34.8 C
New York
Wednesday, July 30, 2025

Microsoft primes 71 fixes for Could Patch Tuesday – Sophos Information


Microsoft on Tuesday launched 71 patches affecting 14 product households. Six of the addressed points, 5 involving distant code execution and one allowing info disclosure (together with PII, Personally Identifiable Info), are thought of by Microsoft to be of Important severity, and 12 have a CVSS base rating of 8.0 or larger. 5, all Necessary-severity points in Home windows, are identified to be beneath energetic exploit within the wild.

At patch time, 9 further CVEs usually tend to be exploited within the subsequent 30 days by the corporate’s estimation. Numerous of this month’s points are amenable to direct detection by Sophos protections, and we embody info on these in a desk beneath.

Along with these patches, eight Necessary-severity Adobe Reader points affecting ColdFusion are lined within the launch. These are listed in Appendix D beneath. That appendix additionally comprises info on eight Edge-related vulnerabilities and 7 affecting Azure, Dataverse, or Energy Apps. Although a number of of the non-Edge points are thrilling, with CVSS Base scores over 9.0 (a “good” 10, in a single case), Microsoft’s launched info signifies that every one have been patched in latest days – in different phrases, the data offered is strictly FYI.

We’re as all the time together with on the finish of this publish appendices itemizing all Microsoft’s patches sorted by severity, by predicted exploitability timeline and CVSS Base rating, and by product household; an appendix protecting the advisory-style updates; and a breakout of the patches affecting the assorted Home windows Server platforms nonetheless in help.

By the numbers

  • Complete CVEs: 71
  • Publicly disclosed: 2
  • Exploit detected: 5
  • Severity
    • Important: 6
    • Necessary: 65
  • Influence:
    • Distant Code Execution: 28
    • Elevation of Privilege: 17
    • Info Disclosure: 15
    • Denial of Service: 7
    • Safety Characteristic Bypass: 2
    • Spoofing: 2
  • CVSS base rating 9.0 or higher: 1*
  • CVSS base rating 8.0 or higher: 11

* A variety of advisory-only points this month, affecting Azure, Dataverse, and Energy Apps however patched by Microsoft previous to the Could launch, have been assigned important CVSS scores. Please see Appendix D for particulars.

a bar chart showing distribution of May's patches by impact, further color-coded by severity; information in text

Determine 1: Distant code execution returns to the highest of the charts for Could’s Patch Tuesday. Observe the bizarre Important-severity information-disclosure subject. This happens in Nuance PowerScribe 360, a product from the medical sphere – ask your native radiologist for particulars. (Eight Edge updates lined this month will not be launched with full impression info and thus don’t seem on this chart)

Merchandise

  • Home windows: 43
  • Workplace: 14
  • 365: 13
  • Excel: 7
  • SharePoint: 4
  • Visible Studio: 4
  • RDP Consumer: 2
  • .NET: 1
  • Azure: 1
  • Dataverse: 1
  • Defender: 1
  • Nuance PowerScribe 360: 1
  • PC Supervisor: 1
  • Home windows HLK: 1

As is our customized for this record, CVEs that apply to a couple of product household are counted as soon as for every household they have an effect on. It must be famous, by the best way, that CVE names in Could don’t all the time replicate affected product households intently. Particularly, some CVEs names within the Workplace household could point out merchandise that don’t seem within the record of merchandise affected by the CVE, and vice versa.

A bar chart showing distribution of May's patches, sorted by product family; information covered in text

Determine 2: Fourteen product households determine in Could’s Patch Tuesday launch. This month, we return to separating Edge / Chromium points from the pack; these are lined in Appendix D, as are some advisory and information-only however attention-grabbing points affecting Azure, Dataverse, and Energy Apps

Notable Could updates

Along with the problems mentioned above, a wide range of particular gadgets benefit consideration.

