Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      The Value-Driven AI Roadmap

      September 9, 2025

      This week in AI updates: Mistral’s new Le Chat features, ChatGPT updates, and more (September 5, 2025)

      September 6, 2025

      Designing For TV: Principles, Patterns And Practical Guidance (Part 2)

      September 5, 2025

      Neo4j introduces new graph architecture that allows operational and analytics workloads to be run together

      September 5, 2025

      Lenovo Legion Go 2 specs unveiled: The handheld gaming device to watch this October

      September 10, 2025

      As Windows 10 support ends, users weigh costly extended security program against upgrading to Windows 11

      September 10, 2025

      Lenovo’s Legion Glasses 2 update could change handheld gaming

      September 10, 2025

      Is Lenovo’s refreshed LOQ tower enough to compete? New OLED monitors raise the stakes at IFA 2025

      September 10, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      External Forces Reshaping Financial Services in 2025 and Beyond

      September 10, 2025
      Recent

      External Forces Reshaping Financial Services in 2025 and Beyond

      September 10, 2025

      Why It’s Time to Move from SharePoint On-Premises to SharePoint Online

      September 10, 2025

      Apple’s Big Move: The Future of Mobile

      September 10, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Lenovo Legion Go 2 specs unveiled: The handheld gaming device to watch this October

      September 10, 2025
      Recent

      Lenovo Legion Go 2 specs unveiled: The handheld gaming device to watch this October

      September 10, 2025

      As Windows 10 support ends, users weigh costly extended security program against upgrading to Windows 11

      September 10, 2025

      Lenovo’s Legion Glasses 2 update could change handheld gaming

      September 10, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Microsoft Patch Tuesday September 2025 Fixes Risky Kernel Flaws

    Microsoft Patch Tuesday September 2025 Fixes Risky Kernel Flaws

    September 10, 2025

    Microsoft Patch Tuesday September 2025 Fixes Risky Kernel Flaws

    Three high-risk Windows kernel flaws were among the fixes included in Microsoft’s September 2025 Patch Tuesday updates released today.

    In all, the Patch Tuesday September 2025 updates included fixes for 86 Microsoft CVEs – eight of which are considered high risk – and five non-Microsoft flaws in Chromium-based Edge and SQL Server (CVE-2024-21907 in Newtonsoft.Json).

    The highest rated vulnerabilities patched this month are rated 8.8 under CVSS 3.1, and three of those – in the Windows kernel, NTLM and SMB – are considered at higher risk for exploitation.

    Windows Kernel Vulnerabilities

    CVE-2025-54110 is an 8.8 rated Windows kernel Elevation of Privilege vulnerability that Microsoft labeled as “Exploitation More Likely.”

    CVE-2025-54110, an Integer Overflow or Wraparound vulnerability (CWE-190) in the Windows kernel, could allow an authorized attacker to elevate privileges locally by sending specially crafted input from a sandboxed user-mode process to trigger an integer overflow, resulting in a buffer overflow in the kernel and enabling privilege escalation or sandbox escape. An attacker who successfully exploited the vulnerability could gain SYSTEM privileges, Microsoft said.

    Microsoft credited an anonymous researcher on Mastodon for the discovery.

    Microsoft also labeled two 5.5-rated Windows kernel vulnerabilities as being at higher risk of exploitation.

    CVE-2025-53804 is a Windows kernel-mode driver Information Disclosure vulnerability that Microsoft said “could allow the disclosure of certain memory address within kernel space. Knowing the exact location of kernel memory could be potentially leveraged by an attacker for other malicious activities.”

    The vulnerability was reported by Lewis Lee.

    CVE-2025-53803, credited to Lee and three other researchers, is a Windows kernel memory Information Disclosure vulnerability that could also allow the disclosure of memory addresses through the generation of error messages containing sensitive information.

    Patch Tuesday September 2025: Other High-risk Vulnerabilities

    CVE-2025-54918 is an 8.8-rated Windows NTLM Elevation of Privilege vulnerability and is remotely exploitable and low complexity. Improper authentication in Windows NTLM could allow an authorized attacker to elevate privileges over a network. The vulnerability was credited to Brian De Houwer of Crimson7.

    CVE-2025-55234 is an 8.8-severity Windows SMB Elevation of Privilege/Improper Authentication vulnerability. SMB Server might be susceptible to relay attacks depending on the configuration, and Microsoft advises enabling SMB Server hardening measures.

    Other high-risk vulnerabilities in the Patch Tuesday September 2025 updates include:

    • CVE-2025-54916, a 7.8-rated Windows NTFS Remote Code Execution vulnerability
    • CVE-2025-54098, a 7.8-severity Windows Hyper-V Elevation of Privilege vulnerability
    • CVE-2025-54093, a 7.0 Windows TCP/IP Driver Elevation of Privilege vulnerability

    Adobe, SAP and Ivanti are among the other IT vendors with critical updates out today.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleSAP Patches Critical NetWeaver (CVSS Up to 10.0) and Previously Exploited S/4HANA Flaws
    Next Article New Linux Botnet Combines Cryptomining and DDoS Attacks

    Related Posts

    Development

    How AI is Redefining Traditional GCC Cost Models for Peak Efficiency

    September 10, 2025
    Development

    How to Automate API Documentation Updates with GitHub Actions and OpenAPI Specifications

    September 10, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-51630 – TOTOLINK N350RT Buffer Overflow Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Designing for Touch: How Finger-Friendly UI Enhances UX

    Web Development

    How to Add Custom Style Variations to WordPress Blocks

    Learning Resources

    Distribution Release: Xubuntu 25.04

    News & Updates

    Highlights

    Matrix3D: Large Photogrammetry Model All-in-One

    May 9, 2025

    We present Matrix3D, a unified model that performs several photogrammetry subtasks, including pose estimation, depth…

    Google is intentionally throttling YouTube videos, slowing down users with ad blockers

    June 17, 2025

    CVE-2025-48071 – OpenEXR ZIPS-packed Deep Scan-Line Heap Buffer Overflow

    July 31, 2025

    CVE-2025-6905 – “Car Rental System SQL Injection Vulnerability”

    June 30, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.