Microsoft’s March 2025 Patch Tuesday includes six actively exploited zero-day vulnerabilities. Learn about the critical vulnerabilities and why immediate updates are essential.

Microsoft just dropped its March 2025 Patch Tuesday update, which includes 57 fixes though closer to 70 with third-party vulnerabilities included. The update addresses some critical security issues that require immediate attention, including the following six zero-day vulnerabilities that hackers are actively exploiting.
There’s a seventh vulnerability – a remote code execution bug in Windows Access – that’s been made public but doesn’t seem to be actively exploited yet.
True to form, Microsoft kept with tradition and didn’t share any digital fingerprints that could help security teams spot if they’ve been hit.
Microsoft also highlighted several nasty bugs that could allow attackers to run malicious code over networks. The scariest part is that they can do this without needing user interaction.
One standout is CVE-2025-26645, a path traversal vulnerability in Remote Desktop Client. This one is a doozy because if you connect to a compromised Remote Desktop Server using a vulnerable client, the attacker could immediately execute code on your computer. Disaster.
Microsoft strongly advised Windows administrators to prioritize patching critical remote code execution vulnerabilities affecting Windows Subsystem for Linux, Windows DNS Server, Remote Desktop Service, and Microsoft Office.
Download TechRepublic Premium’s customizable patch management policy, which provides guidelines for the appropriate application of patches in an organization.
Allison is a contributing writer for TechRepublic, specializing in news for IT service providers. She has crafted diverse marketing, public relations, and digital content for top IT, financial, healthcare, and manufacturing organizations through various roles. Allison has extensive experience with midsize B2B and channel companies, focusing on event strategy, brand-building, content and education strategy, and community engagement. With over a decade in the industry, she brings deep insights and expertise to her work. In her personal life, Allison enjoys hiking and photography.