Microsoft has recently addressed two critical zero-day vulnerabilities actively exploited in the wild targeting Windows systems. These zero-days, identified as CVE-2025-12345 and CVE-2025-12346, allow attackers to execute arbitrary code and escalate privileges, posing significant risks to enterprise and individual users alike. The vulnerabilities were exploited by sophisticated threat actors aiming to gain unauthorized access and control over affected machines. Microsoft responded swiftly by releasing emergency security patches to mitigate these threats and urged users to apply updates immediately to protect their systems. The exploitation of these zero-days highlights the persistent challenges in securing widely used operating systems and the importance of timely patch management. Security experts recommend organizations to enhance their monitoring and incident response capabilities to detect potential exploitation attempts. This incident underscores the evolving tactics of cybercriminals and the critical need for continuous vigilance in cybersecurity practices.
This Cyber News was published on thehackernews.com. Publication date: Wed, 15 Oct 2025 23:14:05 +0000