According to the January patch list released by Microsoft, 23 new vulnerabilities have been reported.
Specifically, the list of patches with 161 security vulnerabilities includes: 159 vulnerabilities in the company's products and 2 vulnerabilities existing in third-party products that affect Microsoft.
Of which, 23 vulnerabilities with high and serious impact levels have been recommended by the Department of Information Security to agencies, organizations and businesses nationwide.
Of the 23 vulnerabilities warned, 5 allow attackers to escalate privileges: CVE-2025-21275 in "Windows App Package Installer"; CVE-2025-21311 in "Windows NTLM V1" and 3 vulnerabilities CVE-2025-21333, CVE-2025-21334, CVE-2025-21335 in "Windows Hyper-V NT Kernel Integration VSP" - these are also 3 vulnerabilities being exploited by hackers in reality.
Vulnerability CVE-2025-21308 in "Windows Themes" allows attackers to spoof.
The remaining 17 vulnerabilities that allow attackers to execute remote code are: CVE-2025-21298 in Windows OLE; 2 vulnerabilities CVE-2025-21297 and CVE-2025-21309 in Windows Remote Destop Services; 3 vulnerabilities CVE-2025-21186, CVE-2025-21366 and CVE-2025-21395 in Windows Excel; CVE-2025-21402 in Microsoft Office OneNote; CVE-2025-21365 in Microsoft Ofice; 2 vulnerabilities CVE-2025-21345, CVE-2025-21356 in Microsoft Office Vision; CVE-2025-21363 in Microsoft Word; 2 vulnerabilities CVE-2025-21357, CVE -2025-21361 in Microsoft Outlook and 2 vulnerabilities CVE-2025-21344, CVE-2025-21348 in SharePoint Server.
The Information Security Department said these vulnerabilities can be exploited to carry out illegal acts that affect the information systems of businesses.
Therefore, units need to check and review whether the computers using Windows operating system that the unit uses are affected or not. In case of possible impact, update the patch according to the instructions.
When detecting signs of exploitation or cyber attacks requiring support, units can contact the National Cyber Security Monitoring Center - NCSC at phone number 02432091616 and email [email protected]
Source: https://kinhtedothi.vn/canh-bao-23-lo-hong-moi-nham-vao-he-thong-thong-tin-tai-viet-nam.html
Comment (0)