16.2 C
New York
Sunday, October 12, 2025

August Patch Tuesday contains blasts from the (latest) previous – Sophos Information


Microsoft on Tuesday introduced 109 patches affecting 16 product households. Eighteen of the addressed points are thought-about by Microsoft to be of Vital severity, and 31 have a CVSS base rating of 8.0 or greater, together with a “good” 10.0 affecting Azure. None are identified to be beneath lively exploit within the wild, although two Home windows points (CVE-2025-53786 and CVE-2025-53779) are already publicly disclosed.

At patch time, 9 CVEs are judged extra prone to be exploited within the subsequent 30 days by the corporate’s estimation. Numerous of this month’s points are amenable to direct detection by Sophos protections, and we embody info on these in a desk beneath. As well as, eight CVEs included on this month’s set, largely involving cloud-centric product households resembling Azure and 365, are already patched – together with the CVSS-10 merchandise talked about above. We’ve got included info on all eight in Appendix D. Apparently, two of these have been truly patched a full month in the past, within the July cycle, however a clerical mix-up left that info out of Microsoft’s July launch supplies. We embody these two in our August rely. Advisory info on ten Edge fixes was additionally included on this month’s launch, and may be seen in Appendix D.

We’re as all the time together with on the finish of this publish extra appendices itemizing all Microsoft’s patches sorted by severity, by predicted exploitability timeline and CVSS Base rating, and by product household. One other appendix covers advisory-style updates and the checklist of points mentioned on this month’s launch supplies however mitigated previous to the discharge, and one other offers breakout of the patches affecting the varied Home windows Server platforms nonetheless in assist.

By the numbers

  • Whole CVEs: 109
  • Publicly disclosed: 2*
  • Exploit detected: 0
  • Severity
    • Vital: 18
    • Essential: 90
    • Reasonable: 1
  • Affect
    • Elevation of Privilege: 44
    • Distant Code Execution: 35
    • Data Disclosure: 18
    • Spoofing: 7
    • Denial of Service: 4
    • Tampering: 1
  • CVSS Base rating 10.0: 1
  • CVSS Base rating 9.0 or better: 5
  • CVSS Base rating 8.0 or better: 31

* Microsoft’s official launch materials states that only one vulnerability, CVE-2025-53779, is publicly disclosed by their requirements. Nonetheless, CVE-2025-53786 was publicly demonstrated at Black Hat final week and has been very extensively mentioned since then, with a CISA Emergency Directive issued. We embody it in our tally for completeness.

A bar chart showing the impact and severity of bugs addressed in the August 2025 Patch Tuesday; described in article text

Determine 1: Elevation of Privilege vulnerabilities outpace Distant Code Execution flaws for the second month in a row, however RCE points account for extra Vital-severity patches

Merchandise

  • Home windows: 65*
  • 365: 16**
  • Workplace: 16
  • Azure: 7***
  • SQL: 6
  • Trade: 5
  • Excel: 4
  • SharePoint: 4
  • Phrase: 3
  • Dynamics 365: 2
  • PowerPoint: 1
  • Groups: 1
  • Visible Studio: 1
  • Internet Deploy: 1
  • Home windows Safety App: 1
  • Home windows Subsystem for Linux (WSL2): 1

* As talked about, the discharge info states that two of those have been patched with the July launch; we embody these two within the August counts right here and all through this publish.

** Consists of two Vital-severity patches for Microsoft 365 Copilot’s Enterprise Chat.

*** The discharge info notes that 4 of the Azure vulnerabilities have already been mitigated.

As is our customized for this checklist, CVEs that apply to a couple of product household are counted as soon as for every household they have an effect on. We word, by the best way, that CVE names don’t all the time replicate affected product households carefully. Particularly, some CVEs names within the Workplace household might point out merchandise that don’t seem within the checklist of merchandise affected by the CVE, and vice versa.

A bar chart showing the product families addressed in the August 2025 Patch Tuesday; described in article text

Determine 2: Home windows patches 5 Vital-severity patches in August, however so do Azure and Workplace – and 365 has all of them beat with six

Notable August updates

Along with the problems mentioned above, a wide range of particular objects advantage consideration.

