August 2025 Patch Tuesday: Addressing 9 Critical Vulnerabilities

Published:

spot_img

Microsoft’s Patch Tuesday update for August 2025 has rolled out fixes addressing 110 vulnerabilities across its systems. This includes nine vulnerabilities identified as higher risk for exploitation, along with five additional vulnerabilities that carry a severity rating of 9.0 or higher. This latest update marks a reduction from July’s total of 130 vulnerabilities.

Critical Vulnerabilities Addressed

Among the vulnerabilities patched, the most critical is CVE-2025-53767, assigned a severity rating of 10.0 for its potential impact on Azure OpenAI. Microsoft confirmed that this vulnerability has been fully mitigated. Another significant vulnerability, CVE-2025-53792, which pertains to the Azure Portal and also involves elevation of privilege, has also been addressed, boasting a severity rating of 9.1.

Additionally, several other high-severity vulnerabilities rated 9.0 and above have been assessed. These include:

  • CVE-2025-50171: A Remote Desktop Spoofing vulnerability
  • CVE-2025-50165: A Windows Graphics Component leading to Remote Code Execution
  • CVE-2025-53766: A GDI+ vulnerability that enables Remote Code Execution

Microsoft has categorized these vulnerabilities as having a lower risk of exploitation, which is an encouraging sign for users and IT administrators alike.

Overview of Vulnerabilities in the August Update

This month’s update also contains fixes for 13 vulnerabilities rated at 8.8 severity, which were discovered in various Microsoft products such as SQL Server, SharePoint, Windows Routing and Remote Access Service (RRAS), Windows Media, Windows Message Queuing, and Web Deploy. Most of these vulnerabilities have been assessed to pose a lower risk.

However, one particular vulnerability, rated 8.8, was found within NTLM and has been deemed higher risk, indicating that users should prioritize its mitigation.

High-Risk Vulnerabilities in Focus

This month highlights ten vulnerabilities that Microsoft has classified as higher risk. Notably, CVE-2025-53786, with a severity rating of 8.0, relates to an elevation of privilege issue in Exchange Server Hybrid Deployment. Alarmingly, current statistics reveal that around 28,000 Exchange instances remain unpatched, as reported by the Shadowserver Foundation, making it imperative for administrators to take immediate action.

Further high-risk vulnerabilities in the August update include:

  • CVE-2025-53778: An 8.8-rated Windows NTLM Elevation of Privilege vulnerability
  • CVE-2025-53156: A 5.5-rated vulnerability in Windows Storage Port Driver for Information Disclosure
  • CVE-2025-53147: A 7.0-rated Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
  • CVE-2025-53132: An 8.0-severity Win32k Elevation of Privilege vulnerability
  • CVE-2025-50177: An 8.1-rated Microsoft Message Queuing (MSMQ) Remote Code Execution vulnerability
  • CVE-2025-50168: A 7.8-rated Win32k Elevation of Privilege vulnerability
  • CVE-2025-50167: A 7.0-severity Windows Hyper-V Elevation of Privilege vulnerability
  • CVE-2025-49743: A 6.7-severity Windows Graphics Component Elevation of Privilege vulnerability

The release of this month’s Patch Tuesday updates has not only focused on Microsoft’s vulnerabilities but has also seen companies like Fortinet and SAP announcing their own patches, indicating a wider effort across the technology landscape to enhance cybersecurity defenses.

spot_img

Related articles

Recent articles

Coordinated Cyberattack Disrupts Operational Technology in 30+ Minnesota Water Utilities, Revealing Vulnerabilities and Response Gaps

In a significant cybersecurity incident, over 30 water and wastewater utilities in Minnesota were targeted by a coordinated cyberattack between July 26 and July...

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...