Monthly Fallout Report

April 2025 Fallout

121 vulnerabilities, Edge Startup Assistant crashes, Windows Explorer freezes, and a surprise DoS via inetpub folder.

Damage Rating
121
Vulnerabilities
2
Zero-Days
12
Critical RCEs
3
KB Updates

Fallout Timeline

Initial Release — Patch Tuesday Day 0

April 2025 tackles 121 vulnerabilities including 2 actively exploited zero-days and 12 criticals. The Windows CLFS Driver elevation of privilege (CVE-2025-29824) is being actively exploited — patch immediately. Hyper-V RCE (CVE-2025-29827) is also critical. A quirky side effect of April's inetpub folder fix creates a denial-of-service opportunity for non-admin users — something to be aware of in shared environments.

CVE-2025-29824 CVSS 7.8

Windows CLFS Driver Elevation of Privilege — actively exploited in the wild.

CVE-2025-29827 CVSS 8.1

Windows Hyper-V Remote Code Execution — critical, patch immediately.

Sources: r/sysadmin · BleepingComputer · AskWoody

72 Hours Out +3 Days Issues Active

Three days in, Edge Startup Assistant is crashing left and right — especially in EU environments due to DMA compliance changes. Windows Explorer freezes are being widely reported. Printer connectivity issues are hitting Server 2022 virtual environments hard, and some admins are rolling back KB5044281. The inetpub folder junction point issue is getting attention in the security community.

Sources: r/sysadmin · AskWoody

2 Weeks Out +14 Days Still Active

Two weeks out, no major new disruptions have surfaced but several issues persist. Edge Startup Assistant crashes and Windows Explorer freezes continue — workarounds include disabling the Startup Assistant or rebooting. Server 2022 printer and VM performance issues remain for some. The inetpub junction point DoS vulnerability has been noted by security researchers but no patch yet — monitor community reports for updates.

Sources: r/sysadmin · AskWoody

Resources