CVE-2025-30385, CVE-2025-30701, CVE-2025-32706 — Home windows Widespread Log File System Driver Elevation of Privilege Vulnerability

CLFS issues account for 2 of the 5 vulnerabilities at present identified to be beneath assault within the wild, and the opposite one (CVE-2025-30385) is predicted to see motion throughout the subsequent 30 days. The logging system has taken a excessive variety of patches prior to now few years, together with lately seen abuse by each Play and PipeMagic malware of CVE-2025-29824, which was patched final month. Microsoft’s identified to be spinning up a brand new verification step for parsing CLFS log information, however within the meantime, the system’s giving RDP a run for its cash as a supply of administrator grief.

CVE-2025-30377, CVE-2025-30386 — Microsoft Workplace Distant Code Execution Vulnerability
Each of those vulnerabilities could be triggered through Preview Pane. If it have been a contest CVE-2025-30386 would have the slight edge, as Microsoft finds that within the worst case, of their phrases, “an attacker might ship a specifically crafted electronic mail to the person with no requirement that the sufferer open, learn, or click on on the hyperlink.” Each vulnerabilities apply to 365 in addition to Workplace.

CVE-2025-27488 — Microsoft Home windows {Hardware} Lab Package (HLK) Elevation of Privilege Vulnerability

An Necessary-class subject, this bug impacts the Home windows {Hardware} Package Lab, which is a framework for testing {hardware} gadgets and drivers for sure editions of Home windows; a number of variations of all the package likewise take an replace this month. That’s good, as the issue itself lies in sure third-party infrastructure throughout the package utilizing a hard-coded password (!).

CVE-2025-30384 — Microsoft SharePoint Server Distant Code Execution Vulnerability

An Necessary-severity subject requiring the attacker to organize the goal forward of time, the finder credited for this merchandise is “zcgonvh’s cat Vanilla.” We admit to some curiosity about how Vanilla caught this bug; did they use… a mouse?

A bar chart showing the cumulative patch counts for 2025, sorted by impact and further indicating severity

Determine 3: RCE and EoP points proceed to dominate the charts in 2025

 Sophos protections

CVESophos Intercept X/Endpoint IPSSophos XGS Firewall
CVE-2025-24063Exp/2524063-AExp/2524063-A
CVE-2025-29971Exp/2529971-AExp/2529971-A
CVE-2025-30377sid:2310992sid:2310992
CVE-2025-30386sid:2310976sid:2310976
CVE-2025-30388sid:2310990sid:2310990
CVE-2025-30397Exp/2530397-AExp/2530397-A
CVE-2025-30400Exp/2530400-AExp/2530400-A
CVE-2025-32701Exp/2532701-AExp/2532701-A
CVE-2025-32706Exp/2532706-AExp/2532706-A
CVE-2025-32709Exp/2532709-AExp/2532709-A

 

As you’ll be able to each month, when you don’t need to wait in your system to drag down Microsoft’s updates itself, you’ll be able to obtain them manually from the Home windows Replace Catalog web site. Run the winver.exe software to find out which construct of Home windows 10 or 11 you’re operating, then obtain the Cumulative Replace package deal in your particular system’s structure and construct quantity.

Appendix A: Vulnerability Influence and Severity

It is a record of Could patches sorted by impression, then sub-sorted by severity. Every record is additional organized by CVE.