CVE-2025-50165 — Home windows Graphics Element Distant Code Execution Vulnerability
CVE-2025-53766 — GDI+ Distant Code Execution Vulnerability

It’s a tricky month for Home windows graphics-related componentry, as these two vulnerabilities weigh in with 9.8 CVSS Base scores. CVE-2025-50165 requires no consumer interplay, and may be exploited by an uninitialized perform pointer being known as when decoding a malicious JPEG, which might be embedded in a doc, a Internet web page, or what you’ll. It impacts strictly the most recent variations of Home windows (Win 11 2H24, Server 2025). Equally, CVE-2025-53766 might be triggered with out consumer interplay, ought to an attacker handle to add paperwork containing a specifically crafted metafile to an online service. (Alternately, they might craft a doc containing the metafile, ship it to an unwary consumer, and get them to open it.) Unusually, this CVE impacts each Home windows and Workplace.

CVE-2025-49712 — Microsoft SharePoint Distant Code Execution Vulnerability

As most Microsoft observers know nicely, there was lots to say between the July and August Patch Tuesday releases about SharePoint. This situation, nevertheless, appears unrelated to ToolShell, although it’s pretty disagreeable all by itself, permitting any authenticated attacker to execute code over the community with little prior data of the community required.

CVE-2025-53731, CVE-2025-53733, CVE-2025-53740, CVE-2025-53784 – 4 365/Workplace points

Preview Pane is a vector for all 4 of those vulnerabilities.

CVE-2025-53774, CVE-2025-53787 — Microsoft 365 Copilot BizChat Data Disclosure Vulnerability

These identically titled information-disclosure vulnerabilities, each Vital-severity, are talked about in Microsoft’s abstract info for August, however the firm notes that each have already been mitigated. Nonetheless, CVE-2025-53787 particularly didn’t go quietly, and web commenters had issues to say concerning the future implications of bugs of this nature. (It’s attention-grabbing to notice that earlier info from Microsoft, as per the WindowsForum publish, thought-about the problem to be Essential in severity; the discharge on Tuesday categorised it as Vital.)

CVE-2025-53786 — Microsoft Trade Server Hybrid Deployment Elevation of Privilege Vulnerability

As famous above, this Essential-severity EoP situation bought loads of consideration at Black Hat and from CISA earlier this month. It’s a bug to be taken critically, and Microsoft states that they consider it’s one of many vulnerabilities extra prone to be exploited inside the first 30 days post-release. However the story of how this patch arrived at launch is an attention-grabbing one from a disclosure standpoint. The finder, Dirk-jan Mollema with Outsider Safety, labored with Microsoft to kind out the problem previous to his Black Hat presentation. In flip, Microsoft credit his discover of their launch supplies, an indication that the disclosure was well-coordinated. The difficulty itself pertains to an April hotfix for hybrid Trade deployments.

CVE-2024-53772 — Internet Deploy Distant Code Execution Vulnerability

Internet Deploy, for these not acquainted with the instrument, is used to deploy Internet purposes and Websites to IIS servers. It would doubtless be acquainted to customers of Visible Studio.

A bar chart showing the impact and severity of bugs addressed in the 2025 Patch Tuesday releases; described in article text

Determine 3: Distant Code Execution points proceed to guide all different varieties in 2025’s Patch Tuesday releases, however Elevation of Privilege points are shut behind – 266 to 257, by our rely. In the meantime, Spoofing picks up its first Vital-severity case in August, and the primary non-advisory Reasonable-severity patch of the yr is famous

Sophos protections

CVESophos Intercept X/Endpoint IPSSophos XGS Firewall
CVE-2025-49743Exp/2549743-AExp/2549743-A
CVE-2025-50167Exp/2550167-AExp/2550167-A
CVE-2025-50168Exp/2550168-AExp/2550168-A
CVE-2025-50177SID:2311472,2311473SID:2311472,2311473
CVE-2025-53132Exp/2553132-AExp/2553132-A
CVE-2025-53147Exp/2553147-AExp/2553147-A
CVE-2025-53778SID:2311491SID:2311491

As you possibly can each month, in case you don’t wish to wait on your system to drag down Microsoft’s updates itself, you possibly can obtain them manually from the Home windows Replace Catalog web site. Run the winver.exe instrument to find out which construct of Home windows 10 or 11 you’re working, then obtain the Cumulative Replace package deal on your particular system’s structure and construct quantity.

