security patches

Tech Optimizer
April 30, 2025
A significant vulnerability, designated as CVE-2025-3500, has been identified in Avast Free Antivirus, allowing attackers to gain elevated system privileges and execute malicious code at the kernel level. The vulnerability has a high CVSS score of 8.8 and was publicly disclosed on April 24, 2025, shortly after a patch was implemented. It originates from inadequate validation of user-supplied data in the aswbidsdriver kernel driver, leading to an integer overflow prior to buffer allocation. Attackers must first execute low-privileged code on the target system to exploit this vulnerability. The flaw affects multiple versions of Avast Free Antivirus, specifically versions ranging from 20.1.2397 to 2016.11.1.2262. A fix was released in version 25.3.9983.922, and users are urged to update their software promptly. Security experts recommend enabling automatic updates and using standard user accounts for daily activities to mitigate risks.
Winsage
April 29, 2025
Microsoft has introduced a no-reboot patching feature for Windows 11 and announced hotpatching costs for Windows Server 2025. Windows 7 and Windows Server 2008 R2 have reached their end-of-support status and lack official security patches. However, users of these legacy systems can utilize a micro patching service called 0patch, which delivers micro patches to address specific vulnerabilities without requiring system reboots. On April 29, 2023, Mitja Kolsek, CEO of ACROS Security, announced that support for Windows 7 and Windows Server 2008 R2 would be extended until January 2027 due to high demand. These micro patches are currently the only available security updates for these legacy versions.
AppWizard
April 29, 2025
Google will implement changes to app functionality on Android devices starting next month, affecting over half of all Android users. The changes are driven by the Play Integrity API, which aims to reduce fraud and data theft, resulting in an 80% reduction in unauthorized app usage. Devices running Android 13 and above will experience improved performance, while those on Android 12 or older may face slower performance. Google is also introducing enhanced security signals for developers to assess device trustworthiness. Over half of Android devices have not upgraded to Android 13 or later, and approximately 200 million users remain on Android 12, which no longer receives security patches. Users on Android 12 or 12L are advised to upgrade for better security and performance.
Winsage
April 28, 2025
Microsoft has launched a new subscription service for Hotpatch security fixes, priced at .50 per month per CPU core, available for Windows Server 2025 Standard or Datacenter, and requires a connection to Azure Arc. The service allows security updates without rebooting, although users must reboot four times a year for baseline updates. The AI server sector is projected to grow to .83 billion by 2030, with a CAGR of 34.3% from 2024 to 2030. Analysts expect Microsoft's upcoming earnings report to show earnings per share of .22 and revenue of .43 billion. The consensus rating for Microsoft stock is Strong Buy, with an average price target of 0.86, indicating a potential upside of 25.36%.
Winsage
April 28, 2025
Microsoft will launch a subscription-based hotpatching service for Windows Server 2025 on July 1, 2025, priced at [openai_gpt model="gpt-4o-mini" prompt="Summarize the content and extract only the fact described in the text bellow. The summary shall NOT include a title, introduction and conclusion. Text: Microsoft is set to transform the landscape of enterprise updates with the upcoming launch of its subscription-based hotpatching service for Windows Server 2025. This innovative approach marks a significant shift in how updates will be managed for businesses operating Windows Server outside of Azure. Beginning July 1, 2025, hotpatching will transition from a complimentary preview to a paid subscription model, priced at .50 per CPU core per month. This change extends a capability that was previously exclusive to Azure users, now making it accessible for on-premises servers and hybrid environments through Azure Arc integration. What Is Hotpatching? Hotpatching is a cutting-edge technology that enables the installation of security and critical updates without necessitating a system reboot. Instead of interrupting services or rebooting servers, hotpatching directly updates the in-memory code of running processes. This advancement brings Windows server deployments in line with similar technologies that Linux administrators have enjoyed for years, such as kpatch and ksplice. By allowing updates without reboots, organizations can significantly reduce disruptions while enhancing their security posture. How Does Hotpatching Work? The hotpatching mechanism follows a structured update cycle: Baseline months: In January, April, July, and October, a full cumulative update will be released, requiring a reboot to establish a new baseline. Hotpatch months: In the two months following each baseline month, critical patches will be deployed via hotpatches without requiring any server reboots. This means that servers will only need to reboot approximately four times a year, rather than monthly. On rare occasions, Microsoft may issue a critical security update that requires a reboot even during a hotpatch month, but the aim remains clear: to provide up to eight rebootless hotpatches annually. Why Is Microsoft Moving to a Paid Model? While hotpatching was available at no additional cost during its preview phase, Microsoft is now positioning it as a premium feature for customers seeking maximum uptime, operational simplicity, and rapid security response. According to the Windows Server team at Microsoft, the value of hotpatching encompasses: Reduced Downtime: Maintain operations without the need for scheduling late-night or weekend reboot windows. Faster Updates: Smaller patches facilitate quicker deployments. Enhanced Security: Address vulnerabilities swiftly without delays associated with reboot coordination. Operational Efficiency: Streamlined change management and patch orchestration. Internal