Distant Code Execution (28 CVEs)

Important severity
CVE-2025-29833Microsoft Digital Machine Bus (VMBus) Distant Code Execution Vulnerability
CVE-2025-29966Distant Desktop Consumer Distant Code Execution Vulnerability
CVE-2025-29967Home windows Distant Desktop Providers Distant Code Execution Vulnerability
CVE-2025-30377Microsoft Workplace Distant Code Execution Vulnerability
CVE-2025-30386Microsoft Workplace Distant Code Execution Vulnerability
Necessary severity
CVE-2025-29831Home windows Distant Desktop Providers Distant Code Execution Vulnerability
CVE-2025-29840Home windows Media Distant Code Execution Vulnerability
CVE-2025-29962Home windows Media Distant Code Execution Vulnerability
CVE-2025-29963Home windows Media Distant Code Execution Vulnerability
CVE-2025-29964Home windows Media Distant Code Execution Vulnerability
CVE-2025-29969MS-EVEN RPC Distant Code Execution Vulnerability
CVE-2025-29977Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-29978Microsoft PowerPoint Distant Code Execution Vulnerability
CVE-2025-29979Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30375Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30376Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30378Microsoft SharePoint Server Distant Code Execution Vulnerability
CVE-2025-30379Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30381Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30382Microsoft SharePoint Server Distant Code Execution Vulnerability
CVE-2025-30383Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30384Microsoft SharePoint Server Distant Code Execution Vulnerability
CVE-2025-30388Home windows Graphics Element Distant Code Execution Vulnerability
CVE-2025-30393Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30397Scripting Engine Reminiscence Corruption Vulnerability
CVE-2025-32702Visible Studio Distant Code Execution Vulnerability
CVE-2025-32704Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-32705Microsoft Outlook Distant Code Execution Vulnerability

 

Elevation of Privilege (17 CVEs)

Necessary severity
CVE-2025-24063Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVE-2025-26684Microsoft Defender Elevation of Privilege Vulnerability
CVE-2025-27468Home windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2025-27488Microsoft Home windows {Hardware} Lab Package (HLK) Elevation of Privilege Vulnerability
CVE-2025-29826Microsoft Dataverse Elevation of Privilege Vulnerability
CVE-2025-29838Home windows Execution Context Driver Elevation of Privilege Vulnerability
CVE-2025-29841Common Print Administration Service Elevation of Privilege Vulnerability
CVE-2025-29970Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-29975Microsoft PC Supervisor Elevation of Privilege Vulnerability
CVE-2025-29976Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2025-30385Home windows Widespread Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-30387Doc Intelligence Studio On-Prem Info Disclosure Vulnerability
CVE-2025-30400Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-32701Home windows Widespread Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-32706Home windows Widespread Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-32707NTFS Elevation of Privilege Vulnerability
CVE-2025-32709Home windows Ancillary Operate Driver for WinSock Elevation of Privilege Vulnerability

 

Info Disclosure (15 CVEs)

Important severity
CVE-2025-30398Nuance PowerScribe 360 Info Disclosure Vulnerability
Necessary severity
CVE-2025-29829Home windows Trusted Runtime Interface Driver Info Disclosure Vulnerability
CVE-2025-29830Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29832Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29835Home windows Distant Entry Connection Supervisor Info Disclosure Vulnerability
CVE-2025-29836Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29837Home windows Installer Info Disclosure Vulnerability
CVE-2025-29839Home windows A number of UNC Supplier Driver Info Disclosure Vulnerability
CVE-2025-29956Home windows SMB Info Disclosure Vulnerability
CVE-2025-29958Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29959Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29960Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29961Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29974Home windows Kernel Info Disclosure Vulnerability
CVE-2025-32703Visible Studio Info Disclosure Vulnerability

 

Denial of Service (7 CVEs)

Necessary severity
CVE-2025-26677Home windows Distant Desktop Gateway (RD Gateway) Denial of Service Vulnerability
CVE-2025-29954Home windows Light-weight Listing Entry Protocol (LDAP) Denial of Service Vulnerability
CVE-2025-29955Home windows Hyper-V Denial of Service Vulnerability
CVE-2025-29957Home windows Deployment Providers Denial of Service Vulnerability
CVE-2025-29968Energetic Listing Certificates Providers (AD CS) Denial of Service Vulnerability
CVE-2025-29971Internet Menace Protection (WTD.sys) Denial of Service Vulnerability
CVE-2025-30394Home windows Distant Desktop Gateway (RD Gateway) Denial of Service Vulnerability

