WEEKLY BRIEFING · 10 MAR – 16 MAR 2025 · UTC
Public sources only
4 public updates in week 11
MSRC published March 2025 Security Updates. 1 roadmap change, led by SharePoint (1). CISA added 6 Microsoft CVEs to its Known Exploited Vulnerabilities catalog.
0Windows KB releases
1MSRC release note
1Roadmap change across 1 product
0Windows and security articles
6Microsoft CVEs added to CISA KEV
Security to act on6
- CVE-2025-26633 — Microsoft Windows Management Console (MMC) Improper Neutralization VulnerabilityKEV 11 Mar
- CVE-2025-24993 — Microsoft Windows NTFS Heap-Based Buffer Overflow VulnerabilityKEV 11 Mar
- CVE-2025-24991 — Microsoft Windows NTFS Out-Of-Bounds Read VulnerabilityKEV 11 Mar
- CVE-2025-24985 — Microsoft Windows Fast FAT File System Driver Integer Overflow VulnerabilityKEV 11 Mar
- CVE-2025-24984 — Microsoft Windows NTFS Information Disclosure VulnerabilityKEV 11 Mar
- CVE-2025-24983 — Microsoft Windows Win32k Use-After-Free VulnerabilityKEV 11 Mar
MSRC security releases1
From the community2
Every line opens its detail page or the original Microsoft source. This briefing uses public sources only and says nothing about your tenant or devices.