{"id":2812,"date":"2025-09-14T16:52:45","date_gmt":"2025-09-14T16:52:45","guid":{"rendered":"https:\/\/ft365.org\/index.php\/2025\/09\/14\/two-zero-days-among-patch-tuesday-cves-this-month\/"},"modified":"2025-09-14T16:52:45","modified_gmt":"2025-09-14T16:52:45","slug":"two-zero-days-among-patch-tuesday-cves-this-month","status":"publish","type":"post","link":"http:\/\/ft365.org\/index.php\/2025\/09\/14\/two-zero-days-among-patch-tuesday-cves-this-month\/","title":{"rendered":"Two Zero-Days Among Patch Tuesday CVEs This Month"},"content":{"rendered":"<div>\n<p><img decoding=\"async\" src=\"https:\/\/ft365.org\/wp-content\/uploads\/2025\/06\/localimages\/ea721ff9-8ba4-4d88-b386-57e9e1606077.jpg?width=64&#038;height=64&#038;mode=crop&#038;scale=both&#038;format=webp\" alt=\"Photo of Phil Muncaster\" loading=\"lazy\"><\/p>\n<\/div>\n<div id=\"cphContent_pnlArticleBody\">\n<div id=\"layout-a6489a8e-a17c-4f1b-9daf-cbc9911d91e1\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>Microsoft issued updates to fix 81 vulnerabilities in this month\u2019s Patch Tuesday yesterday, including two classed as zero-days which have been disclosed but not yet exploited.<\/p>\n<p>The first is CVE-2024-21907, which relates to improper handling of exceptional conditions in Newtonsoft.Json \u2013 a part of SQL server. The bug was originally made public in January 2024, although it may have been flagged as far back as 2018, according to Adam Barnett, lead software engineer at Rapid7.<\/p>\n<p>\u201cWhat happens if you ask SQL Server to deserialize a JSON object with thousands of levels of nested objects? If you guessed denial of service, then you are good at guessing, because that\u2019s what\u00a0CVE-2024-21907\u00a0describes,\u201d he explained.<\/p>\n<p>\u201cAs zero-day vulnerabilities go, it doesn\u2019t seem particularly terrifying, since presumably the worst an attacker can do is knock down a service, which can then be picked up again. Of course, that\u2019s all relative, since some SQL Server instances are doing very important work: think hospitals, airports\u00a0and other critical infrastructure.\u201d<\/p>\n<p><em>Read more on Patch Tuesday:\u00a0Read more on Patch Tuesday: Microsoft Fixes Seven Zero-Days in May Patch Tuesday<\/em><\/p>\n<p>The second zero-day is CVE-2025-55234, a Windows SMB elevation of privilege (EoP) vulnerability that can be exploited remotely.<\/p>\n<p>\u201cMicrosoft says that an attacker with network access would be able to perform a replay attack against a target host, which could result in the attacker gaining additional privileges, which could lead to code execution,\u201d explained Immersive senior director of threat research, Kev Breen. \u00a0<\/p>\n<p>\u201cIt is noted that the SMB Server already has the ability to harden against replay attacks by enabling features like SMB Server Signing and Extended Protection for Authentication. Before turning on these additional security features, organizations should check the potential impact, as enabling these features may adversely affect some third-party integrations or network configurations.\u201d<\/p>\n<p>Microsoft is also offering users audit capabilities to help them assess any compatibility issues before turning on the additional security features.<\/p>\n<h2>Exploitation More Likely<\/h2>\n<p>Breen flagged several other EoP vulnerabilities fixed this Patch Tuesday which are labelled \u201cexploitation more likely\u201d by Microsoft. These include:<\/p>\n<ul>\n<li>CVE-2025-54110, which impacts the Windows Kernel<\/li>\n<li>CVE-2025-54093 (Windows TCP\/IP Driver)<\/li>\n<li>CVE-2025-54098 in the Windows Hyper-V system<\/li>\n<\/ul>\n<p>\u201cWhile local privilege escalation vulnerabilities don\u2019t often get high CVSS scores, that doesn\u2019t make them any less important. Once a threat actor gains initial code execution through a remote code execution (RCE) vulnerability, stolen credentials\u00a0or a phishing attack, they will then try to escalate their permissions both locally on the host and, if possible, across the domain,\u201d he explained.<\/p>\n<p>\u201cWith system or administrator-level permissions, threat actors are able to disable security tooling and logging as well as deploy additional malware or tools in order to move laterally across the network.\u201d<\/p>\n<p>In total, there are 41 EoP vulnerabilities and 22 RCE flaws to fix, although only two of the former and five of the latter are rated critical.<\/p>\n<\/p><\/div>\n<p>Image\u00a0credit: gguy \/ Shutterstock.com<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft issued updates to fix 81 vulnerabilities in this month\u2019s Patch Tuesday yesterday, including two classed as zero-days which have been disclosed but not yet exploited. The first is CVE-2024-21907, which relates to improper handling of exceptional conditions in Newtonsoft.Json \u2013 a part of SQL server. The bug was originally made public in January 2024<\/p>\n","protected":false},"author":2,"featured_media":2813,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2812","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2812-650154f7-7781-4a5c-80a1-8e1dd5b8949d.jpg",300,300,false],"thumbnail":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2812-650154f7-7781-4a5c-80a1-8e1dd5b8949d-150x150.jpg",150,150,true],"medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2812-650154f7-7781-4a5c-80a1-8e1dd5b8949d.jpg",300,300,false],"medium_large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2812-650154f7-7781-4a5c-80a1-8e1dd5b8949d.jpg",300,300,false],"large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2812-650154f7-7781-4a5c-80a1-8e1dd5b8949d.jpg",300,300,false],"1536x1536":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2812-650154f7-7781-4a5c-80a1-8e1dd5b8949d.jpg",300,300,false],"2048x2048":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2812-650154f7-7781-4a5c-80a1-8e1dd5b8949d.jpg",300,300,false],"morenews-featured":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2812-650154f7-7781-4a5c-80a1-8e1dd5b8949d.jpg",300,300,false],"morenews-large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2812-650154f7-7781-4a5c-80a1-8e1dd5b8949d.jpg",300,300,false],"morenews-medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2812-650154f7-7781-4a5c-80a1-8e1dd5b8949d.jpg",300,300,false],"crawlomatic_preview_image":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/09\/2812-650154f7-7781-4a5c-80a1-8e1dd5b8949d-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"http:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"http:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/2812","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=2812"}],"version-history":[{"count":0,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/2812\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/2813"}],"wp:attachment":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=2812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=2812"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=2812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}