Appendix A: Vulnerability Affect and Severity

This can be a checklist of August patches sorted by affect, then sub-sorted by severity. Every checklist is additional organized by CVE.

Elevation of Privilege (44 CVEs)

Vital severity
CVE-2025-24999Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-53767Azure OpenAI Elevation of Privilege Vulnerability
CVE-2025-53778Home windows NTLM Elevation of Privilege Vulnerability
CVE-2025-53792Azure Portal Elevation of Privilege Vulnerability
Essential severity
CVE-2025-47954Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-49743Home windows Graphics Element Elevation of Privilege Vulnerability
CVE-2025-49758Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-49759Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-49761Home windows Kernel Elevation of Privilege Vulnerability
CVE-2025-49762Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-50153Desktop Home windows Supervisor Elevation of Privilege Vulnerability
CVE-2025-50155Home windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2025-50159Distant Entry Level-to-Level Protocol (PPP) EAP-TLS Elevation of Privilege Vulnerability
CVE-2025-50161Win32k Elevation of Privilege Vulnerability
CVE-2025-50167Home windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-50168Win32k Elevation of Privilege Vulnerability
CVE-2025-50170Home windows Cloud Recordsdata Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-50173Home windows Installer Elevation of Privilege Vulnerability
CVE-2025-53132Win32k Elevation of Privilege Vulnerability
CVE-2025-53133Home windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
CVE-2025-53134Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53135DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-53137Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53140Home windows Kernel Transaction Supervisor Elevation of Privilege Vulnerability
CVE-2025-53141Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53142Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-53147Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53149Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
CVE-2025-53151Home windows Kernel Elevation of Privilege Vulnerability
CVE-2025-53154Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53155Home windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-53718Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53721Home windows Related Units Platform Service Elevation of Privilege Vulnerability
CVE-2025-53723Home windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-53724Home windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2025-53725Home windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2025-53726Home windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2025-53727Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-53729Microsoft Azure File Sync Elevation of Privilege Vulnerability
CVE-2025-53760Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2025-53786Microsoft Trade Server Hybrid Deployment Elevation of Privilege Vulnerability
CVE-2025-53788Home windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
CVE-2025-53789Home windows StateRepository API Server file Elevation of Privilege Vulnerability
Reasonable severity
CVE-2025-53779Home windows Kerberos Elevation of Privilege Vulnerability

 

Distant Code Execution (35 CVEs)

Vital severity
CVE-2025-48807Microsoft SQL Server Distant Code Execution Vulnerability
CVE-2025-50165Home windows Graphics Element Distant Code Execution Vulnerability
CVE-2025-50176DirectX Graphics Kernel Distant Code Execution Vulnerability
CVE-2025-50177Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
CVE-2025-53731Microsoft Workplace Distant Code Execution Vulnerability
CVE-2025-53733Microsoft Phrase Distant Code Execution Vulnerability
CVE-2025-53740Microsoft Workplace Distant Code Execution Vulnerability
CVE-2025-53766GDI+ Distant Code Execution Vulnerability
CVE-2025-53784Microsoft Phrase Distant Code Execution Vulnerability
CVE-2025-48807Microsoft SQL Server Distant Code Execution Vulnerability
Essential severity
CVE-2025-49712Microsoft SharePoint Distant Code Execution Vulnerability
CVE-2025-49757Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
CVE-2025-50160Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
CVE-2025-50162Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
CVE-2025-50163Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
CVE-2025-50164Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
CVE-2025-50169Home windows SMB Distant Code Execution Vulnerability
CVE-2025-53131Home windows Media Distant Code Execution Vulnerability
CVE-2025-53143Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
CVE-2025-53144Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
CVE-2025-53145Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
CVE-2025-53152Desktop Home windows Supervisor Distant Code Execution Vulnerability
CVE-2025-53720Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
CVE-2025-53730Microsoft Workplace Visio Distant Code Execution Vulnerability
CVE-2025-53732Microsoft Workplace Distant Code Execution Vulnerability
CVE-2025-53734Microsoft Workplace Visio Distant Code Execution Vulnerability
CVE-2025-53735Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53737Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53738Microsoft Phrase Distant Code Execution Vulnerability
CVE-2025-53739Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53741Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53759Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53761Microsoft PowerPoint Distant Code Execution Vulnerability
CVE-2025-53772Internet Deploy Distant Code Execution Vulnerability
CVE-2025-53773GitHub Copilot and Visible Studio Distant Code Execution Vulnerability
CVE-2025-53783Microsoft Groups Distant Code Execution Vulnerability

