Microsoft Security Bulletin Re-Releases/Advisories

Discussion in 'Virus Software Updates (Read Only)' started by NICK ADSL UK, Jun 19, 2008.

  1. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    March 2025 Security Updates
    This release consists of the following 57 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?

    Windows exFAT File System CVE-2025-21180
    Azure Agent Installer CVE-2025-21199
    Windows MapUrlToZone CVE-2025-21247
    Windows Remote Desktop Services CVE-2025-24035
    .NET CVE-2025-24043
    Windows Win32 Kernel Subsystem CVE-2025-24044
    Windows Remote Desktop Services CVE-2025-24045
    Microsoft Streaming Service CVE-2025-24046
    Role: Windows Hyper-V CVE-2025-24048
    Azure CLI CVE-2025-24049
    Role: Windows Hyper-V CVE-2025-24050
    Windows Routing and Remote Access Service (RRAS) CVE-2025-24051
    Windows NTLM CVE-2025-24054
    Windows USB Video Driver CVE-2025-24055
    Windows Telephony Server CVE-2025-24056
    Microsoft Office CVE-2025-24057
    Windows Common Log File System Driver CVE-2025-24059
    Windows Mark of the Web (MOTW) CVE-2025-24061
    Role: DNS Server CVE-2025-24064
    Windows Kernel-Mode Drivers CVE-2025-24066
    Microsoft Streaming Service CVE-2025-24067
    ASP.NET Core & Visual Studio CVE-2025-24070
    Windows File Explorer CVE-2025-24071
    Microsoft Local Security Authority Server (lsasrv) CVE-2025-24072
    Microsoft Office Excel CVE-2025-24075
    Windows Cross Device Service CVE-2025-24076
    Microsoft Office Word CVE-2025-24077
    Microsoft Office Word CVE-2025-24078
    Microsoft Office Word CVE-2025-24079
    Microsoft Office CVE-2025-24080
    Microsoft Office Excel CVE-2025-24081
    Microsoft Office Excel CVE-2025-24082
    Microsoft Office CVE-2025-24083
    Windows Subsystem for Linux CVE-2025-24084
    Windows Win32 Kernel Subsystem CVE-2025-24983
    Windows NTFS CVE-2025-24984
    Windows Fast FAT Driver CVE-2025-24985
    Azure PromptFlow CVE-2025-24986
    Windows USB Video Driver CVE-2025-24987
    Windows USB Video Driver CVE-2025-24988
    Windows NTFS CVE-2025-24991
    Windows NTFS CVE-2025-24992
    Windows NTFS CVE-2025-24993
    Windows Cross Device Service CVE-2025-24994
    Kernel Streaming WOW Thunk Service Driver CVE-2025-24995
    Windows NTLM CVE-2025-24996
    Windows Kernel Memory CVE-2025-24997
    Visual Studio CVE-2025-24998
    Visual Studio CVE-2025-25003
    Microsoft Windows CVE-2025-25008
    Azure Arc CVE-2025-26627
    Microsoft Office CVE-2025-26629
    Microsoft Office Access CVE-2025-26630
    Visual Studio Code CVE-2025-26631
    Microsoft Management Console CVE-2025-26633
    Microsoft Edge (Chromium-based) CVE-2025-26643
    Remote Desktop Client CVE-2025-26645

    We are republishing 10 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    Synaptics, Inc. Microsoft Windows CVE-2024-9157 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1914 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1915 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1916 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1917 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1918 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1919 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1921 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1922 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1923 Yes No No

    Security Update Guide Blog Posts
    Date Blog Post
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5053596 Windows 10, version 1809, Windows Server 2019
    5053598 Windows 11, version 24H2
    5053599 Windows Server 2022, 23H2 Edition (Server Core installation)
    5053602 Windows 11, version 22H2, Windows 11, version 23H2
    5053606 Windows 10, version 21H2, Windows 10, version 22H2
    5053888 Windows Server 2008 (Monthly Rollup)
    5053995 Windows Server 2008 (Security-only update)

    Released: Mar 11, 2025
    March 2025 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  2. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    April 2025 Security Updates
    This release consists of the following 126 Microsoft CVEs:

