Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Patches Over 100 Vulnerabilities

Microsoft’s August 2025 Patch Tuesday updates address critical vulnerabilities in Windows, Office, and Hyper-V.

Microsoft vulnerability

Microsoft’s August 2025 Patch Tuesday updates address more than 100 vulnerabilities across the tech giant’s products.

None of the security holes patched this month appear to have been exploited in the wild. One vulnerability, a Windows privilege escalation tracked as CVE-2025-53779, has been flagged as publicly disclosed.

A dozen vulnerabilities have been assigned a ‘critical severity’ rating. Most of them are actually ‘high severity’ based on their CVSS score, except for CVE-2025-53766, a remote code execution flaw in Windows’ GDI+ component that has a CVSS score of 9.8.

According to Trend Micro’s Zero Day Initiative (ZDI), which has summarized the patches, CVE-2025-53766 can be exploited by getting the targeted user to visit a malicious website or to open a malicious document.

“A worst-case scenario would be an attacker uploading something through an ad network that is served up to users. Ad blockers are just to remove annoyances; they also protect against malicious ads,” ZDI’s Dustin Childs explained. “They’re rare, but they have occurred in the past. Since GDI+ touches so many different components (and users tend to click on anything), test and deploy this one quickly.”

Another vulnerability that is ‘critical’ based on its CVSS score is CVE-2025-50165, which impacts Windows’ graphics component and which also allows remote code execution. Exploitation requires the user to view a specially crafted image. Microsoft has assigned the issue an ‘important’ severity rating.

Advertisement. Scroll to continue reading.

Other vulnerabilities allowing remote code execution are CVE-2025-53740 and CVE-2025-53731, which impact Office and can be exploited through the Preview Pane.

Another flaw worth highlighting is CVE-2025-49712, a remote code execution bug affecting SharePoint. ZDI noted that it’s similar to a vulnerability exploited recently as part of the ToolShell exploit chain. 

The list of vulnerabilities flagged as ‘critical’ by Microsoft also includes several Hyper-V issues (information disclosure, spoofing, and remote code execution), and an Azure Stack Hub information disclosure bug.

Microsoft’s exploitability assessment for all of these issues is ‘exploitation less likely’ or ‘exploitation unlikely’, which indicates that the tech giant does not expect them to be exploited in the wild.

Adobe has also released its Patch Tuesday updates, addressing nearly 70 CVEs across over a dozen products.

Related: Microsoft Offers $5 Million at Zero Day Quest Hacking Contest

Related: Organizations Warned of Vulnerability in Microsoft Exchange Hybrid Deployment

Related: Microsoft Paid Out $17 Million in Bug Bounties in Past Year

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.