AI drives rise in critical Microsoft vulnerabilities

BeyondTrust found critical vulnerabilities in Microsoft platforms rose from 78 to 157 in 2025, while AI reduced the time between disclosure and exploitation.

 


Critical vulnerabilities in Microsoft environments increased significantly during 2025 despite a decline in the total number of reported flaws.

BeyondTrust warned that risks associated with privileges and identities are growing faster than traditional defense capabilities.


Critical vulnerabilities in Microsoft platforms doubled during 2025 despite an overall decline in the total number of reported flaws, according to BeyondTrust’s latest Microsoft Vulnerabilities Annual Report.

The report identifies a shift in the risk profile of Microsoft environments, driven by factors such as artificial intelligence, cloud service expansion, and attacks targeting identities and privileged access.

Critical vulnerabilities and privileges.

According to the report, Microsoft disclosed 1,273 vulnerabilities during 2025, down 6% from the 1,360 reported in 2024. However, critical vulnerabilities increased from 78 to 157, reversing the downward trend observed in previous years.

James Maude, Field CTO at BeyondTrust, said:

“The ninefold increase in critical vulnerabilities in Azure and Dynamics 365 shows where that concentration is occurring. When combined with the growing wave of identity-based attacks exploiting standing privileges, patching alone will not be enough to close this gap”.

The report also warns that Elevation of Privilege (EoP) vulnerabilities accounted for 40% of the total reported, remaining one of the primary paths for escalating access and compromising critical systems.

Azure, Office, and enterprise services.

Among the most relevant findings, the report identified a ninefold increase in critical vulnerabilities associated with Microsoft Azure and Dynamics 365, rising from 4 to 37 reported cases.

Vulnerabilities related to Microsoft Office also rose sharply, reaching 157 cases during 2025, more than triple the previous year’s figure.

According to the report, critical vulnerabilities in Office increased tenfold, increasing exposure across widely used enterprise platforms and productivity tools.

In contrast, Microsoft Edge showed an 83% reduction in vulnerabilities, declining to 50 reported cases during 2025.

AI, identities, and emerging risks.

The report also warns that artificial intelligence is accelerating both vulnerability discovery and attackers’ ability to analyze patches, develop exploits, and exploit flaws before organizations can respond.

It also notes that AI is reducing the time between vulnerability disclosure and exploitation, increasing pressure on security teams and traditional response processes.

According to the company, risks associated with non-human identities, AI agents with excessive privileges, and misconfigurations in identity systems are not always reflected in traditional CVE vulnerability counts, limiting the ability to measure real risk based solely on reported vulnerabilities.

Defense strategies.

In response to this scenario, the company recommends strengthening least-privilege strategies, accelerating patch deployment, and adopting identity- and access-focused security strategies.

BeyondTrust also recommends that organizations focus their security strategies not only on individual vulnerabilities, but also on potential privilege escalation paths within their critical systems.


Share:
Hosting Web
Most Read