CVEs have been published or revised in the Security Update Guide
April 11, 2025
These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:
CVE-2025-21204
Title: Windows Process Activation Elevation of Privilege Vulnerability
Version: 2.1
Reason for revision: Added FAQ to explain that after installing the updates listed in the Security Updates table for your operating system, a new %systemdrive%\inetpub folder will be created on your device. This folder should not be deleted regardless of whether Internet Information Services (IIS) is active on the target device. This behavior is part of changes that increase protection and does not require any action from IT admins and end users. This is an informational change only.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Important
Customer action required: Yes
CVE-2025-26647
Title: Windows Kerberos Elevation of Privilege Vulnerability
Version: 1.1
Reason for revision: Updated FAQ information. This is an informational change only.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Important
Customer action required: Yes
CVE-2025-27732
Title: Windows Graphics Component Elevation of Privilege Vulnerability
Version: 2.0
Reason for revision: The security updates for Windows 10 for 32-bit Systems and Windows 10 for x64-based Systems are now available. See the Security Updates table for more information.
Originally released: April 8, 2025
Last updated: April 2, 2025
Aggregate CVE severity rating: Important
Customer action required: Yes
CVE-2025-27740
Title: Active Directory Certificate Services Elevation of Privilege Vulnerability
Version: 1.1
Reason for revision: Updated FAQ information. This is an informational change only.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Important
Customer action required: Yes
CVE-2025-27745
Title: Microsoft Office Remote Code Execution Vulnerability
Version: 2.0
Reason for revision: To address a known issue that customers might experience after installing KB5002700 and that causes Microsoft Word, Microsoft Excel, and Microsoft Outlook to stop responding, Microsoft released KB5002623. Customers who have already installed KB5002700 must also install KB5002623 to correct the known issue. Customers who have not yet installed any updates must install both updates to correct the known issue. These updates can be installed in any order.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Critical
Customer action required: Yes
CVE-2025-27747
Title: Microsoft Word Remote Code Execution Vulnerability
Version: 2.0
Reason for revision: Revised CVE to inform customers that security update 5002692 is temporarily unavailable following some reports that the update can’t be installed. We are currently investigating the issue and will notify customers via a revision to this CVE information when the issue is resolved.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Important
Customer action required: Yes
CVE-2025-27748
Title: Microsoft Office Remote Code Execution Vulnerability
Version: 2.0
Reason for revision: To address a known issue that customers might experience after installing KB5002700 and that causes Microsoft Word, Microsoft Excel, and Microsoft Outlook to stop responding, Microsoft released KB5002623. Customers who have already installed KB5002700 must also install KB5002623 to correct the known issue. Customers who have not yet installed any updates must install both updates to correct the known issue. These updates can be installed in any order.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Critical
Customer action required: Yes
CVE-2025-27749
Title: Microsoft Office Remote Code Execution Vulnerability
Version: 2.0
Reason for revision: To address a known issue that customers might experience after installing KB5002700 and that causes Microsoft Word, Microsoft Excel, and Microsoft Outlook to stop responding, Microsoft released KB5002623. Customers who have already installed KB5002700 must also install KB5002623 to correct the known issue. Customers who have not yet installed any updates must install both updates to correct the known issue. These updates can be installed in any order.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Critical
Customer action required: Yes
CVE-2025-27752
Title: Microsoft Excel Remote Code Execution Vulnerability
Version: 2.0
Reason for revision: To address a known issue that customers might experience after installing KB5002700 and that causes Microsoft Word, Microsoft Excel, and Microsoft Outlook to stop responding, Microsoft released KB5002623. Customers who have already installed KB5002700 must also install KB5002623 to correct the known issue. Customers who have not yet installed any updates must install both updates to correct the known issue. These updates can be installed in any order.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Critical
Customer action required: Yes
CVE-2025-29791
Title: Microsoft Excel Remote Code Execution Vulnerability
Version: 2.0
Reason for revision: To address a known issue that customers might experience after installing KB5002700 and that causes Microsoft Word, Microsoft Excel, and Microsoft Outlook to stop responding, Microsoft released KB5002623. Customers who have already installed KB5002700 must also install KB5002623 to correct the known issue. Customers who have not yet installed any updates must install both updates to correct the known issue. These updates can be installed in any order.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Critical
Customer action required: Yes
CVE-2025-29792
Title: Microsoft Office Elevation of Privilege Vulnerability
Version: 2.0
Reason for revision: To address a known issue that customers might experience after installing KB5002700 and that causes Microsoft Word, Microsoft Excel, and Microsoft Outlook to stop responding, Microsoft released KB5002623. Customers who have already installed KB5002700 must also install KB5002623 to correct the known issue. Customers who have not yet installed any updates must install both updates to correct the known issue. These updates can be installed in any order.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Important
Customer action required: Yes
CVE-2025-29793
Title: Microsoft SharePoint Remote Code Execution Vulnerability
Version: 2.0
Reason for revision: Revised CVE to inform customers that security update 5002692 is temporarily unavailable following some reports that the update can’t be installed. We are currently investigating the issue and will notify customers via a revision to this CVE information when the issue is resolved.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Important
Customer action required: Yes
CVE-2025-29794
Title: Microsoft SharePoint Remote Code Execution Vulnerability
Version: 2.0
Reason for revision: Revised CVE to inform customers that security update 5002692 is temporarily unavailable following some reports that the update can’t be installed. We are currently investigating the issue and will notify customers via a revision to this CVE information when the issue is resolved.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Important
Customer action required: Yes
CVE-2025-29820
Title: Microsoft Word Remote Code Execution Vulnerability
Version: 2.0
Reason for revision: Revised CVE to inform customers that security update 5002692 is temporarily unavailable following some reports that the update can’t be installed. We are currently investigating the issue and will notify customers via a revision to this CVE information when the issue is resolved.
Originally released: April 8, 2025
Last updated: April 10, 2025
Aggregate CVE severity rating: Important
Customer action required: Yes