teams at Microsoft, including the Xbox division, have already experienced notable efficiency improvements with hotpatching, completing tasks that previously took weeks in just days. Subscription Details Feature Details Launch Date July 1, 2025 Price .50 USD per CPU core per month Editions Supported Windows Server 2025 Standard and Datacenter Deployment Requirement Must be connected to Azure Arc Included with Azure Editions Datacenter: Azure Edition (no extra charge) Patch Frequency 8 hotpatches/year + 4 reboot-required baseline patches Organizations currently utilizing the free preview must either opt out before June 30, 2025, or they will be automatically transitioned into the paid subscription starting in July. While hotpatching offers powerful capabilities, it does not entirely eliminate the need for traditional updates. Certain updates will still necessitate a reboot, including: Major non-security updates. .NET Framework patches. Driver and firmware updates. Emergency out-of-band security patches. As such, administrators should still anticipate occasional downtime, albeit significantly reduced. By incorporating hotpatching into their update strategies, organizations can bolster system availability and streamline their maintenance processes." max_tokens="3500" temperature="0.3" top_p="1.0" best_of="1" presence_penalty="0.1" frequency_penalty="frequency_penalty"].50 per CPU core per month. Hotpatching allows security and critical updates to be installed without rebooting the system, reducing downtime and enhancing security. The update cycle includes four baseline months requiring reboots and eight hotpatches annually without reboots. The service is available for Windows Server 2025 Standard and Datacenter editions and requires connection to Azure Arc. Organizations using the free preview must opt out by June 30, 2025, or will be transitioned to the paid model. Certain updates, such as major non-security updates and .NET Framework patches, will still require reboots.
Tech Optimizer
April 27, 2025
In recent years, the belief that iOS devices are "immune" to viruses has been challenged as cybercriminals increasingly target these platforms. Apple’s security measures, including sandboxing, help isolate apps to prevent the spread of malware. The App Store is strictly controlled, with Apple reviewing apps for security compliance, resulting in few harmful applications being reported. Antivirus software available in the App Store, from companies like McAfee and Norton, operates under the same constraints as other apps and cannot directly access the operating system kernel. Users are advised to avoid jailbreaking their devices, enable automatic updates, and take precautions such as avoiding public charging stations and regularly reviewing app permissions. Utilizing a password manager or VPN can enhance security, and those who have experienced data breaches may consider identity theft protection.
Winsage
April 27, 2025
A recent survey by Canalys revealed that over a third (35%) of channel partners reported their small and medium-sized business (SMB) clients are either unaware of the upcoming end-of-service (EoS) deadline for Windows 10 or lack a plan to transition away from it. Additionally, 14% of respondents admitted they do not know that support for Windows 10 is ending on October 14, 2025. The market for business PCs is growing, with a 9.4% year-on-year increase in shipments, reaching 62.7 million units in Q1 2025. Experts warn that the lack of upgrade plans could lead to significant financial repercussions for SMBs, especially with rising tariffs and potential supply constraints. A structured approach for transitioning to Windows 11 is recommended, including assessing current hardware, evaluating application compatibility, developing a timeline for upgrades, budgeting for investments, training staff, and implementing endpoint security strategies.
Winsage
April 25, 2025
In early April 2025, Microsoft addressed a security vulnerability (CVE-2025-21204) related to symbolic links in the Windows servicing stack, specifically affecting the c:inetpub directory used by Internet Information Services (IIS). The updates created the c:inetpub folder with appropriate permissions to mitigate risks. However, this fix introduced a new denial-of-service (DoS) vulnerability, allowing non-administrative users to create junction points on the c: drive, disrupting the Windows Update mechanism. A command such as "mklink /j c:inetpub c:windowssystem32notepad.exe" could be used to exploit this flaw, preventing systems from receiving future security patches. As of April 25, Microsoft had not released a patch or acknowledged the issue, leaving systems vulnerable and emphasizing the need for monitoring user permissions and manually removing suspicious symlinks.
Winsage
April 25, 2025
The Windows 11 Insider Preview Build (27842) will replace the Blue Screen of Death (BSoD) with a new error screen featuring a Medium Forest Green backdrop. This change is part of an effort to create a more streamlined user interface for unexpected restarts, although it may provide less context for troubleshooting. The new design is currently being tested in Microsoft's Canary Channel and is expected to become standard with the Windows 11 25H2 update later this year.
Winsage
April 23, 2025
Windows 10's April update has disrupted the functionality of jump lists in the Start menu, causing frustration among users who relied on this feature. Reports indicate that the jump lists, which provide shortcuts for applications, have stopped working after the update. This issue has been noted on various Windows 10 devices, with many complaints on platforms like Microsoft’s Answers.com and Reddit. While some users remain unaffected by the glitch, the prevailing solution to restore functionality involves uninstalling the update, which compromises access to security patches. There is speculation that the changes may be linked to elements introduced from Windows 11, although this remains unconfirmed. As Windows 10's support nears its end, users are faced with the decision to upgrade to Windows 11 or pay for an extension of support.
Search