    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?
    Visual Studio Code CVE-2025-20570
    Windows Standards-Based Storage Management Service CVE-2025-21174
    Windows Local Security Authority (LSA) CVE-2025-21191
    Windows NTFS CVE-2025-21197
    Windows Routing and Remote Access Service (RRAS) CVE-2025-21203
    Windows Update Stack CVE-2025-21204
    Windows Telephony Service CVE-2025-21205
    Windows Telephony Service CVE-2025-21221
    Windows Telephony Service CVE-2025-21222
    Windows DWM Core Library CVE-2025-24058
    Windows DWM Core Library CVE-2025-24060
    Windows DWM Core Library CVE-2025-24062
    Windows DWM Core Library CVE-2025-24073
    Windows DWM Core Library CVE-2025-24074
    Microsoft Edge (Chromium-based) CVE-2025-25000
    Microsoft Edge (Chromium-based) CVE-2025-25001
    Azure Local Cluster CVE-2025-25002
    Azure Local Cluster CVE-2025-26628
    Windows Hello CVE-2025-26635
    Windows BitLocker CVE-2025-26637
    Windows USB Print Driver CVE-2025-26639
    Windows Digital Media CVE-2025-26640
    Windows Cryptographic Services CVE-2025-26641
    Microsoft Office CVE-2025-26642
    Windows Hello CVE-2025-26644
    Windows Kerberos CVE-2025-26647
    Windows Kernel CVE-2025-26648
    Windows Secure Channel CVE-2025-26649
    Windows Local Session Manager (LSM) CVE-2025-26651
    Windows Standards-Based Storage Management Service CVE-2025-26652
    Windows LDAP - Lightweight Directory Access Protocol CVE-2025-26663
    Windows Routing and Remote Access Service (RRAS) CVE-2025-26664
    Windows upnphost.dll CVE-2025-26665
    Windows Media CVE-2025-26666
    Windows Routing and Remote Access Service (RRAS) CVE-2025-26667
    Windows Routing and Remote Access Service (RRAS) CVE-2025-26668
    Windows Routing and Remote Access Service (RRAS) CVE-2025-26669
    Windows LDAP - Lightweight Directory Access Protocol CVE-2025-26670
    Windows Remote Desktop Services CVE-2025-26671
    Windows Routing and Remote Access Service (RRAS) CVE-2025-26672
    Windows LDAP - Lightweight Directory Access Protocol CVE-2025-26673
    Windows Media CVE-2025-26674
    Windows Subsystem for Linux CVE-2025-26675
    Windows Routing and Remote Access Service (RRAS) CVE-2025-26676
    Windows Defender Application Control (WDAC) CVE-2025-26678
    RPC Endpoint Mapper Service CVE-2025-26679
    Windows Standards-Based Storage Management Service CVE-2025-26680
    Windows Win32K - GRFX CVE-2025-26681
    ASP.NET Core CVE-2025-26682
    Windows TCP/IP CVE-2025-26686
    Windows Win32K - GRFX CVE-2025-26687
    Microsoft Virtual Hard Drive CVE-2025-26688
    Windows Digital Media CVE-2025-27467
    Windows LDAP - Lightweight Directory Access Protocol CVE-2025-27469
    Windows Standards-Based Storage Management Service CVE-2025-27470
    Microsoft Streaming Service CVE-2025-27471
    Windows Mark of the Web (MOTW) CVE-2025-27472
    Windows HTTP.sys CVE-2025-27473
    Windows Routing and Remote Access Service (RRAS) CVE-2025-27474
    Windows Update Stack CVE-2025-27475
    Windows Digital Media CVE-2025-27476
    Windows Telephony Service CVE-2025-27477
    Windows Local Security Authority (LSA) CVE-2025-27478
    Windows Kerberos CVE-2025-27479
    Remote Desktop Gateway Service CVE-2025-27480
    Windows Telephony Service CVE-2025-27481
    Remote Desktop Gateway Service CVE-2025-27482
    Windows NTFS CVE-2025-27483
    Windows Universal Plug and Play (UPnP) Device Host CVE-2025-27484
    Windows Standards-Based Storage Management Service CVE-2025-27485
    Windows Standards-Based Storage Management Service CVE-2025-27486
    Remote Desktop Client CVE-2025-27487
    Azure Local CVE-2025-27489
    Windows Bluetooth Service CVE-2025-27490
    Windows Hyper-V CVE-2025-27491
    Windows Secure Channel CVE-2025-27492
    Windows Installer CVE-2025-27727
    Windows Kernel-Mode Drivers CVE-2025-27728
    Windows Shell CVE-2025-27729
    Windows Digital Media CVE-2025-27730
    OpenSSH for Windows CVE-2025-27731
    Windows Win32K - GRFX CVE-2025-27732
    Windows NTFS CVE-2025-27733
    Windows Virtualization-Based Security (VBS) Enclave CVE-2025-27735
    Windows Power Dependency Coordinator CVE-2025-27736
    Windows Security Zone Mapping CVE-2025-27737
    Windows Resilient File System (ReFS) CVE-2025-27738
    Windows Kernel CVE-2025-27739
    Windows Active Directory Certificate Services CVE-2025-27740
    Windows NTFS CVE-2025-27741
    Windows NTFS CVE-2025-27742
    System Center CVE-2025-27743
    Microsoft Office CVE-2025-27744
    Microsoft Office CVE-2025-27745
    Microsoft Office CVE-2025-27746
    Microsoft Office Word CVE-2025-27747
    Microsoft Office CVE-2025-27748
    Microsoft Office CVE-2025-27749
    Microsoft Office Excel CVE-2025-27750
    Microsoft Office Excel CVE-2025-27751
    Microsoft Office Excel CVE-2025-27752
    Microsoft Office CVE-2025-29791
    Microsoft Office CVE-2025-29792
    Microsoft Office SharePoint CVE-2025-29793
    Microsoft Office SharePoint CVE-2025-29794
    Microsoft Edge for iOS CVE-2025-29796
    Microsoft AutoUpdate (MAU) CVE-2025-29800
    Microsoft AutoUpdate (MAU) CVE-2025-29801
    Visual Studio CVE-2025-29802
    Visual Studio Tools for Applications and SQL Server Management Studio CVE-2025-29803
    Visual Studio CVE-2025-29804
    Outlook for Android CVE-2025-29805
    Windows Cryptographic Services CVE-2025-29808
    Windows Kerberos CVE-2025-29809
    Active Directory Domain Services CVE-2025-29810
    Windows Mobile Broadband CVE-2025-29811
    Windows Kernel Memory CVE-2025-29812
    Microsoft Edge (Chromium-based) CVE-2025-29815
    Microsoft Office Word CVE-2025-29816
    Power Automate CVE-2025-29817
    Azure Portal Windows Admin Center CVE-2025-29819
    Microsoft Office Word CVE-2025-29820
    Dynamics Business Central CVE-2025-29821
    Microsoft Office OneNote CVE-2025-29822
    Microsoft Office Excel CVE-2025-29823
    Windows Common Log File System Driver CVE-2025-29824

