Monthly Fallout Report

February 2025 Fallout

67 vulnerabilities, 4 zero-days, 2 actively exploited. NTLM hash disclosure and Winsock privilege escalation causing headaches.

Damage Rating
67
Vulnerabilities
4
Zero-Days
3
Critical RCEs
2
KB Updates

Fallout Timeline

Initial Release — Patch Tuesday Day 0

February 2025 delivers 67 vulnerabilities including 4 zero-days — 2 of which (CVE-2025-21391 and CVE-2025-21418) are actively exploited in the wild. NTLM hash disclosure risk via CVE-2025-21377 raises pass-the-hash concerns for organizations still relying on NTLM. Critical RCEs in LDAP and Excel round out a month that demands prompt patching, especially for Active Directory environments.

CVE-2025-21391 CVSS 7.1

Windows Storage Elevation of Privilege — actively exploited in the wild.

CVE-2025-21418 CVSS 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege — actively exploited.

CVE-2025-21377 CVSS 6.5

Windows NTLM Hash Disclosure — enables pass-the-hash attacks without user interaction.

CVE-2025-21194 CVSS 7.1

Windows Security Feature Bypass vulnerability.

Sources: r/sysadmin · BleepingComputer · MSRC

72 Hours Out +3 Days Issues Active

Three days in, February's zero-days are the main concern. NTLMv2 hash disclosure is a real risk for any environment not yet migrated off NTLM. Winsock privilege escalation reports are trickling in. LDAP and Excel RCE risks are being monitored but no widespread exploitation confirmed yet. Patch your domain controllers and Exchange servers first.

Sources: r/sysadmin · BleepingComputer

2 Weeks Out +14 Days Largely Resolved

Two weeks out, February ended up being relatively quiet on the operational disruption front. No major widespread breakage surfaced beyond the zero-day concerns. Minor isolated reports of network connectivity hiccups and File Explorer UI glitches, but nothing requiring emergency rollbacks. Microsoft smoothed things out without needing out-of-band updates.

Sources: r/sysadmin

Resources