypass VulnerabilityWysoka
Windows Bluetooth ServiceCVE-2025-27490Windows Bluetooth Service Elevation of Privilege VulnerabilityWysoka
Windows Common Log File System DriverCVE-2025-29824Windows Common Log File System Driver Elevation of Privilege VulnerabilityWysoka
Windows Cryptographic ServicesCVE-2025-29808Windows Cryptographic Services Information Disclosure VulnerabilityWysoka
Windows Cryptographic ServicesCVE-2025-26641Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityWysoka
Windows Defender Application Control (WDAC)CVE-2025-26678Windows Defender Application Control Security Feature Bypass VulnerabilityWysoka
Windows Digital MediaCVE-2025-27730Windows Digital Media Elevation of Privilege VulnerabilityWysoka
Windows Digital MediaCVE-2025-27467Windows Digital Media Elevation of Privilege VulnerabilityWysoka
Windows Digital MediaCVE-2025-26640Windows Digital Media Elevation of Privilege VulnerabilityWysoka
Windows Digital MediaCVE-2025-27476Windows Digital Media Elevation of Privilege VulnerabilityWysoka
Windows DWM Core LibraryCVE-2025-24074Microsoft DWM Core Library Elevation of Privilege VulnerabilityWysoka
Windows DWM Core LibraryCVE-2025-24073Microsoft DWM Core Library Elevation of Privilege VulnerabilityWysoka
Windows DWM Core LibraryCVE-2025-24058Windows DWM Core Library Elevation of Privilege VulnerabilityWysoka
Windows DWM Core LibraryCVE-2025-24062Microsoft DWM Core Library Elevation of Privilege VulnerabilityWysoka
Windows DWM Core LibraryCVE-2025-24060Microsoft DWM Core Library Elevation of Privilege VulnerabilityWysoka
Windows HelloCVE-2025-26635Windows Hello Security Feature Bypass VulnerabilityWysoka
Windows HelloCVE-2025-26644Windows Hello Spoofing VulnerabilityWysoka
Windows HTTP.sysCVE-2025-27473HTTP.sys Denial of Service VulnerabilityWysoka
Windows Hyper-VCVE-2025-27491Windows Hyper-V Remote Code Execution VulnerabilityKrytyczna
Windows InstallerCVE-2025-27727Windows Installer Elevation of Privilege VulnerabilityWysoka
Windows KerberosCVE-2025-26647Windows Kerberos Elevation of Privilege VulnerabilityWysoka
Windows KerberosCVE-2025-27479Kerberos Key Distribution Proxy Service Denial of Service VulnerabilityWysoka
Windows KerberosCVE-2025-29809Windows Kerberos Security Feature Bypass VulnerabilityWysoka
Windows KernelCVE-2025-26648Windows Kernel Elevation of Privilege VulnerabilityWysoka
Windows KernelCVE-2025-27739Windows Kernel Elevation of Privilege VulnerabilityWysoka
Windows Kernel MemoryCVE-2025-29812DirectX Graphics Kernel Elevation of Privilege VulnerabilityWysoka
Windows Kernel-Mode DriversCVE-2025-27728Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityWysoka
Windows LDAP – Lightweight Directory Access ProtocolCVE-2025-26673Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityWysoka
Windows LDAP – Lightweight Directory Access ProtocolCVE-2025-26663Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityKrytyczna
Windows LDAP – Lightweight Directory Access ProtocolCVE-2025-27469Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityWysoka
Windows LDAP – Lightweight Directory Access ProtocolCVE-2025-26670Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution VulnerabilityKrytyczna
Windows Local Security Authority (LSA)CVE-2025-21191Windows Local Security Authority (LSA) Elevation of Privilege VulnerabilityWysoka
Windows Local Security Authority (LSA)CVE-2025-27478Windows Local Security Authority (LSA) Elevation of Privilege VulnerabilityWysoka
Windows Local Session Manager (LSM)CVE-2025-26651Windows Local Session Manager (LSM) Denial of Service VulnerabilityWysoka
Windows Mark of the Web (MOTW)CVE-2025-27472Windows Mark of the Web Security Feature Bypass VulnerabilityWysoka
Windows MediaCVE-2025-26666Windows Media Remote Code Execution VulnerabilityWysoka
Windows MediaCVE-2025-26674Windows Media Remote Code Execution VulnerabilityWysoka
Windows Mobile BroadbandCVE-2025-29811Windows Mobile Broadband Driver Elevation of Privilege VulnerabilityWysoka
Windows NTFSCVE-2025-27742NTFS Information Disclosure VulnerabilityWysoka
Windows NTFSCVE-2025-21197Windows NTFS Information Disclosure VulnerabilityWysoka
Windows NTFSCVE-2025-27741NTFS Elevation of Privilege VulnerabilityWysoka
Windows NTFSCVE-2025-27483NTFS Elevation of Privilege VulnerabilityWysoka
Windows NTFSCVE-2025-27733NTFS Elevation of Privilege VulnerabilityWysoka
