India’s apex cybersecurity body, the Indian Computer Emergency Response Team (CERT-In), has issued a high-risk advisory over several newly discovered vulnerabilities in Microsoft products, urging both organisations and individual users to act swiftly.

According to a report by Business Standard, the advisory—published on CERT-In’s official portal—warns that these security flaws affect a wide range of Microsoft tools, including Windows, Azure, Microsoft Office, Developer Tools, Dynamics, and System Center, as well as extended support updates for legacy Microsoft systems.

What’s At Risk?

The vulnerabilities could be exploited by malicious actors to:

  • Gain unauthorised elevated privileges
  • Access or steal confidential data
  • Bypass standard security mechanisms
  • Remotely execute malicious code
  • Launch Denial-of-Service (DoS) or spoofing attacks

“These multiple vulnerabilities in Microsoft products could be exploited to compromise system integrity and put sensitive information at risk,” CERT-In cautioned, emphasizing the need for immediate action from IT administrators, security professionals, and general users.

No Official Fix Yet, But Patches Are Available

Microsoft has not released any specific workarounds for the vulnerabilities. However, users are strongly advised to install the security patches rolled out as part of Microsoft’s May 2025 update cycle to mitigate potential threats.

CERT-In’s Recommendations:

  • Install all recent Microsoft security updates without delay.
  • Monitor systems for unusual behaviour and suspicious activity.
  • Harden access controls and implement strict endpoint security protocols.
  • Consult cybersecurity experts for vulnerability assessments and threat prevention.

This alert comes amid a rising wave of sophisticated cyberattacks targeting software giants. It serves as a reminder that maintaining up-to-date systems and adopting proactive cybersecurity practices is no longer optional—it’s essential.