Monthly Fallout Report
February 2025 Fallout
67 vulnerabilities, 4 zero-days, 2 actively exploited. NTLM hash disclosure and Winsock privilege escalation causing headaches.
Tired of patch chaos? Automox automates patching across Windows, Mac, and Linux — so you're never caught off guard on Patch Tuesday.
Try Free →Fallout Timeline
February 2025 delivers 67 vulnerabilities including 4 zero-days — 2 of which (CVE-2025-21391 and CVE-2025-21418) are actively exploited in the wild. NTLM hash disclosure risk via CVE-2025-21377 raises pass-the-hash concerns for organizations still relying on NTLM. Critical RCEs in LDAP and Excel round out a month that demands prompt patching, especially for Active Directory environments.
Windows Ancillary Function Driver for WinSock Elevation of Privilege — actively exploited.
Windows NTLM Hash Disclosure — enables pass-the-hash attacks without user interaction.
Sources: r/sysadmin · BleepingComputer · MSRC
Three days in, February's zero-days are the main concern. NTLMv2 hash disclosure is a real risk for any environment not yet migrated off NTLM. Winsock privilege escalation reports are trickling in. LDAP and Excel RCE risks are being monitored but no widespread exploitation confirmed yet. Patch your domain controllers and Exchange servers first.
Sources: r/sysadmin · BleepingComputer
Two weeks out, February ended up being relatively quiet on the operational disruption front. No major widespread breakage surfaced beyond the zero-day concerns. Minor isolated reports of network connectivity hiccups and File Explorer UI glitches, but nothing requiring emergency rollbacks. Microsoft smoothed things out without needing out-of-band updates.
Sources: r/sysadmin
Resources