Windows Power Dependency CoordinatorCVE-2025-27736Windows Power Dependency Coordinator Information Disclosure VulnerabilityWysoka
Windows Remote Desktop ServicesCVE-2025-26671Windows Remote Desktop Services Remote Code Execution VulnerabilityWysoka
Windows Resilient File System (ReFS)CVE-2025-27738Windows Resilient File System (ReFS) Information Disclosure VulnerabilityWysoka
Windows Routing and Remote Access Service (RRAS)CVE-2025-27474Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityWysoka
Windows Routing and Remote Access Service (RRAS)CVE-2025-21203Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityWysoka
Windows Routing and Remote Access Service (RRAS)CVE-2025-26668Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWysoka
Windows Routing and Remote Access Service (RRAS)CVE-2025-26667Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityWysoka
Windows Routing and Remote Access Service (RRAS)CVE-2025-26664Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityWysoka
Windows Routing and Remote Access Service (RRAS)CVE-2025-26672Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityWysoka
Windows Routing and Remote Access Service (RRAS)CVE-2025-26669Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityWysoka
Windows Routing and Remote Access Service (RRAS)CVE-2025-26676Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityWysoka
Windows Secure ChannelCVE-2025-27492Windows Secure Channel Elevation of Privilege VulnerabilityWysoka
Windows Secure ChannelCVE-2025-26649Windows Secure Channel Elevation of Privilege VulnerabilityWysoka
Windows Security Zone MappingCVE-2025-27737Windows Security Zone Mapping Security Feature Bypass VulnerabilityWysoka
Windows ShellCVE-2025-27729Windows Shell Remote Code Execution VulnerabilityWysoka
Windows Standards-Based Storage Management ServiceCVE-2025-27485Windows Standards-Based Storage Management Service Denial of Service VulnerabilityWysoka
Windows Standards-Based Storage Management ServiceCVE-2025-27486Windows Standards-Based Storage Management Service Denial of Service VulnerabilityWysoka
Windows Standards-Based Storage Management ServiceCVE-2025-21174Windows Standards-Based Storage Management Service Denial of Service VulnerabilityWysoka
Windows Standards-Based Storage Management ServiceCVE-2025-26680Windows Standards-Based Storage Management Service Denial of Service VulnerabilityWysoka
Windows Standards-Based Storage Management ServiceCVE-2025-27470Windows Standards-Based Storage Management Service Denial of Service VulnerabilityWysoka
Windows Standards-Based Storage Management ServiceCVE-2025-26652Windows Standards-Based Storage Management Service Denial of Service VulnerabilityWysoka
Windows Subsystem for LinuxCVE-2025-26675Windows Subsystem for Linux Elevation of Privilege VulnerabilityWysoka
Windows TCP/IPCVE-2025-26686Windows TCP/IP Remote Code Execution VulnerabilityKrytyczna
Windows Telephony ServiceCVE-2025-27481Windows Telephony Service Remote Code Execution VulnerabilityWysoka
Windows Telephony ServiceCVE-2025-21222Windows Telephony Service Remote Code Execution VulnerabilityWysoka
Windows Telephony ServiceCVE-2025-21205Windows Telephony Service Remote Code Execution VulnerabilityWysoka
Windows Telephony ServiceCVE-2025-21221Windows Telephony Service Remote Code Execution VulnerabilityWysoka
Windows Telephony ServiceCVE-2025-27477Windows Telephony Service Remote Code Execution VulnerabilityWysoka
Windows Universal Plug and Play (UPnP) Device HostCVE-2025-27484Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege VulnerabilityWysoka
Windows Update StackCVE-2025-21204Windows Process Activation Elevation of Privilege VulnerabilityWysoka
Windows Update StackCVE-2025-27475Windows Update Stack Elevation of Privilege VulnerabilityWysoka
Windows upnphost.dllCVE-2025-26665Windows upnphost.dll Elevation of Privilege VulnerabilityWysoka
Windows USB Print DriverCVE-2025-26639Windows USB Print Driver Elevation of Privilege VulnerabilityWysoka
Windows Virtualization-Based Security (VBS) EnclaveCVE-2025-27735Windows Virtualization-Based Security (VBS) Security Feature Bypass VulnerabilityWysoka
Windows Win32K – GRFXCVE-2025-27732Windows Graphics Component Elevation of Privilege VulnerabilityWysoka
Windows Win32K – GRFXCVE-2025-26687Win32k Elevation of Privilege VulnerabilityWysoka
Windows Win32K – GRFXCVE-2025-26681Win32k Elevation of Privilege VulnerabilityWysoka