Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Patches Over 100 Vulnerabilities

Microsoft’s August 2025 Patch Tuesday updates address critical vulnerabilities in Windows, Office, and Hyper-V.

Microsoft vulnerability

Microsoft’s August 2025 Patch Tuesday updates address more than 100 vulnerabilities across the tech giant’s products.

None of the security holes patched this month appear to have been exploited in the wild. One vulnerability, a Windows privilege escalation tracked as CVE-2025-53779, has been flagged as publicly disclosed.

A dozen vulnerabilities have been assigned a ‘critical severity’ rating. Most of them are actually ‘high severity’ based on their CVSS score, except for CVE-2025-53766, a remote code execution flaw in Windows’ GDI+ component that has a CVSS score of 9.8.

According to Trend Micro’s Zero Day Initiative (ZDI), which has summarized the patches, CVE-2025-53766 can be exploited by getting the targeted user to visit a malicious website or to open a malicious document.

“A worst-case scenario would be an attacker uploading something through an ad network that is served up to users. Ad blockers are just to remove annoyances; they also protect against malicious ads,” ZDI’s Dustin Childs explained. “They’re rare, but they have occurred in the past. Since GDI+ touches so many different components (and users tend to click on anything), test and deploy this one quickly.”

Another vulnerability that is ‘critical’ based on its CVSS score is CVE-2025-50165, which impacts Windows’ graphics component and which also allows remote code execution. Exploitation requires the user to view a specially crafted image. Microsoft has assigned the issue an ‘important’ severity rating.

Advertisement. Scroll to continue reading.

Other vulnerabilities allowing remote code execution are CVE-2025-53740 and CVE-2025-53731, which impact Office and can be exploited through the Preview Pane.

Another flaw worth highlighting is CVE-2025-49712, a remote code execution bug affecting SharePoint. ZDI noted that it’s similar to a vulnerability exploited recently as part of the ToolShell exploit chain. 

The list of vulnerabilities flagged as ‘critical’ by Microsoft also includes several Hyper-V issues (information disclosure, spoofing, and remote code execution), and an Azure Stack Hub information disclosure bug.

Microsoft’s exploitability assessment for all of these issues is ‘exploitation less likely’ or ‘exploitation unlikely’, which indicates that the tech giant does not expect them to be exploited in the wild.

Adobe has also released its Patch Tuesday updates, addressing nearly 70 CVEs across over a dozen products.

Related: Microsoft Offers $5 Million at Zero Day Quest Hacking Contest

Related: Organizations Warned of Vulnerability in Microsoft Exchange Hybrid Deployment

Related: Microsoft Paid Out $17 Million in Bug Bounties in Past Year

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.

Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.