 

Data Disclosure (18 CVEs)

Vital severity
CVE-2025-53774Microsoft 365 Copilot BizChat Data Disclosure Vulnerability
CVE-2025-53781Azure Digital Machines Data Disclosure Vulnerability
CVE-2025-53787Microsoft 365 Copilot BizChat Data Disclosure Vulnerability
CVE-2025-53793Azure Stack Hub Data Disclosure Vulnerability
Essential severity
CVE-2025-33051Microsoft Trade Server Data Disclosure Vulnerability
CVE-2025-50156Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability
CVE-2025-50157Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability
CVE-2025-50158Home windows NTFS Data Disclosure Vulnerability
CVE-2025-50166Home windows Distributed Transaction Coordinator (MSDTC) Data Disclosure Vulnerability
CVE-2025-53136NT OS Kernel Data Disclosure Vulnerability
CVE-2025-53138Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability
CVE-2025-53148Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability
CVE-2025-53153Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability
CVE-2025-53156Home windows Storage Port Driver Data Disclosure Vulnerability
CVE-2025-53719Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability
CVE-2025-53728Microsoft Dynamics 365 (On-Premises) Data Disclosure Vulnerability
CVE-2025-53736Microsoft Phrase Data Disclosure Vulnerability
CVE-2025-53765Azure Stack Hub Data Disclosure Vulnerability

 

Spoofing (7 CVEs)

Vital severity
CVE-2025-49707Azure Digital Machines Spoofing Vulnerability
Essential severity
CVE-2025-25006Microsoft Trade Server Spoofing Vulnerability
CVE-2025-25007Microsoft Trade Server Spoofing Vulnerability
CVE-2025-49745Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2025-50154Microsoft Home windows File Explorer Spoofing Vulnerability
CVE-2025-50171Distant Desktop Spoofing Vulnerability
CVE-2025-53769Home windows Safety App Spoofing Vulnerability

 

Denial of Service (4 CVEs)

Essential severity
CVE-2025-49751Home windows Hyper-V Denial of Service Vulnerability
CVE-2025-50172DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-53716Native Safety Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2025-53722Home windows Distant Desktop Providers Denial of Service Vulnerability

 

Tampering (1 CVE)

Essential severity
CVE-2025-25005Microsoft Trade Server Tampering Vulnerability

 

Appendix B: Exploitability and CVSS

This can be a checklist of the August CVEs judged by Microsoft to be extra prone to be exploited within the wild inside the first 30 days post-release. (No CVE amongst this month’s patches is understood to be already exploited within the wild, in order that checklist doesn’t seem this month.) The checklist is additional organized by CVE.

Exploitation extra doubtless inside the subsequent 30 days
CVE-2025-49743Home windows Graphics Element Elevation of Privilege Vulnerability
CVE-2025-50167Home windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-50168Win32k Elevation of Privilege Vulnerability
CVE-2025-50177Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
CVE-2025-53132Win32k Elevation of Privilege Vulnerability
CVE-2025-53147Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53156Home windows Storage Port Driver Data Disclosure Vulnerability
CVE-2025-53778Home windows NTLM Elevation of Privilege Vulnerability
CVE-2025-53786Microsoft Trade Server Hybrid Deployment Elevation of Privilege Vulnerability

 

This can be a checklist of August’s CVEs with a Microsoft-assessed CVSS Base rating of 8.0 or greater. They’re organized by rating and additional sorted by CVE. For extra info on how CVSS works, please see our sequence on patch prioritization schema.

