Overview

Microsoft's January 2025 Patch Tuesday is the largest patch release in recent memory, covering 159 CVEs across Windows, Office, Azure, and developer tools.

Critical Priorities

CVE-2025-21298 — Windows OLE RCE (CVSS 9.8)

Email preview in Outlook triggers RCE without user interaction. Apply immediately. Interim: set Outlook to read email in plain text.

CVE-2025-21333 — Hyper-V PrivEsc (Zero-Day, Exploited)

Local attacker achieves SYSTEM on Windows 11 and Server 2025. Confirmed exploited in the wild.

CVE-2025-21311 — Windows NTLM V1 Elevation (CVSS 9.8)

Critical elevation via NTLM V1 — disable NTLMv1 in environment before patching for defense-in-depth.

Patch Priority Order

  1. Windows domain controllers (LDAP, Kerberos bugs)
  2. Exchange and Outlook servers (OLE RCE)
  3. Hyper-V hosts
  4. All endpoints (3 exploited zero-days)
  5. Azure-connected services

Testing Notes

  • KB5050009 has known printing issues on some HP LaserJet models — test before broad deployment
  • Server 2025 LSASS restart required for Kerberos patch KB5049613