Patch Tuesday: Microsoft Patches Two Zero-Days and a Critical NTLM Flaw
September's Big Patch Day
As with every second Tuesday of the month, Windows administrators worldwide were nervously refreshing their Windows Update service. As part of the September "Patch Tuesday," Microsoft released 84 security fixes, 8 of which were rated as critical. This time, however, the bundle included two particularly nasty surprises.
Two Zero-Days Served on a Silver Platter
Among the patched holes were two zero-day vulnerabilities, meaning they were known and potentially actively exploited by cybercriminals before Microsoft could release a fix.
- CVE-2025-55234 (CVSS 8.8): This flaw in the Windows SMB Server service allowed for relay attacks, enabling attackers to impersonate users on a network. The vulnerability was publicly disclosed, further increasing the risk of its widespread exploitation.
- The second vulnerability, though less detailed, was also actively exploited, giving attackers unauthorized access to systems.
Watch Out for NTLM!
The biggest stir, however, was caused by the critical vulnerability CVE-2025-54918 (CVSS 8.8) in the Windows NTLM authentication mechanism. This flaw allowed an authenticated (but low-privileged) attacker to remotely elevate their privileges to the SYSTEM level. In simpler terms: someone with basic access could easily become the lord and master of the server. It's like giving an intern the keys to the server room and the code to the safe.
This month, Microsoft also patched a range of other critical vulnerabilities in products like Microsoft Office, Windows Graphics Component, and Hyper-V, which could lead to remote code execution.
The recommendation, as always, is simple and boring, but crucial: patch your systems before cybercriminals do it for you, because unlike us, they never take a day off.
If you want to better understand the zero-day phenomenon and their global market, read our comprehensive guide to 0-day vulnerabilities.
Sources: CrowdStrike, Redmond Magazine
About the Author

Dyrektor ds. Technologii w SecurHub.pl
Doktorant z zakresu neuronauki poznawczej. Psycholog i ekspert IT specjalizujący się w cyberbezpieczeństwie.
Powiązane artykuły
Pilny Alert: Google Łata Krytyczną Dziurę w Chrome Wykorzystywaną przez Hakerów
Google wydało nadzwyczajną aktualizację dla przeglądarki Chrome, aby załatać lukę zero-day (CVE-2025-10585), która jest już aktywnie wykorzystywana w atakach. Nie zwlekaj, zaktualizuj przeglądarkę!

Najważniejsze krytyczne podatności tygodnia: wrzesień 2025
Przegląd najgroźniejszych podatności cyberbezpieczeństwa zgłoszonych w drugim tygodniu września 2025 – priorytetowe luki dotyczą Windows, Microsoft Office, Android oraz ICS.
Cl0p kradnie dane przez lukę w Oracle – czy twoja firma jest następna w kolejce?
Grupa ransomware Cl0p wykorzystała zero-day w Oracle E-Business Suite (CVE-2025-61882), kradnąc dane od wielu firm w sierpniu. Oracle właśnie wydał łatkę, ale eksperci ostrzegają: sprawdźcie swoje systemy natychmiast, bo ataki trwają.
Komentarze
Ładowanie komentarzy...