CVSS BaseCVSS TemporalCVETitle
10.08.7CVE-2025-53767Azure OpenAI Elevation of Privilege Vulnerability
9.88.5CVE-2025-50165Home windows Graphics Element Distant Code Execution Vulnerability
9.88.5CVE-2025-53766GDI+ Distant Code Execution Vulnerability
9.17.9CVE-2025-50171Distant Desktop Spoofing Vulnerability
9.17.9CVE-2025-53792Azure Portal Elevation of Privilege Vulnerability
8.87.7CVE-2025-24999Microsoft SQL Server Elevation of Privilege Vulnerability
8.87.7CVE-2025-47954Microsoft SQL Server Elevation of Privilege Vulnerability
8.87.7CVE-2025-49712Microsoft SharePoint Distant Code Execution Vulnerability
8.87.7CVE-2025-49757Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
8.87.7CVE-2025-49758Microsoft SQL Server Elevation of Privilege Vulnerability
8.87.7CVE-2025-49759Microsoft SQL Server Elevation of Privilege Vulnerability
8.87.7CVE-2025-50163Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
8.87.7CVE-2025-53131Home windows Media Distant Code Execution Vulnerability
8.87.7CVE-2025-53143Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
8.87.7CVE-2025-53144Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
8.87.7CVE-2025-53145Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
8.87.7CVE-2025-53727Microsoft SQL Server Elevation of Privilege Vulnerability
8.87.7CVE-2025-53772Internet Deploy Distant Code Execution Vulnerability
8.87.7CVE-2025-53778Home windows NTLM Elevation of Privilege Vulnerability
8.47.3CVE-2025-53731Microsoft Workplace Distant Code Execution Vulnerability
8.47.3CVE-2025-53733Microsoft Phrase Distant Code Execution Vulnerability
8.47.3CVE-2025-53740Microsoft Workplace Distant Code Execution Vulnerability
8.47.3CVE-2025-53784Microsoft Phrase Distant Code Execution Vulnerability
8.27.1CVE-2025-53787Microsoft 365 Copilot BizChat Data Disclosure Vulnerability
8.17.1CVE-2025-50177Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
8.07.0CVE-2025-50160Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
8.07.0CVE-2025-50162Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
8.07.0CVE-2025-50164Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
8.07.0CVE-2025-53132Win32k Elevation of Privilege Vulnerability
8.07.0CVE-2025-53720Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
8.07.0CVE-2025-53786Microsoft Trade Server Hybrid Deployment Elevation of Privilege Vulnerability

 

Appendix C: Merchandise Affected

This can be a checklist of August’s patches sorted by product household, then sub-sorted by severity. Every checklist is additional organized by CVE. Patches which might be shared amongst a number of product households are listed a number of occasions, as soon as for every product household. Sure vital points for which advisories have been issued are coated in Appendix D, and points affecting Home windows Server are additional sorted in Appendix E. All CVE titles are correct as made obtainable by Microsoft; for additional info on why sure merchandise might seem in titles and never product households (or vice versa), please seek the advice of Microsoft.

Home windows (65 CVEs)