    We are republishing 9 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3066
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3067
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3068
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3069
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3070
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3071
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3072
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3073
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3074

    Security Update Guide Blog Posts
    Date Blog Post
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5055518 Windows 10, version 21H2, Windows 10, version 22H2
    5055519 Windows 10, version 1809, Windows Server 2019
    5055523 Windows 11, version 24H2
    5055526 Windows Server 2022
    5055527 Windows Server 2022, 23H2 Edition (Server Core installation)
    5055528 Windows 11, version 22H2, Windows 11, version 23H2
    5055596 Windows Server 2008 (Security-only update)
    5055609 Windows Server 2008 (Monthly Rollup)
    Released: Apr 8, 2025
    April 2025 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  3. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    May 2025 Security Updates
    This release consists of the following 78 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?

    Visual Studio Code CVE-2025-21264
    Windows Kernel CVE-2025-24063
    .NET, Visual Studio, and Build Tools for Visual Studio CVE-2025-26646
    Remote Desktop Gateway Service CVE-2025-26677
    Microsoft Defender for Endpoint CVE-2025-26684
    Microsoft Defender for Identity CVE-2025-26685
    Windows Secure Kernel Mode CVE-2025-27468
    Windows Hardware Lab Kit CVE-2025-27488
    Azure DevOps CVE-2025-29813
    Microsoft Edge (Chromium-based) CVE-2025-29825
    Microsoft Dataverse CVE-2025-29826
    Azure Automation CVE-2025-29827
    Windows Trusted Runtime Interface Driver CVE-2025-29829
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29830
    Remote Desktop Gateway Service CVE-2025-29831
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29832
    Windows Virtual Machine Bus CVE-2025-29833
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29835
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29836
    Windows Installer CVE-2025-29837
    Windows Drivers CVE-2025-29838
    Windows File Server CVE-2025-29839
    Windows Media CVE-2025-29840
    Universal Print Management Service CVE-2025-29841
    UrlMon CVE-2025-29842
    Windows LDAP - Lightweight Directory Access Protocol CVE-2025-29954
    Role: Windows Hyper-V CVE-2025-29955
    Windows SMB CVE-2025-29956
    Windows Deployment Services CVE-2025-29957
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29958
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29959
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29960
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29961
    Windows Media CVE-2025-29962
    Windows Media CVE-2025-29963
    Windows Media CVE-2025-29964
    Windows Remote Desktop CVE-2025-29966
    Remote Desktop Gateway Service CVE-2025-29967
    Active Directory Certificate Services (AD CS) CVE-2025-29968
    Windows Fundamentals CVE-2025-29969
    Microsoft Brokering File System CVE-2025-29970
    Web Threat Defense (WTD.sys) CVE-2025-29971
    Azure Storage Resource Provider CVE-2025-29972
    Azure File Sync CVE-2025-29973
    Windows Kernel CVE-2025-29974
    Microsoft PC Manager CVE-2025-29975
    Microsoft Office SharePoint CVE-2025-29976
    Microsoft Office Excel CVE-2025-29977
    Microsoft Office PowerPoint CVE-2025-29978
    Microsoft Office Excel CVE-2025-29979
    Microsoft Office Excel CVE-2025-30375
    Microsoft Office Excel CVE-2025-30376
    Microsoft Office CVE-2025-30377
    Microsoft Office SharePoint CVE-2025-30378
    Microsoft Office Excel CVE-2025-30379
    Microsoft Office Excel CVE-2025-30381
    Microsoft Office SharePoint CVE-2025-30382
    Microsoft Office Excel CVE-2025-30383
    Microsoft Office SharePoint CVE-2025-30384
    Windows Common Log File System Driver CVE-2025-30385
    Microsoft Office CVE-2025-30386
    Azure CVE-2025-30387
    Windows Win32K - GRFX CVE-2025-30388
    Microsoft Office Excel CVE-2025-30393
    Remote Desktop Gateway Service CVE-2025-30394
    Microsoft Scripting Engine CVE-2025-30397
    Windows DWM CVE-2025-30400
    Windows Common Log File System Driver CVE-2025-32701
    Visual Studio CVE-2025-32702
    Visual Studio CVE-2025-32703
    Microsoft Office Excel CVE-2025-32704
    Microsoft Office Outlook CVE-2025-32705
    Windows Common Log File System Driver CVE-2025-32706
    Windows NTFS CVE-2025-32707
    Windows Ancillary Function Driver for WinSock CVE-2025-32709
    Azure CVE-2025-33072
    Microsoft Dataverse CVE-2025-47732
    Microsoft Power Apps CVE-2025-47733

    We are republishing 5 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    Chrome Microsoft Edge (Chromium-based) CVE-2025-4050
    Chrome Microsoft Edge (Chromium-based) CVE-2025-4051
    Chrome Microsoft Edge (Chromium-based) CVE-2025-4052
    Chrome Microsoft Edge (Chromium-based) CVE-2025-4096
    Chrome Microsoft Edge (Chromium-based) CVE-2025-4372

    Security Update Guide Blog Posts
    Date Blog Post
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5058379 Windows 10, version 21H2, Windows 10, version 22H2
    5058384 Windows Server 2022, 23H2 Edition (Server Core installation)
    5058385 Windows Server 2022
    5058392 Windows 10, version 1809, Windows Server 2019
    5058405 Windows 11, version 22H2, Windows 11, version 23H2
    5058411 Windows 11, version 24H2
    5058429 Windows Server 2008 (Security-only update)
    5058449 Windows Server 2008 (Monthly Rollup)
    Released: May 13, 2025
    May 2025 Security Updates - Release Notes - Security Update Guide - Microsoft

     
  4. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    June 2025 Security Updates



    This release consists of the following 66 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?

    Windows Storage Management Provider CVE-2025-24065
    Windows Storage Management Provider CVE-2025-24068
    Windows Storage Management Provider CVE-2025-24069
    Windows Cryptographic Services CVE-2025-29828
    .NET and Visual Studio CVE-2025-30399
    Windows Remote Desktop Services CVE-2025-32710
    Windows Win32K - GRFX CVE-2025-32712
    Windows Common Log File System Driver CVE-2025-32713
    Windows Installer CVE-2025-32714
    Remote Desktop Client CVE-2025-32715
    Windows Media CVE-2025-32716
    Windows SMB CVE-2025-32718
    Windows Storage Management Provider CVE-2025-32719
    Windows Storage Management Provider CVE-2025-32720
    Windows Recovery Driver CVE-2025-32721
    Windows Storage Port Driver CVE-2025-32722
    Windows Local Security Authority Subsystem Service (LSASS) CVE-2025-32724
    Windows DHCP Server CVE-2025-32725
    Windows DHCP Server CVE-2025-33050
    Windows DWM Core Library CVE-2025-33052
    WebDAV CVE-2025-33053
    Windows Storage Management Provider CVE-2025-33055
    Microsoft Local Security Authority Server (lsasrv) CVE-2025-33056
    Windows Local Security Authority (LSA) CVE-2025-33057
    Windows Storage Management Provider CVE-2025-33058
    Windows Storage Management Provider CVE-2025-33059
    Windows Storage Management Provider CVE-2025-33060
    Windows Storage Management Provider CVE-2025-33061
    Windows Storage Management Provider CVE-2025-33062
    Windows Storage Management Provider CVE-2025-33063
    Windows Routing and Remote Access Service (RRAS) CVE-2025-33064
    Windows Storage Management Provider CVE-2025-33065
    Windows Routing and Remote Access Service (RRAS) CVE-2025-33066
    Windows Kernel CVE-2025-33067
    Windows Standards-Based Storage Management Service CVE-2025-33068
    App Control for Business (WDAC) CVE-2025-33069
    Windows Netlogon CVE-2025-33070
    Windows KDC Proxy Service (KPSSVC) CVE-2025-33071
    Windows SMB CVE-2025-33073 8.8
    Windows Installer CVE-2025-33075
    Windows Shell CVE-2025-47160
    Microsoft Office CVE-2025-47162
    Microsoft Office SharePoint CVE-2025-47163
    Microsoft Office CVE-2025-47164 8.4
    Microsoft Office Excel CVE-2025-47165
    Microsoft Office SharePoint CVE-2025-47166
    Microsoft Office CVE-2025-47167
    Microsoft Office Word CVE-2025-47168
    Microsoft Office Word CVE-2025-47169
    Microsoft Office Word CVE-2025-47170
    Microsoft Office Outlook CVE-2025-47171
    Microsoft Office SharePoint CVE-2025-47172
    Microsoft Office CVE-2025-47173
    Microsoft Office Excel CVE-2025-47174
    Microsoft Office PowerPoint CVE-2025-47175
    Microsoft Office Outlook CVE-2025-47176
    Microsoft Office CVE-2025-47953
    Windows Remote Access Connection Manager CVE-2025-47955
    Windows Security App CVE-2025-47956
    Microsoft Office Word CVE-2025-47957
    Visual Studio CVE-2025-47959
    Windows SDK CVE-2025-47962
    Power Automate CVE-2025-47966
    Microsoft AutoUpdate (MAU) CVE-2025-47968
    Windows Hello CVE-2025-47969
    Nuance Digital Engagement Platform CVE-2025-47977

    We are republishing 3 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?

    CERT/CC Windows Secure Boot CVE-2025-3052
    Chrome Microsoft Edge (Chromium-based) CVE-2025-5068
    Chrome Microsoft Edge (Chromium-based) CVE-2025-5419

    Security Update Guide Blog Posts
    Date Blog Post

    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5002735 Excel 2016
    5002736 SharePoint Server Subscription Edition
    5060533 Windows 10, version 21H2, Windows 10, version 22H2
    5060842 Windows 11, version 24H2
    5060999 Windows 11, version 22H2, Windows 11, version 23H2
    5061026 Windows Server 2008 (Monthly Rollup)
    5061072 Windows Server 2008 (Security-only update)


    Released: Jun 10, 2025
    June 2025 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  5. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    July 2025 Security Updates


    This release consists of the following 130 Microsoft CVEs:

    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?


    Service Fabric CVE-2025-21195

    Windows Kernel CVE-2025-26636

    Remote Desktop Client CVE-2025-33054

    Windows Visual Basic Scripting CVE-2025-47159

    Microsoft Intune CVE-2025-47178

    Virtual Hard Disk (VHDX) CVE-2025-47971

    Microsoft Input Method Editor (IME) CVE-2025-47972

    Virtual Hard Disk (VHDX) CVE-2025-47973

    Windows SSDP Service CVE-2025-47975

    Windows SSDP Service CVE-2025-47976

    Windows Kerberos CVE-2025-47978

    Windows Imaging Component CVE-2025-47980

    Windows SPNEGO Extended Negotiation CVE-2025-47981

    Windows Storage VSP Driver CVE-2025-47982

    Windows GDI CVE-2025-47984

    Windows Event Tracing CVE-2025-47985

    Universal Print Management Service CVE-2025-47986

    Windows Cred SSProvider Protocol CVE-2025-47987

    Azure Monitor Agent CVE-2025-47988

    Microsoft Input Method Editor (IME) CVE-2025-47991

    Microsoft PC Manager CVE-2025-47993

    Microsoft Office CVE-2025-47994

    Windows MBT Transport driver CVE-2025-47996

    Windows Routing and Remote Access Service (RRAS) CVE-2025-47998

    Role: Windows Hyper-V CVE-2025-47999

    Windows Connected Devices Platform Service CVE-2025-48000

    Windows BitLocker CVE-2025-48001

    Role: Windows Hyper-V CVE-2025-48002

    Windows BitLocker CVE-2025-48003

    Windows Update Service CVE-2025-48799

    Windows BitLocker CVE-2025-48800

    Windows SMB CVE-2025-48802

    Windows Virtualization-Based Security (VBS) Enclave CVE-2025-48803

    Windows BitLocker CVE-2025-48804

    Microsoft MPEG-2 Video Extension CVE-2025-48805

    Microsoft MPEG-2 Video Extension CVE-2025-48806

    Windows Kernel CVE-2025-48808

    Windows Kernel CVE-2025-48809

    Windows Secure Kernel Mode CVE-2025-48810

    Windows Virtualization-Based Security (VBS) Enclave CVE-2025-48811

    Microsoft Office Excel CVE-2025-48812

    Windows Remote Desktop Licensing Service CVE-2025-48814

    Windows SSDP Service CVE-2025-48815

    HID class driver CVE-2025-48816

    Remote Desktop Client CVE-2025-48817

    Windows BitLocker CVE-2025-48818

    Windows Universal Plug and Play (UPnP) Device Host CVE-2025-48819

    Windows AppX Deployment Service CVE-2025-48820

    Windows Universal Plug and Play (UPnP) Device Host CVE-2025-48821

    Role: Windows Hyper-V CVE-2025-48822

    Windows Cryptographic Services CVE-2025-48823

    Windows Routing and Remote Access Service (RRAS) CVE-2025-48824

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49657

    Windows TDX.sys CVE-2025-49658

    Windows TDX.sys CVE-2025-49659

    Windows Event Tracing CVE-2025-49660

    Windows Ancillary Function Driver for WinSock CVE-2025-49661

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49663

    Windows User-Mode Driver Framework Host CVE-2025-49664

    Workspace Broker CVE-2025-49665

    Windows Kernel CVE-2025-49666

    Windows Win32K - ICOMP CVE-2025-49667

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49668

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49669

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49670

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49671

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49672

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49673

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49674

    Kernel Streaming WOW Thunk Service Driver CVE-2025-49675

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49676

    Microsoft Brokering File System CVE-2025-49677

    Windows NTFS CVE-2025-49678

    Windows Shell CVE-2025-49679

    Windows Performance Recorder CVE-2025-49680

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49681

    Windows Media CVE-2025-49682

    Virtual Hard Disk (VHDX) CVE-2025-49683

    Storage Port Driver CVE-2025-49684

    Microsoft Windows Search Component CVE-2025-49685

    Windows TCP/IP CVE-2025-49686

    Microsoft Input Method Editor (IME) CVE-2025-49687

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49688

    Virtual Hard Disk (VHDX) CVE-2025-49689

    Capability Access Management Service (camsvc) CVE-2025-49690

    Windows Media CVE-2025-49691

    Microsoft Brokering File System CVE-2025-49693

    Microsoft Brokering File System CVE-2025-49694

    Microsoft Office CVE-2025-49695

    Microsoft Office CVE-2025-49696

    Microsoft Office CVE-2025-49697

    Microsoft Office Word CVE-2025-49698

    Microsoft Office CVE-2025-49699 Microsoft Office Word CVE-2025-49700

    Microsoft Office SharePoint CVE-2025-49701

    Microsoft Office CVE-2025-49702

    Microsoft Office Word CVE-2025-49703

    Microsoft Office SharePoint CVE-2025-49704

    Microsoft Office PowerPoint CVE-2025-49705

    Microsoft Office SharePoint CVE-2025-49706

    Microsoft Office Excel CVE-2025-49711

    Microsoft Edge (Chromium-based) CVE-2025-49713

    Visual Studio Code - Python extension CVE-2025-49714

    Windows Netlogon CVE-2025-49716

    SQL Server CVE-2025-49717

    SQL Server CVE-2025-49718

    SQL Server CVE-2025-49719

    Windows Fast FAT Driver CVE-2025-49721

    Windows Print Spooler Components CVE-2025-49722

    Windows StateRepository API CVE-2025-49723

    Windows Connected Devices Platform Service CVE-2025-49724

    Windows Notification CVE-2025-49725

    Windows Notification CVE-2025-49726

    Windows Win32K - GRFX CVE-2025-49727

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49729

    Microsoft Windows QoS scheduler CVE-2025-49730

    Microsoft Teams CVE-2025-49731

    Microsoft Graphics Component CVE-2025-49732

    Windows Win32K - ICOMP CVE-2025-49733

    Windows KDC Proxy Service (KPSSVC) CVE-2025-49735

    Microsoft Teams CVE-2025-49737

    Microsoft PC Manager CVE-2025-49738

    Visual Studio CVE-2025-49739

    Windows SmartScreen CVE-2025-49740

    Microsoft Edge (Chromium-based) CVE-2025-49741

    Microsoft Graphics Component CVE-2025-49742

    Microsoft Graphics Component CVE-2025-49744

    Windows Routing and Remote Access Service (RRAS) CVE-2025-49753

    Office Developer Platform CVE-2025-49756

    Windows Storage CVE-2025-49760


    We are republishing 10 non-Microsoft CVEs:

    CNA Tag CVE FAQs? Workarounds? Mitigations?

    MITRE Visual Studio CVE-2025-27613

    MITRE Visual Studio CVE-2025-27614

    AMD AMD Store Queue CVE-2025-36350

    AMD AMD L1 Data Queue CVE-2025-36357

    MITRE Visual Studio CVE-2025-46334

    MITRE Visual Studio CVE-2025-46835

    MITRE Visual Studio CVE-2025-48384

    MITRE Visual Studio CVE-2025-48385

    MITRE Visual Studio CVE-2025-48386

    Chrome Microsoft Edge (Chromium-based) CVE-2025-6554


    Security Update Guide Blog Posts

    Date Blog Post

    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files

    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs

    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs

    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API

    January 11, 2022 Coming Soon: New Security Update Guide Notification System

    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API

    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners

    December 8, 2020 Security Update Guide: Let’s keep the conversation going

    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide


    Relevant Resources

    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.

    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.

    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.

    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.

    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.

    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues

    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.


    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).


    KB Article Applies To

    5062554 Windows 10, version 21H2, Windows 10, version 22H2

    5062557 Windows 10, version 1809, Windows Server 2019

    5062560 Windows 10, version 1607, Windows Server 2016

    5062572 Windows Server 2022

    5062618 Windows Server 2008 (Security-only update)

    5062624 Windows Server 2008 (Monthly Rollup)

    Released: Jul 8, 2025


    July 2025 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  6. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    August 2025 Security Updates

    This release consists of the following 111 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?

    SQL Server CVE-2025-24999

    Microsoft Exchange Server CVE-2025-25005
    Microsoft Exchange Server CVE-2025-25006
    Microsoft Exchange Server CVE-2025-25007
    Microsoft Exchange Server CVE-2025-33051
    SQL Server CVE-2025-47954
    Role: Windows Hyper-V CVE-2025-48807
    Azure Virtual Machines CVE-2025-49707
    Microsoft Office SharePoint CVE-2025-49712
    Microsoft Edge for Android CVE-2025-49736
    Microsoft Graphics Component CVE-2025-49743
    Microsoft Dynamics 365 (on-premises) CVE-2025-49745
    Role: Windows Hyper-V CVE-2025-49751
    Microsoft Edge for Android CVE-2025-49755
    Windows Routing and Remote Access Service (RRAS) CVE-2025-49757
    SQL Server CVE-2025-49758
    SQL Server CVE-2025-49759
    Windows Kernel CVE-2025-49761
    Windows Ancillary Function Driver for WinSock CVE-2025-49762
    Desktop Windows Manager CVE-2025-50153
    Windows File Explorer CVE-2025-50154
    Windows Push Notifications CVE-2025-50155
    Windows Routing and Remote Access Service (RRAS) CVE-2025-50156
    Windows Routing and Remote Access Service (RRAS) CVE-2025-50157
    Windows NTFS CVE-2025-50158
    Remote Access Point-to-Point Protocol (PPP) EAP-TLS CVE-2025-50159
    Windows Routing and Remote Access Service (RRAS) CVE-2025-50160
    Windows Win32K - GRFX CVE-2025-50161
    Windows Routing and Remote Access Service (RRAS) CVE-2025-50162
    Windows Routing and Remote Access Service (RRAS) CVE-2025-50163
    Windows Routing and Remote Access Service (RRAS) CVE-2025-50164
    Microsoft Graphics Component CVE-2025-50165
    Windows Distributed Transaction Coordinator CVE-2025-50166
    Role: Windows Hyper-V CVE-2025-50167
    Windows Win32K - ICOMP CVE-2025-50168
    Windows SMB CVE-2025-50169
    Windows Cloud Files Mini Filter Driver CVE-2025-50170
    Remote Desktop Server CVE-2025-50171
    Windows DirectX CVE-2025-50172
    Windows Installer CVE-2025-50173
    Graphics Kernel CVE-2025-50176
    Windows Message Queuing CVE-2025-50177
    Windows Media CVE-2025-53131
    Windows Win32K - GRFX CVE-2025-53132
    Windows PrintWorkflowUserSvc CVE-2025-53133
    Windows Ancillary Function Driver for WinSock CVE-2025-53134
    Windows DirectX CVE-2025-53135
    Windows NT OS Kernel CVE-2025-53136
    Windows Ancillary Function Driver for WinSock CVE-2025-53137
    Windows Routing and Remote Access Service (RRAS) CVE-2025-53138
    Kernel Transaction Manager CVE-2025-53140
    Windows Ancillary Function Driver for WinSock CVE-2025-53141
    Microsoft Brokering File System CVE-2025-53142
    Windows Message Queuing CVE-2025-53143
    Windows Message Queuing CVE-2025-53144
    Windows Message Queuing CVE-2025-53145
    Windows Ancillary Function Driver for WinSock CVE-2025-53147
    Windows Routing and Remote Access Service (RRAS) CVE-2025-53148
    Kernel Streaming WOW Thunk Service Driver CVE-2025-53149
    Windows Kernel CVE-2025-53151
    Desktop Windows Manager CVE-2025-53152
    Windows Routing and Remote Access Service (RRAS) CVE-2025-53153
    Windows Ancillary Function Driver for WinSock CVE-2025-53154
    Role: Windows Hyper-V CVE-2025-53155
    Storage Port Driver CVE-2025-53156
    Windows Local Security Authority Subsystem Service (LSASS) CVE-2025-53716
    Windows Ancillary Function Driver for WinSock CVE-2025-53718
    Windows Routing and Remote Access Service (RRAS) CVE-2025-53719
    Windows Routing and Remote Access Service (RRAS) CVE-2025-53720
    Windows Connected Devices Platform Service CVE-2025-53721
    Windows Remote Desktop Services CVE-2025-53722
    Role: Windows Hyper-V CVE-2025-53723
    Windows Push Notifications CVE-2025-53724
    Windows Push Notifications CVE-2025-53725
    Windows Push Notifications CVE-2025-53726
    SQL Server CVE-2025-53727
    Microsoft Dynamics 365 (on-premises) CVE-2025-53728
    Azure File Sync CVE-2025-53729
    Microsoft Office Visio CVE-2025-53730
    Microsoft Office CVE-2025-53731
    Microsoft Office CVE-2025-53732
    Microsoft Office Word CVE-2025-53733
    Microsoft Office Visio CVE-2025-53734
    Microsoft Office Excel CVE-2025-53735
    Microsoft Office Word CVE-2025-53736
    Microsoft Office Excel CVE-2025-53737
    Microsoft Office Word CVE-2025-53738
    Microsoft Office Excel CVE-2025-53739
    Microsoft Office CVE-2025-53740
    Microsoft Office Excel CVE-2025-53741
    Microsoft Office Excel CVE-2025-53759
    Microsoft Office SharePoint CVE-2025-53760
    Microsoft Office PowerPoint CVE-2025-53761
    Azure Stack CVE-2025-53765
    Windows GDI+ CVE-2025-53766
    Azure OpenAI CVE-2025-53767
    Windows Security App CVE-2025-53769
    Web Deploy CVE-2025-53772
    GitHub Copilot and Visual Studio CVE-2025-53773
    Microsoft 365 Copilot's Business Chat CVE-2025-53774
    Windows NTLM CVE-2025-53778
    Windows Kerberos CVE-2025-53779
    Azure Virtual Machines CVE-2025-53781
    Microsoft Teams CVE-2025-53783
    Microsoft Office Word CVE-2025-53784
    Microsoft Exchange Server CVE-2025-53786
    Microsoft 365 Copilot's Business Chat CVE-2025-53787
    Windows Subsystem for Linux CVE-2025-53788
    Windows StateRepository API CVE-2025-53789
    Azure Portal CVE-2025-53792
    Azure Stack CVE-2025-53793

