HomeMicrosoft Patch Tuesday › March 2025

Microsoft Patch Tuesday, March 2025

·

Microsoft's March 2025 security release, published March 11, 2025: 33 updates fixing 50 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 1 CVE from this release is on the Senserva hot list today (as of 2026-08-30), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
33
Updates (KBs)
50
CVEs fixed
9
On the CISA KEV list
1
Ransomware-linked
0
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2025-24985Windows Fast FAT File System Driver Remote Code Execution VulnerabilityCVSS 7.8Exploited
CVE-2025-24993Windows NTFS Remote Code Execution VulnerabilityCVSS 7.8Exploited
CVE-2025-21418Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-21391Windows Storage Elevation of Privilege VulnerabilityCVSS 7.1Exploited
CVE-2025-26633Microsoft Management Console Security Feature Bypass VulnerabilityCVSS 7.0ExploitedRansomware Hot now
CVE-2025-24983Windows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityCVSS 7.0Exploited
CVE-2025-24054NTLM Hash Disclosure Spoofing VulnerabilityCVSS 6.5Exploited
CVE-2025-24991Windows NTFS Information Disclosure VulnerabilityCVSS 5.5Exploited
CVE-2025-24984Windows NTFS Information Disclosure VulnerabilityCVSS 4.6Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2025-24051Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-24056Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-26645Remote Desktop Client Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21368Microsoft Digest Authentication Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21369Microsoft Digest Authentication Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21208Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21406Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21407Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21410Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21190Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21200Windows Telephony Service Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-21201Windows Telephony Server Remote Code Execution VulnerabilityCVSS 8.8

Products fixed this month

Windows 10 Version 1809 for 32-bit Systems (25)Windows 10 Version 1809 for x64-based Systems (24)Windows Server 2019 (24)Microsoft Office 2019 for 32-bit editions (6)Microsoft Office 2019 for 64-bit editions (6)Microsoft 365 Apps for Enterprise for 32-bit Systems (3)Office Online Server (3)ASP.NET Core 8.0 (2)ASP.NET Core 9.0 (2)Microsoft Visual Studio 2022 version 17.12 (2)

Every update in this release

All 33 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5053596 Exploited RansomwareHigh8.833Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053603 Exploited RansomwareHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053638 Exploited RansomwareHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053606 Exploited RansomwareHigh8.830Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053602 Exploited RansomwareHigh8.833Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053598 Exploited RansomwareHigh8.836Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053636 Exploited RansomwareHigh8.836Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053599 Exploited RansomwareHigh8.835Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053618 Exploited RansomwareHigh8.828Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053594 Exploited RansomwareHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053620 Exploited RansomwareHigh8.821Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053627 Exploited RansomwareHigh8.821Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053886 Exploited RansomwareHigh8.824Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053887 Exploited RansomwareHigh8.825Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053888 Exploited RansomwareHigh8.819Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5053995 Exploited RansomwareHigh8.819Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052000 ExploitedHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5051979 ExploitedHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5051974 ExploitedHigh8.832Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5051989 ExploitedHigh8.832Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5051987 ExploitedHigh8.838Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5051980 ExploitedHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052040 ExploitedHigh8.827Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5052006 ExploitedHigh8.833Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5002693High7.83Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002697High7.81Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002690High7.83Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5002696High7.83Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5002662High7.82Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002694High7.81Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5054229High7.01ASP.NET Core 8.0, ASP.NET Core 9.0, Microsoft Visual Studio 2022 version 17.12Support · Catalog
KB5054230High7.01ASP.NET Core 8.0, ASP.NET Core 9.0, Microsoft Visual Studio 2022 version 17.12Support · Catalog
KB5053593Medium4.31Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
Take this release to your AI

Composed from the March 2025 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see the same thing in your own tenant.

Siemserva by Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and returns every missing update ranked by what is actually being exploited, alongside all 650+ configuration checks.

1Find it2Fix it3Prove it
Start my free auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.