Vital severity
CVE-2025-50165Home windows Graphics Element Distant Code Execution Vulnerability
CVE-2025-50176DirectX Graphics Kernel Distant Code Execution Vulnerability
CVE-2025-50177Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
CVE-2025-53766GDI+ Distant Code Execution Vulnerability
CVE-2025-53778Home windows NTLM Elevation of Privilege Vulnerability
Essential severity
CVE-2025-49743Home windows Graphics Element Elevation of Privilege Vulnerability
CVE-2025-49751Home windows Hyper-V Denial of Service Vulnerability
CVE-2025-49757Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
CVE-2025-49761Home windows Kernel Elevation of Privilege Vulnerability
CVE-2025-49762Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-50153Desktop Home windows Supervisor Elevation of Privilege Vulnerability
CVE-2025-50154Microsoft Home windows File Explorer Spoofing Vulnerability
CVE-2025-50155Home windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2025-50156Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability
CVE-2025-50157Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability
CVE-2025-50158Home windows NTFS Data Disclosure Vulnerability
CVE-2025-50159Distant Entry Level-to-Level Protocol (PPP) EAP-TLS Elevation of Privilege Vulnerability
CVE-2025-50160Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
CVE-2025-50161Win32k Elevation of Privilege Vulnerability
CVE-2025-50162Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
CVE-2025-50163Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
CVE-2025-50164Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
CVE-2025-50166Home windows Distributed Transaction Coordinator (MSDTC) Data Disclosure Vulnerability
CVE-2025-50167Home windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-50168Win32k Elevation of Privilege Vulnerability
CVE-2025-50169Home windows SMB Distant Code Execution Vulnerability
CVE-2025-50170Home windows Cloud Recordsdata Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-50171Distant Desktop Spoofing Vulnerability
CVE-2025-50172DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-50173Home windows Installer Elevation of Privilege Vulnerability
CVE-2025-53131Home windows Media Distant Code Execution Vulnerability
CVE-2025-53132Win32k Elevation of Privilege Vulnerability
CVE-2025-53133Home windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
CVE-2025-53134Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53135DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-53136NT OS Kernel Data Disclosure Vulnerability
CVE-2025-53137Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53138Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability
CVE-2025-53140Home windows Kernel Transaction Supervisor Elevation of Privilege Vulnerability
CVE-2025-53141Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53142Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-53143Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
CVE-2025-53144Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
CVE-2025-53145Microsoft Message Queuing (MSMQ) Distant Code Execution Vulnerability
CVE-2025-53147Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53148Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability
CVE-2025-53149Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
CVE-2025-53151Home windows Kernel Elevation of Privilege Vulnerability
CVE-2025-53152Desktop Home windows Supervisor Distant Code Execution Vulnerability
CVE-2025-53153Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability
CVE-2025-53154Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53155Home windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-53156Home windows Storage Port Driver Data Disclosure Vulnerability
CVE-2025-53716Native Safety Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2025-53718Home windows Ancillary Perform Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-53719Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability
CVE-2025-53720Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability
CVE-2025-53721Home windows Related Units Platform Service Elevation of Privilege Vulnerability
CVE-2025-53722Home windows Distant Desktop Providers Denial of Service Vulnerability
CVE-2025-53723Home windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-53724Home windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2025-53725Home windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2025-53726Home windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2025-53789Home windows StateRepository API Server file Elevation of Privilege Vulnerability
Reasonable severity
CVE-2025-53779Home windows Kerberos Elevation of Privilege Vulnerability

 

365 (16 CVEs)

Vital severity
CVE-2025-53731Microsoft Workplace Distant Code Execution Vulnerability
CVE-2025-53733Microsoft Phrase Distant Code Execution Vulnerability
CVE-2025-53740Microsoft Workplace Distant Code Execution Vulnerability
CVE-2025-53774Microsoft 365 Copilot BizChat Data Disclosure Vulnerability
CVE-2025-53784Microsoft Phrase Distant Code Execution Vulnerability
CVE-2025-53787Microsoft 365 Copilot BizChat Data Disclosure Vulnerability
Essential severity
CVE-2025-53730Microsoft Workplace Visio Distant Code Execution Vulnerability
CVE-2025-53734Microsoft Workplace Visio Distant Code Execution Vulnerability
CVE-2025-53735Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53736Microsoft Phrase Data Disclosure Vulnerability
CVE-2025-53737Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53738Microsoft Phrase Distant Code Execution Vulnerability
CVE-2025-53739Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53741Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53759Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53761Microsoft PowerPoint Distant Code Execution Vulnerability

 

Workplace (16 CVEs)

Vital severity
CVE-2025-53731Microsoft Workplace Distant Code Execution Vulnerability
CVE-2025-53733Microsoft Phrase Distant Code Execution Vulnerability
CVE-2025-53740Microsoft Workplace Distant Code Execution Vulnerability
CVE-2025-53766GDI+ Distant Code Execution Vulnerability
CVE-2025-53784Microsoft Phrase Distant Code Execution Vulnerability
Essential severity
CVE-2025-53730Microsoft Workplace Visio Distant Code Execution Vulnerability
CVE-2025-53732Microsoft Workplace Distant Code Execution Vulnerability
CVE-2025-53734Microsoft Workplace Visio Distant Code Execution Vulnerability
CVE-2025-53735Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53736Microsoft Phrase Data Disclosure Vulnerability
CVE-2025-53737Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53738Microsoft Phrase Distant Code Execution Vulnerability
CVE-2025-53739Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53741Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53759Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53761Microsoft PowerPoint Distant Code Execution Vulnerability

