Microsoft’s Patch Tuesday update for August 2025 has rolled out fixes addressing 110 vulnerabilities across its systems. This includes nine vulnerabilities identified as higher risk for exploitation, along with five additional vulnerabilities that carry a severity rating of 9.0 or higher. This latest update marks a reduction from July’s total of 130 vulnerabilities.
Critical Vulnerabilities Addressed
Among the vulnerabilities patched, the most critical is CVE-2025-53767, assigned a severity rating of 10.0 for its potential impact on Azure OpenAI. Microsoft confirmed that this vulnerability has been fully mitigated. Another significant vulnerability, CVE-2025-53792, which pertains to the Azure Portal and also involves elevation of privilege, has also been addressed, boasting a severity rating of 9.1.
Additionally, several other high-severity vulnerabilities rated 9.0 and above have been assessed. These include:
- CVE-2025-50171: A Remote Desktop Spoofing vulnerability
- CVE-2025-50165: A Windows Graphics Component leading to Remote Code Execution
- CVE-2025-53766: A GDI+ vulnerability that enables Remote Code Execution
Microsoft has categorized these vulnerabilities as having a lower risk of exploitation, which is an encouraging sign for users and IT administrators alike.
Overview of Vulnerabilities in the August Update
This month’s update also contains fixes for 13 vulnerabilities rated at 8.8 severity, which were discovered in various Microsoft products such as SQL Server, SharePoint, Windows Routing and Remote Access Service (RRAS), Windows Media, Windows Message Queuing, and Web Deploy. Most of these vulnerabilities have been assessed to pose a lower risk.
However, one particular vulnerability, rated 8.8, was found within NTLM and has been deemed higher risk, indicating that users should prioritize its mitigation.
High-Risk Vulnerabilities in Focus
This month highlights ten vulnerabilities that Microsoft has classified as higher risk. Notably, CVE-2025-53786, with a severity rating of 8.0, relates to an elevation of privilege issue in Exchange Server Hybrid Deployment. Alarmingly, current statistics reveal that around 28,000 Exchange instances remain unpatched, as reported by the Shadowserver Foundation, making it imperative for administrators to take immediate action.
Further high-risk vulnerabilities in the August update include:
- CVE-2025-53778: An 8.8-rated Windows NTLM Elevation of Privilege vulnerability
- CVE-2025-53156: A 5.5-rated vulnerability in Windows Storage Port Driver for Information Disclosure
- CVE-2025-53147: A 7.0-rated Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
- CVE-2025-53132: An 8.0-severity Win32k Elevation of Privilege vulnerability
- CVE-2025-50177: An 8.1-rated Microsoft Message Queuing (MSMQ) Remote Code Execution vulnerability
- CVE-2025-50168: A 7.8-rated Win32k Elevation of Privilege vulnerability
- CVE-2025-50167: A 7.0-severity Windows Hyper-V Elevation of Privilege vulnerability
- CVE-2025-49743: A 6.7-severity Windows Graphics Component Elevation of Privilege vulnerability
The release of this month’s Patch Tuesday updates has not only focused on Microsoft’s vulnerabilities but has also seen companies like Fortinet and SAP announcing their own patches, indicating a wider effort across the technology landscape to enhance cybersecurity defenses.


