HomeMicrosoft Patch Tuesday › March 2025

Microsoft Patch Tuesday, March 2025

·

Microsoft's March 2025 security release, published March 11, 2025: 33 updates fixing 52 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 1 CVE from this release is on the Senserva hot list today (as of 2026-09-18), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
33
Updates (KBs)
52
CVEs fixed
9
On the CISA KEV list
1
Ransomware-linked
0
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2025-24985Windows Fast FAT File System Driver Remote Code Execution VulnerabilityCVSS 7.8Exploited
CVE-2025-24993Windows NTFS Remote Code Execution VulnerabilityCVSS 7.8Exploited
CVE-2025-21418Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-21391Windows Storage Elevation of Privilege VulnerabilityCVSS 7.1Exploited
CVE-2025-26633Microsoft Management Console Security Feature Bypass VulnerabilityCVSS 7.0ExploitedRansomware Hot now
CVE-2025-24983Windows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityCVSS 7.0Exploited
CVE-2025-24054NTLM Hash Disclosure Spoofing VulnerabilityCVSS 6.5Exploited
CVE-2025-24991Windows NTFS Information Disclosure VulnerabilityCVSS 5.5Exploited
CVE-2025-24984Windows NTFS Information Disclosure VulnerabilityCVSS 4.6Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2025-24051Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-24056Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-26645Remote Desktop Client Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21368Microsoft Digest Authentication Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21369Microsoft Digest Authentication Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21208Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21406Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21407Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21410Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21190Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21200Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21201Windows Telephony Server Remote Code Execution VulnerabilityCVSS 8.8

Products fixed this month

Windows 10 Version 1809 for 32-bit Systems (25)Windows 10 Version 1809 for x64-based Systems (24)Windows Server 2019 (24)Microsoft Office 2019 for 32-bit editions (6)Microsoft Office 2019 for 64-bit editions (6)Microsoft 365 Apps for Enterprise for 32-bit Systems (3)Office Online Server (3)ASP.NET Core 8.0 (2)ASP.NET Core 9.0 (2)Microsoft Visual Studio 2022 version 17.12 (2)

Every update in this release

All 33 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5053596 Exploited RansomwareHigh8.833Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053603 Exploited RansomwareHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053638 Exploited RansomwareHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053606 Exploited RansomwareHigh8.830Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053602 Exploited RansomwareHigh8.833Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053598 Exploited RansomwareHigh8.836Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053636 Exploited RansomwareHigh8.836Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053599 Exploited RansomwareHigh8.835Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053618 Exploited RansomwareHigh8.828Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053594 Exploited RansomwareHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053620 Exploited RansomwareHigh8.821Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053627 Exploited RansomwareHigh8.821Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053886 Exploited RansomwareHigh8.824Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053887 Exploited RansomwareHigh8.825Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053888 Exploited RansomwareHigh8.819Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053995 Exploited RansomwareHigh8.819Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052000 ExploitedHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5051979 ExploitedHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5051974 ExploitedHigh8.832Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5051989 ExploitedHigh8.832Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5051987 ExploitedHigh8.838Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5051980 ExploitedHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052040 ExploitedHigh8.827Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052006 ExploitedHigh8.833Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5002693High7.83Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002697High7.81Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002690High7.83Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5002696High7.83Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5002662High7.82Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002694High7.81Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5054229High7.01ASP.NET Core 8.0, ASP.NET Core 9.0, Microsoft Visual Studio 2022 version 17.12Support · Catalog
KB5054230High7.01ASP.NET Core 8.0, ASP.NET Core 9.0, Microsoft Visual Studio 2022 version 17.12Support · Catalog
KB5053593Medium4.31Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
Take this release to your AI

Composed from the March 2025 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.