Overview
Microsoft's January 2025 Patch Tuesday is the largest patch release in recent memory, covering 159 CVEs across Windows, Office, Azure, and developer tools.
Critical Priorities
CVE-2025-21298 — Windows OLE RCE (CVSS 9.8)
Email preview in Outlook triggers RCE without user interaction. Apply immediately. Interim: set Outlook to read email in plain text.
CVE-2025-21333 — Hyper-V PrivEsc (Zero-Day, Exploited)
Local attacker achieves SYSTEM on Windows 11 and Server 2025. Confirmed exploited in the wild.
CVE-2025-21311 — Windows NTLM V1 Elevation (CVSS 9.8)
Critical elevation via NTLM V1 — disable NTLMv1 in environment before patching for defense-in-depth.
Patch Priority Order
- Windows domain controllers (LDAP, Kerberos bugs)
- Exchange and Outlook servers (OLE RCE)
- Hyper-V hosts
- All endpoints (3 exploited zero-days)
- Azure-connected services
Testing Notes
- KB5050009 has known printing issues on some HP LaserJet models — test before broad deployment
- Server 2025 LSASS restart required for Kerberos patch KB5049613