 

Safety Characteristic Bypass (2 CVEs)

Necessary severity
CVE-2025-21264Visible Studio Code Safety Characteristic Bypass Vulnerability
CVE-2025-29842UrlMon Safety Characteristic Bypass Vulnerability

 

Spoofing (2 CVEs)

Necessary severity
CVE-2025-26646.NET, Visible Studio, and Construct Instruments for Visible Studio Spoofing Vulnerability
CVE-2025-26685Microsoft Defender for Identification Spoofing Vulnerability

 

 

Appendix B: Exploitability and CVSS

It is a record of the Could CVEs judged by Microsoft to be both beneath exploitation within the wild or extra prone to be exploited within the wild throughout the first 30 days post-release. The record is additional organized by CVE. Curiously, 28 of this month’s vulnerabilities have been marked in Microsoft’s launch supplies as “exploitation unlikely” – a class far much less generally assigned by the corporate prior to now.

Exploitation detected
CVE-2025-30397Scripting Engine Reminiscence Corruption Vulnerability
CVE-2025-30400Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-32701Home windows Widespread Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-32706Home windows Widespread Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-32709Home windows Ancillary Operate Driver for WinSock Elevation of Privilege Vulnerability
Exploitation extra doubtless throughout the subsequent 30 days
CVE-2025-24063Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVE-2025-29841Common Print Administration Service Elevation of Privilege Vulnerability
CVE-2025-29971Internet Menace Protection (WTD.sys) Denial of Service Vulnerability
CVE-2025-29976Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2025-30382Microsoft SharePoint Server Distant Code Execution Vulnerability
CVE-2025-30385Home windows Widespread Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-30386Microsoft Workplace Distant Code Execution Vulnerability
CVE-2025-30388Home windows Graphics Element Distant Code Execution Vulnerability
CVE-2025-30398Nuance PowerScribe 360 Info Disclosure Vulnerability

 

It is a record of Could’s CVEs with a Microsoft-assessed CVSS Base rating of 8.0 or larger. They’re organized by rating and additional sorted by CVE. For extra info on how CVSS works, please see our collection on patch prioritization schema. For a have a look at the CVSS scores for sure merchandise lined on this month’s advisories, please see Appendix D.

CVSS BaseCVSS TemporalCVETitle
9.88.5CVE-2025-30387Doc Intelligence Studio On-Prem Info Disclosure Vulnerability
8.87.7CVE-2025-29840Home windows Media Distant Code Execution Vulnerability
8.87.7CVE-2025-29962Home windows Media Distant Code Execution Vulnerability
8.87.7CVE-2025-29963Home windows Media Distant Code Execution Vulnerability
8.87.7CVE-2025-29964Home windows Media Distant Code Execution Vulnerability
8.87.7CVE-2025-29966Distant Desktop Consumer Distant Code Execution Vulnerability
8.87.7CVE-2025-29967Home windows Distant Desktop Providers Distant Code Execution Vulnerability
8.47.3CVE-2025-30377Microsoft Workplace Distant Code Execution Vulnerability
8.47.3CVE-2025-30386Microsoft Workplace Distant Code Execution Vulnerability
8.47.3CVE-2025-32704Microsoft Excel Distant Code Execution Vulnerability
8.17.1CVE-2025-30398Nuance PowerScribe 360 Info Disclosure Vulnerability
8.07.0CVE-2025-26646.NET, Visible Studio, and Construct Instruments for Visible Studio Spoofing Vulnerability

 

Appendix C: Merchandise Affected

It is a record of Could’s patches sorted by product household, then sub-sorted by severity. Every record is additional organized by CVE. Patches which might be shared amongst a number of product households are listed a number of instances, as soon as for every product household. Sure important points for which advisories have been issued are lined in Appendix D, and points affecting Home windows Server are additional sorted in Appendix E. All CVE titles are correct as made accessible by Microsoft; for additional info on why sure merchandise could seem in titles and never product households (or vice versa), please seek the advice of Microsoft.