 

Azure (7 CVEs)

Vital severity
CVE-2025-49707Azure Digital Machines Spoofing Vulnerability
CVE-2025-53767Azure OpenAI Elevation of Privilege Vulnerability
CVE-2025-53781Azure Digital Machines Data Disclosure Vulnerability
CVE-2025-53792Azure Portal Elevation of Privilege Vulnerability
CVE-2025-53793Azure Stack Hub Data Disclosure Vulnerability
Essential severity
CVE-2025-53729Microsoft Azure File Sync Elevation of Privilege Vulnerability
CVE-2025-53765Azure Stack Hub Data Disclosure Vulnerability

 

SQL (6 CVEs)

Vital severity
CVE-2025-24999Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-48807Microsoft SQL Server Distant Code Execution Vulnerability
Essential severity
CVE-2025-47954Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-49758Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-49759Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-53727Microsoft SQL Server Elevation of Privilege Vulnerability

 

Trade (5 CVEs)

Essential severity
CVE-2025-25005Microsoft Trade Server Tampering Vulnerability
CVE-2025-25006Microsoft Trade Server Spoofing Vulnerability
CVE-2025-25007Microsoft Trade Server Spoofing Vulnerability
CVE-2025-33051Microsoft Trade Server Data Disclosure Vulnerability
CVE-2025-53786Microsoft Trade Server Hybrid Deployment Elevation of Privilege Vulnerability

 

Excel (4 CVEs)

Essential severity
CVE-2025-53735Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53737Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53739Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-53741Microsoft Excel Distant Code Execution Vulnerability

SharePoint (4 CVEs)

Vital severity
CVE-2025-53733Microsoft Phrase Distant Code Execution Vulnerability
Essential severity
CVE-2025-49712Microsoft SharePoint Distant Code Execution Vulnerability
CVE-2025-53736Microsoft Phrase Data Disclosure Vulnerability
CVE-2025-53760Microsoft SharePoint Elevation of Privilege Vulnerability

Phrase (3 CVEs)

Vital severity
CVE-2025-53733Microsoft Phrase Distant Code Execution Vulnerability
Essential severity
CVE-2025-53736Microsoft Phrase Data Disclosure Vulnerability
CVE-2025-53738Microsoft Phrase Distant Code Execution Vulnerability

 

Dynamics 365 (2 CVEs)

Essential severity
CVE-2025-49745Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2025-53728Microsoft Dynamics 365 (On-Premises) Data Disclosure Vulnerability

 

PowerPoint (1 CVE)

Essential severity
CVE-2025-53761Microsoft PowerPoint Distant Code Execution Vulnerability

 

Groups (1 CVE)

Essential severity
CVE-2025-53783Microsoft Groups Distant Code Execution Vulnerability

 

Visible Studio (1 CVE)

Essential severity
CVE-2025-53773GitHub Copilot and Visible Studio Distant Code Execution Vulnerability

 

Internet Deploy (1 CVE)

Essential severity
CVE-2025-53772Internet Deploy Distant Code Execution Vulnerability

 

Home windows Safety App (1 CVE)

Essential severity
CVE-2025-53769Home windows Safety App Spoofing Vulnerability

 

Home windows Subsystem for Linux (WSL2) (1 CVE)

Essential severity
CVE-2025-53788Home windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability

 

Appendix D: Advisories and Different Merchandise

There are 10 Edge-related advisories in August’s launch, all however two of which originated exterior Microsoft.

CVE-2025-8576Chromium: CVE-2025-8576 Use after free in Extensions
CVE-2025-8577Chromium: CVE-2025-8577 Inappropriate implementation in Image In Image
CVE-2025-8578Chromium: CVE-2025-8578 Use after free in Solid
CVE-2025-8579Chromium: CVE-2025-8579 Inappropriate implementation in Gemini Stay in Chrome
CVE-2025-8580Chromium: CVE-2025-8580 Inappropriate implementation in Filesystems
CVE-2025-8581Chromium: CVE-2025-8581 Inappropriate implementation in Extensions
CVE-2025-8582Chromium: CVE-2025-8582 Inadequate validation of untrusted enter in DOM
CVE-2025-8583Chromium: CVE-2025-8583 Inappropriate implementation in Permissions
CVE-2025-49736Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2025-49755Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

As well as, eight of CVEs seem on this month’s Patch Tuesday info solely to guarantee the general public that they’ve already been mitigated, whether or not as a part of the traditional course of cloud enterprise or (within the case of two Home windows patches) as a part of final month’s patch assortment, although they have been unnamed in that launch. Since this month’s CVSS 10.0 CVE is amongst these eight, we’re itemizing these right here with their CVE, title, affect, severity, and CVSS base rating.

 

CVE-2025-48807Microsoft SQL Server Distant Code Execution VulnerabilityDistant Code ExecutionVital7.5
CVE-2025-49707Azure Digital Machines Spoofing VulnerabilitySpoofingVital7.9
CVE-2025-53767Azure OpenAI Elevation of Privilege VulnerabilityElevation of PrivilegeVital10.0
CVE-2025-53774Microsoft 365 Copilot BizChat Data Disclosure VulnerabilityData DisclosureVital6.5
CVE-2025-53781Azure Digital Machines Data Disclosure VulnerabilityData DisclosureVital7.7
CVE-2025-53787Microsoft 365 Copilot BizChat Data Disclosure VulnerabilityData DisclosureVital8.2
CVE-2025-53789Home windows StateRepository API Server file Elevation of Privilege VulnerabilityElevation of PrivilegeEssential7.8
CVE-2025-53792Azure Portal Elevation of Privilege VulnerabilityElevation of PrivilegeVital9.1

 

There have been no Adobe advisories included within the August launch.

Appendix E: Affected Home windows Server variations

This can be a desk of the 66 CVEs within the August launch affecting Home windows Server variations 2008 by way of 2025. CVE-2025-48807 and CVE-2025-53789, the 2 CVEs that shipped in July however have been neglected of the official info final month as talked about above, are included right here.  The desk differentiates amongst main variations of the platform however doesn’t go into deeper element (eg., Server Core). Vital-severity points are marked in purple; an “x” signifies that the CVE doesn’t apply to that model. Directors are inspired to make use of this appendix as a place to begin to establish their particular publicity, as every reader’s scenario, particularly because it issues merchandise out of mainstream assist, will fluctuate. For particular Data Base numbers, please seek the advice of Microsoft.

CVES-088r2S-1212r2S-16S-19S-2223h2S-25
CVE-2025-48807××××
CVE-2025-49743
CVE-2025-49751××××
CVE-2025-49757
CVE-2025-49761×
CVE-2025-49762
CVE-2025-50153×××
CVE-2025-50154
CVE-2025-50155××
CVE-2025-50156
CVE-2025-50157
CVE-2025-50158
CVE-2025-50159××
CVE-2025-50160
CVE-2025-50161
CVE-2025-50162
CVE-2025-50163
CVE-2025-50164
CVE-2025-50165××××××××
CVE-2025-50166
CVE-2025-50167××
CVE-2025-50168×××××××
CVE-2025-50169××××××××
CVE-2025-50170×××××
CVE-2025-50171××××××
CVE-2025-50172×××××
CVE-2025-50173
CVE-2025-50176××××××
CVE-2025-50177
CVE-2025-53131×××××
CVE-2025-53132
CVE-2025-53133××××××××
CVE-2025-53134
CVE-2025-53135×××
CVE-2025-53136
CVE-2025-53137
CVE-2025-53138
CVE-2025-53140
CVE-2025-53141
CVE-2025-53142×××××××
CVE-2025-53143
CVE-2025-53144
CVE-2025-53145
CVE-2025-53147
CVE-2025-53148
CVE-2025-53149
CVE-2025-53151×××××
CVE-2025-53152×××
CVE-2025-53153
CVE-2025-53154
CVE-2025-53155××
CVE-2025-53156×××××××
CVE-2025-53716×××××
CVE-2025-53718
CVE-2025-53719
CVE-2025-53720
CVE-2025-53721×××××
CVE-2025-53722×
CVE-2025-53723××
CVE-2025-53724××
CVE-2025-53725××
CVE-2025-53726××
CVE-2025-53766
CVE-2025-53778
CVE-2025-53779××××××××
CVE-2025-53789××××

 

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles