Trinetri logo
Updated monthly

Microsoft Patch Tuesday
April 2025

Microsoft's April 2025 Patch Tuesday fixes 127 vulnerabilities across Windows, Microsoft Office and Azure - 17 rated Critical, one already exploited in the wild. Patch CVE-2025-29824 first.

Released April 8, 2025, 10:00 PT1 actively exploited35 KB articles to deploy

April 2025 Patch Tuesday at a glance

127
Microsoft CVEs
excl. Edge & Azure Linux
17
Critical
13% of the release
1
Actively exploited
CVE-2025-29824
0
Publicly disclosed
known before the patch
9.9
Highest CVSS
CVE-2025-30390
35
KB articles
what you actually deploy

Why this number differs from other roundups. Microsoft's April 2025 release document lists 375 entries. 232 are Azure Linux (Mariner) OS package updates and 16 are republished Chromium fixes for Edge - neither is a Microsoft product vulnerability. The 127 above is the real Patch Tuesday set. See the breakdown →

Priority order

Patch these first

Ranked by exploitation reality, not score alone. This month's exploited flaw is rated Important - a severity-sorted list would bury it.

Patch this week

Publicly disclosed

Details are already public. Working exploits typically follow within days.

Nothing was disclosed before the patch shipped.

Patch this cycle

Critical remote code execution

No known exploitation yet, but network-reachable and high impact.

CVE-2025-26663Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityCriticalCVSS 8.1RCEKB5055518CVE-2025-26670Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution VulnerabilityCriticalCVSS 8.1RCEKB5055518CVE-2025-27480Windows Remote Desktop Services Remote Code Execution VulnerabilityCriticalCVSS 8.1RCEKB5055519See all 17 Critical →
The numbers

What’s in this release

Where the 375 entries actually come from

Most roundups quote a single number. These are three unrelated release streams.

127 Microsoft products232 Azure Linux (Mariner)16 Edge (Chromium)

Severity

Microsoft channel only · 127 CVEs

April 2025 severity breakdown
Critical17
Important110
Moderate0
Low0

Impact type

What an attacker gains if it works

April 2025 impact breakdown
Elevation of Privilege52
Remote Code Execution32
Information Disclosure19
Denial of Service14
Security Feature Bypass9
Spoofing1

Most-affected components

Where this month’s fixes concentrate - filter by any of them in the table below

Microsoft Office8Windows Routing and Remote Access Service (RRAS)8Windows Standards-Based Storage Management Service6Windows DWM Core Library5Windows NTFS5Windows Telephony Service5Microsoft Office Excel4Windows LDAP - Lightweight Directory Access Protocol4Microsoft Office Word3Windows Digital Media3Windows Kerberos3Windows Win32K - GRFX3
Every patch

Browse all 375 entries

Sorted by risk by default: exploited first, then publicly disclosed, then severity, then CVSS. Search by CVE, title, component or KB number.

Showing 127 of 127
127 Microsoft vulnerabilities in the April 2025 Patch Tuesday, sortable by severity, CVSS and exploit status.
TitleStatusKB
ImportantCVE-2025-29824Windows Common Log File System Driver Elevation of Privilege VulnerabilityEoP7.8ExploitedWindows Common Log File System Driver5055518 +13
CriticalCVE-2025-30390Azure ML Compute Elevation of Privilege VulnerabilityEoP9.9More likelyAzure
CriticalCVE-2025-26663Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityRCE8.1More likelyWindows LDAP - Lightweight Directory Access Protocol5055518 +13
CriticalCVE-2025-26670Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution VulnerabilityRCE8.1More likelyWindows LDAP - Lightweight Directory Access Protocol5055518 +13
CriticalCVE-2025-27480Windows Remote Desktop Services Remote Code Execution VulnerabilityRCE8.1More likelyRemote Desktop Gateway Service5055519 +6
CriticalCVE-2025-27482Windows Remote Desktop Services Remote Code Execution VulnerabilityRCE8.1More likelyRemote Desktop Gateway Service5055519 +4
ImportantCVE-2025-29794Microsoft SharePoint Remote Code Execution VulnerabilityRCE8.8More likelyMicrosoft Office SharePoint5002691 +2
ImportantCVE-2025-27727Windows Installer Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Installer5055518 +13
ImportantCVE-2025-29812DirectX Graphics Kernel Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Kernel Memory5055523 +3
ImportantCVE-2025-29792Microsoft Office Elevation of Privilege VulnerabilityEoP7.3More likelyMicrosoft Office5002623 +1
ImportantCVE-2025-29793Microsoft SharePoint Remote Code Execution VulnerabilityRCE7.2More likelyMicrosoft Office SharePoint5002691 +2
ImportantCVE-2025-29809Windows Kerberos Security Feature Bypass VulnerabilityBypass7.1More likelyWindows Kerberos5055518 +7
ImportantCVE-2025-27472Windows Mark of the Web Security Feature Bypass VulnerabilityBypass5.4More likelyWindows Mark of the Web (MOTW)5055547 +2
CriticalCVE-2025-27745Microsoft Office Remote Code Execution VulnerabilityRCE7.8Microsoft Office5002623 +1
CriticalCVE-2025-27748Microsoft Office Remote Code Execution VulnerabilityRCE7.8Microsoft Office5002623 +1
CriticalCVE-2025-27749Microsoft Office Remote Code Execution VulnerabilityRCE7.8Microsoft Office5002623 +1
CriticalCVE-2025-27752Microsoft Excel Remote Code Execution VulnerabilityRCE7.8Microsoft Office Excel5002623 +1
CriticalCVE-2025-29791Microsoft Excel Remote Code Execution VulnerabilityRCE7.8Microsoft Office5002623 +1
CriticalCVE-2025-26686Windows TCP/IP Remote Code Execution VulnerabilityRCE7.5Windows TCP/IP5055518 +13
CriticalCVE-2025-27491Windows Hyper-V Remote Code Execution VulnerabilityRCE7.1Windows Hyper-V5055518 +7
ImportantCVE-2025-21205Windows Telephony Service Remote Code Execution VulnerabilityRCE8.8Windows Telephony Service5055518 +13
ImportantCVE-2025-21221Windows Telephony Service Remote Code Execution VulnerabilityRCE8.8Windows Telephony Service5055518 +13
ImportantCVE-2025-21222Windows Telephony Service Remote Code Execution VulnerabilityRCE8.8Windows Telephony Service5055518 +13
ImportantCVE-2025-26647Windows Kerberos Elevation of Privilege VulnerabilityEoP8.8Windows Kerberos5055519 +10
ImportantCVE-2025-26669Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInfo Disc.8.8Windows Routing and Remote Access Service (RRAS)5055518 +13
Your move

What your IT team should do

The same five steps every month, in the order that reduces risk fastest.

Test the known-issue candidates

Check the Windows release health dashboard before promoting past ring 1, and have the rollback path written down before you need it. Kernel, networking and authentication fixes are the ones that historically break things.

12 Patch Management Best Practices for 2026

Verify installed state, then evidence it

Confirm the patch is actually present on each endpoint rather than trusting that "deployment succeeded". Keep the resulting report - it is the artefact auditors ask for, and reconstructing it later is far more work than capturing it now.

Patch Management: The Complete Guide

Trinetri does steps two through five automatically - detecting the 35 KB articles across every endpoint, staging them in rings, verifying installed state and producing the compliance evidence. See patch management →

Patch Tuesday FAQ

Patch Tuesday falls on the second Tuesday of every month, with updates going live at 10:00 a.m. Pacific Time. Microsoft introduced the practice in October 2003, following the Blaster worm, to cut distribution costs and give administrators a predictable cadence instead of patches arriving at random. The 10:00 a.m. timing is deliberate: it leaves a full working week to remediate before the weekend. Internally Microsoft calls it the "B" release; optional "C" and "D" preview releases follow later in the month. The next Patch Tuesday is September 8, 2026.

Microsoft fixed 127 vulnerabilities in April 2025, across Windows, Microsoft Office, Azure and Developer Tools. 17 are rated Critical, 0 were publicly disclosed before the patch shipped, and 1 was already being exploited. Note that Microsoft's release document lists 375 entries in total, but 232 of those are Azure Linux package updates and 16 are republished Chromium fixes for Edge, which is why other sources sometimes quote a much larger number.

Exploit Wednesday is the day after Patch Tuesday. Attackers compare the newly released patches against the previous version to locate the flaw each one fixes, then build working exploits from that difference - often within 24 to 48 hours. It is the reason the deployment window matters as much as the patch itself: every hour a Critical remote code execution fix sits undeployed is an hour of measurable exposure.

A workable target for most organisations: actively exploited vulnerabilities within 24 hours, publicly disclosed ones within 72 hours, remaining Critical fixes within seven days, and everything else within the month. CISA's Known Exploited Vulnerabilities catalogue sets binding deadlines for US federal agencies and is a reasonable benchmark for everyone else. Stage the rollout in rings rather than deploying everywhere at once, so a regression is caught on a pilot group instead of in production.

An out-of-band update is a patch released outside the monthly cycle because the risk will not wait for the next Patch Tuesday. Microsoft issues them for actively exploited flaws with no mitigation - most famously during the WannaCry outbreak in 2017, when it took the unusual step of patching versions of Windows that were already out of support.

Yes. Adobe aligned its releases with Patch Tuesday in November 2012, and both SAP's Security Patch Day and Oracle's quarterly Critical Patch Updates are coordinated to the same week. Part of the reason is defensive: staggered releases let attackers reverse-engineer one vendor's patch to find the same underlying flaw in another's still-unpatched product. For IT teams it means the second Tuesday is rarely just a Microsoft problem.

Edge is built on Chromium, so most of its security fixes originate with the Chromium project and are republished by Microsoft under their own CVE identifiers. They ship on Chromium's cadence rather than the Patch Tuesday cycle, and they are delivered by Edge's own updater rather than Windows Update. Counting the 16 Edge entries alongside Microsoft product fixes would inflate the headline number and imply work for your Windows Update rings that does not exist.

Stop the sprawl. Eliminate the guesswork.

Ready to See Autonomous Endpoint Management in Action?

Experience how Trinetri transforms endpoint chaos into clarity. Try the 30 minute demo session, our experts will walk you through how AI-powered automation, real-time visibility, and unified control can secure your entire hybrid environment, without the overhead.