Home windows (43 CVEs)

Important severity
CVE-2025-29833Microsoft Digital Machine Bus (VMBus) Distant Code Execution Vulnerability
CVE-2025-29966Distant Desktop Consumer Distant Code Execution Vulnerability
CVE-2025-29967Home windows Distant Desktop Providers Distant Code Execution Vulnerability
Necessary severity
CVE-2025-24063Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVE-2025-26677Home windows Distant Desktop Gateway (RD Gateway) Denial of Service Vulnerability
CVE-2025-27468Home windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2025-29829Home windows Trusted Runtime Interface Driver Info Disclosure Vulnerability
CVE-2025-29830Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29831Home windows Distant Desktop Providers Distant Code Execution Vulnerability
CVE-2025-29832Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29835Home windows Distant Entry Connection Supervisor Info Disclosure Vulnerability
CVE-2025-29836Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29837Home windows Installer Info Disclosure Vulnerability
CVE-2025-29838Home windows ExecutionContext Driver Elevation of Privilege Vulnerability
CVE-2025-29839Home windows A number of UNC Supplier Driver Info Disclosure Vulnerability
CVE-2025-29840Home windows Media Distant Code Execution Vulnerability
CVE-2025-29841Common Print Administration Service Elevation of Privilege Vulnerability
CVE-2025-29842UrlMon Safety Characteristic Bypass Vulnerability
CVE-2025-29954Home windows Light-weight Listing Entry Protocol (LDAP) Denial of Service Vulnerability
CVE-2025-29955Home windows Hyper-V Denial of Service Vulnerability
CVE-2025-29956Home windows SMB Info Disclosure Vulnerability
CVE-2025-29957Home windows Deployment Providers Denial of Service Vulnerability
CVE-2025-29958Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29959Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29960Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29961Home windows Routing and Distant Entry Service (RRAS) Info Disclosure Vulnerability
CVE-2025-29962Home windows Media Distant Code Execution Vulnerability
CVE-2025-29963Home windows Media Distant Code Execution Vulnerability
CVE-2025-29964Home windows Media Distant Code Execution Vulnerability
CVE-2025-29968Energetic Listing Certificates Providers (AD CS) Denial of Service Vulnerability
CVE-2025-29969MS-EVEN RPC Distant Code Execution Vulnerability
CVE-2025-29970Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-29971Internet Menace Protection (WTD.sys) Denial of Service Vulnerability
CVE-2025-29974Home windows Kernel Info Disclosure Vulnerability
CVE-2025-30385Home windows Widespread Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-30388Home windows Graphics Element Distant Code Execution Vulnerability
CVE-2025-30394Home windows Distant Desktop Gateway (RD Gateway) Denial of Service Vulnerability
CVE-2025-30397Scripting Engine Reminiscence Corruption Vulnerability
CVE-2025-30400Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-32701Home windows Widespread Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-32706Home windows Widespread Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-32707NTFS Elevation of Privilege Vulnerability
CVE-2025-32709Home windows Ancillary Operate Driver for WinSock Elevation of Privilege Vulnerability

 

Workplace (14 CVEs)

Important severity
CVE-2025-30377Microsoft Workplace Distant Code Execution Vulnerability
CVE-2025-30386Microsoft Workplace Distant Code Execution Vulnerability
Necessary severity
CVE-2025-29977Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-29978Microsoft PowerPoint Distant Code Execution Vulnerability
CVE-2025-29979Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30375Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30376Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30379Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30381Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30383Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30388Home windows Graphics Element Distant Code Execution Vulnerability
CVE-2025-30393Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-32704Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-32705Microsoft Outlook Distant Code Execution Vulnerability

 

365 (13 CVEs)

Important severity
CVE-2025-30377Microsoft Workplace Distant Code Execution Vulnerability
CVE-2025-30386Microsoft Workplace Distant Code Execution Vulnerability
Necessary severity
CVE-2025-29977Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-29978Microsoft PowerPoint Distant Code Execution Vulnerability
CVE-2025-29979Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30375Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30376Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30379Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30381Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30383Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30393Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-32704Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-32705Microsoft Outlook Distant Code Execution Vulnerability

 

Excel (7 CVEs)

Necessary severity
CVE-2025-29977Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30375Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30376Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30379Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30381Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-30383Microsoft Excel Distant Code Execution Vulnerability
CVE-2025-32704Microsoft Excel Distant Code Execution Vulnerability

 

SharePoint (4 CVEs)

Necessary severity
CVE-2025-29976Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2025-30378Microsoft SharePoint Server Distant Code Execution Vulnerability
CVE-2025-30382Microsoft SharePoint Server Distant Code Execution Vulnerability
CVE-2025-30384Microsoft SharePoint Server Distant Code Execution Vulnerability

 

Visible Studio (4 CVEs)

Necessary severity
CVE-2025-21264Visible Studio Code Safety Characteristic Bypass Vulnerability
CVE-2025-26646.NET, Visible Studio, and Construct Instruments for Visible Studio Spoofing Vulnerability
CVE-2025-32702Visible Studio Distant Code Execution Vulnerability
CVE-2025-32703Visible Studio Info Disclosure Vulnerability

 

RDP Consumer (2 CVEs)

Important severity
CVE-2025-29966Distant Desktop Consumer Distant Code Execution Vulnerability
CVE-2025-29967Home windows Distant Desktop Providers Distant Code Execution Vulnerability

.NET (1 CVE)

Necessary severity
CVE-2025-26646.NET, Visible Studio, and Construct Instruments for Visible Studio Spoofing Vulnerability

 

Azure (1 CVE)

Necessary severity
CVE-2025-30387Doc Intelligence Studio On-Prem Info Disclosure Vulnerability

 

Dataverse (1 CVE)

Necessary severity
CVE-2025-29826Microsoft Dataverse Elevation of Privilege Vulnerability

 

Defender (1 CVE)

Necessary severity
CVE-2025-26685Microsoft Defender for Identification Spoofing Vulnerability

 

Nuance PowerScribe 360 (1 CVE)

Important severity
CVE-2025-30398Nuance PowerScribe 360 Info Disclosure Vulnerability

 

PC Supervisor (1 CVE)

Necessary severity
CVE-2025-29975Microsoft PC Supervisor Elevation of Privilege Vulnerability

 

Home windows HLK (1 CVE)

Necessary severity
CVE-2025-27488Microsoft Home windows {Hardware} Lab Package (HLK) Elevation of Privilege Vulnerability

 

Appendix D: Advisories and Different Merchandise

There are 8 Adobe advisories on this month’s launch.

CVE-2025-43559APSB25-52Improper Enter Validation (CWE-20)
CVE-2025-43560APSB25-52Improper Enter Validation (CWE-20)
CVE-2025-43561APSB25-52Improper Entry Management (CWE-284)
CVE-2025-43562APSB25-52Improper Neutralization of Particular Components utilized in an OS Command (‘OS Command Injection’) (CWE-78)
CVE-2025-43563APSB25-52Improper Entry Management (CWE-284)
CVE-2025-43564APSB25-52Incorrect Authorization (CWE-863)
CVE-2025-43565APSB25-52Improper Entry Management (CWE-284)
CVE-2025-43566APSB25-52Improper Limitation of a Pathname to a Restricted Listing (‘Path Traversal’) (CWE-22)

 

There are, this month, an extra load of Microsoft advisories and informational releases that deserve consideration. Most of them are Edge-related, and we current these within the regular style. Nevertheless, seven further CVEs contain Azure, Dataverse, or Energy Apps. All of them have already been addressed by Microsoft and thus ought to pose no motion merchandise for directors, however are important sufficient that we select to flag them right here with their severities and CVSS scores. Could’s launch additionally contains servicing stack updates.

ADV990001Newest Servicing Stack Updates
CVE-2025-4050Chromium: CVE-2025-4050 Out of bounds reminiscence entry in DevTools
CVE-2025-4051Chromium: CVE-2025-4051 Inadequate information validation in DevTools
CVE-2025-4052Chromium: CVE-2025-4052 Inappropriate implementation in DevTools
CVE-2025-4096Chromium: CVE-2025-4096 Heap buffer overflow in HTML
CVE-2025-4372Chromium: CVE-2025-4372 Use after free in WebAudio
CVE-2025-21353Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2025-21388Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2025-29825Microsoft Edge (Chromium-based) Spoofing Vulnerability

 

CVETitleInfluenceSeverityCVSS BaseCVSS Temporal
CVE-2025-29813Azure DevOps Elevation of Privilege VulnerabilityElevation of PrivilegeImportant10.09.0
CVE-2025-29827Azure Automation Elevation of Privilege VulnerabilityElevation of PrivilegeImportant9.98.9
CVE-2025-29972Azure Storage Useful resource Supplier Spoofing VulnerabilitySpoofingImportant9.98.9
CVE-2025-29973Microsoft Azure File Sync Elevation of Privilege VulnerabilityElevation of PrivilegeNecessary7.06.1
CVE-2025-33072Microsoft msagsfeedback.azurewebsites.web Info Disclosure VulnerabilityInfo DisclosureImportant8.17.1
CVE-2025-47732Microsoft Dataverse Distant Code Execution VulnerabilityDistant Code ExecutionImportant8.77.6
CVE-2025-47733Microsoft Energy Apps Info Disclosure VulnerabilityInfo DisclosureImportant9.17.9

 

 

Appendix E: Affected Home windows Server variations

It is a desk of the CVEs within the Could launch affecting 9 Home windows Server variations, 2008 by way of 2025. The desk differentiates amongst main variations of the platform however doesn’t go into deeper element (eg., Server Core). Important-severity points are marked in purple; an “x” signifies that the CVE doesn’t apply to that model. Directors are inspired to make use of this appendix as a place to begin to determine their particular publicity, as every reader’s state of affairs, particularly because it issues merchandise out of mainstream help, will fluctuate. For particular Information Base numbers, please seek the advice of Microsoft. Please notice that CVE-2025-29971 is a client-only Home windows subject and thus seems on this chart, however with no server variations marked.

20082008-R220122012-R22016201920222022 23H22025
CVE-2025-24063
CVE-2025-26677××××
CVE-2025-27468××
CVE-2025-29829××××
CVE-2025-29830
CVE-2025-29831×
CVE-2025-29832
CVE-2025-29833××
CVE-2025-29835×
CVE-2025-29836
CVE-2025-29837
CVE-2025-29838××××××××
CVE-2025-29839
CVE-2025-29840×××××
CVE-2025-29841××××××
CVE-2025-29842××××
CVE-2025-29954×
CVE-2025-29955×××××××
CVE-2025-29956
CVE-2025-29957
CVE-2025-29958
CVE-2025-29959
CVE-2025-29960
CVE-2025-29961
CVE-2025-29962
CVE-2025-29963×××××
CVE-2025-29964×××××
CVE-2025-29966×
CVE-2025-29967×
CVE-2025-29968×
CVE-2025-29969
CVE-2025-29970×××××××
CVE-2025-29971×××××××××
CVE-2025-29974
CVE-2025-30385
CVE-2025-30388
CVE-2025-30394××
CVE-2025-30397
CVE-2025-30400×××××
CVE-2025-32701
CVE-2025-32706
CVE-2025-32707×××
CVE-2025-32709

 

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles