A serious vulnerability has been discovered in Windows 11 that could allow for arbitrary code execution. A combination of factors, including a race condition, malicious DLL, and lack of certain validation, make this vulnerability possible. Threat actors could exploit it via a .theme file on Microsoft’s latest OS. Although a fix has been released, it does not fully address all issues, leaving users potentially at risk.

PipeMagic Trojan Exploits Windows CLFS Zero-Day Vulnerability to Deploy Ransomware
Microsoft reported a now-patched security flaw, CVE-2025-29824, in Windows’ Common Log File System that was exploited in select ransomware attacks against IT and real estate