HomeMicrosoft Patch Tuesday › February 2025

Microsoft Patch Tuesday, February 2025

·

Microsoft's February 2025 security release, published February 11, 2025: 25 updates fixing 45 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

25
Updates (KBs)
45
CVEs fixed
2
On the CISA KEV list
0
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2025-21418Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-21391Windows Storage Elevation of Privilege VulnerabilityCVSS 7.1Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2025-21368Microsoft Digest Authentication Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21369Microsoft Digest Authentication Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21208Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21406Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21407Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21410Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21190Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21200Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21201Windows Telephony Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21371Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8

Products fixed this month

Windows 10 Version 1809 for 32-bit Systems (9)Windows 10 Version 1809 for x64-based Systems (9)Windows Server 2019 (9)Microsoft Office 2019 for 32-bit editions (5)Microsoft Office 2019 for 64-bit editions (5)Microsoft SharePoint Enterprise Server 2016 (3)Microsoft SharePoint Server 2019 (3)Microsoft SharePoint Server Subscription Edition (3)Office Online Server (3)Microsoft 365 Apps for Enterprise for 32-bit Systems (2)

Every update in this release

All 17 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5052106 ExploitedHigh8.833Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052105 ExploitedHigh8.837Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052038 ExploitedHigh8.820Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052016 ExploitedHigh8.821Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052020 ExploitedHigh8.823Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052042 ExploitedHigh8.823Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052072 ExploitedHigh8.819Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052032 ExploitedHigh8.820Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5002685High8.01Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002678High8.01Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002681High8.01Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002679High7.85Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5002687High7.85Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5002179High7.82Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002684High7.81Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5002686High7.81Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5051972Medium6.51Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
Take this release to your AI

Composed from the February 2025 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see the same thing in your own tenant.

Siemserva by Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and returns every missing update ranked by what is actually being exploited, alongside all 650+ configuration checks.

1Find it2Fix it3Prove it
Start my free auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.