    We are republishing 8 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?

    Chrome Microsoft Edge (Chromium-based) CVE-2025-8576

    Chrome Microsoft Edge (Chromium-based) CVE-2025-8577
    Chrome Microsoft Edge (Chromium-based) CVE-2025-8578
    Chrome Microsoft Edge (Chromium-based) CVE-2025-8579
    Chrome Microsoft Edge (Chromium-based) CVE-2025-8580
    Chrome Microsoft Edge (Chromium-based) CVE-2025-8581
    Chrome Microsoft Edge (Chromium-based) CVE-2025-8582
    Chrome Microsoft Edge (Chromium-based) CVE-2025-8583

    Security Update Guide Blog Posts
    Date Blog Post
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files

    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.

    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).


    KB Article Applies To
    5063888 Windows Server 2008 (Monthly Rollup)

    5063948 Windows Server 2008 (Security-only update)
    5002769 SharePoint Server 2019
    5050672 Exchange Server 2019 CU15
    5050673 Exchange Server 2019 CU14
    5050674 Exchange Server 2016 CU23
    Released: Aug 12, 2025
    August 2025 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  7. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

  8. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    September 2025 Security Updates

    This release consists of the following 86 Microsoft CVEs:

    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?
    SQL Server CVE-2025-47997

    Azure Windows Virtual Machine Agent CVE-2025-49692
    Windows PowerShell CVE-2025-49734
    Microsoft Edge (Chromium-based) CVE-2025-53791
    Windows Routing and Remote Access Service (RRAS) CVE-2025-53796
    Windows Routing and Remote Access Service (RRAS) CVE-2025-53797
    Windows Routing and Remote Access Service (RRAS) CVE-2025-53798
    Windows Imaging Component CVE-2025-53799
    Microsoft Graphics Component CVE-2025-53800
    Windows DWM CVE-2025-53801
    Windows Bluetooth Service CVE-2025-53802
    Windows Kernel CVE-2025-53803
    Windows Kernel CVE-2025-53804
    Windows Internet Information Services CVE-2025-53805
    Windows Routing and Remote Access Service (RRAS) CVE-2025-53806
    Microsoft Graphics Component CVE-2025-53807
    Windows Defender Firewall Service CVE-2025-53808
    Windows Local Security Authority Subsystem Service (LSASS) CVE-2025-53809
    Windows Defender Firewall Service CVE-2025-53810
    Role: Windows Hyper-V CVE-2025-54091
    Role: Windows Hyper-V CVE-2025-54092
    Windows TCP/IP CVE-2025-54093
    Windows Defender Firewall Service CVE-2025-54094
    Windows Routing and Remote Access Service (RRAS) CVE-2025-54095
    Windows Routing and Remote Access Service (RRAS) CVE-2025-54096
    Windows Routing and Remote Access Service (RRAS) CVE-2025-54097
    Role: Windows Hyper-V CVE-2025-54098
    Windows Ancillary Function Driver for WinSock CVE-2025-54099
    Windows SMBv3 Client CVE-2025-54101
    Windows Connected Devices Platform Service CVE-2025-54102
    Windows Management Services CVE-2025-54103
    Windows Defender Firewall Service CVE-2025-54104
    Microsoft Brokering File System CVE-2025-54105
    Windows Routing and Remote Access Service (RRAS) CVE-2025-54106
    Windows MapUrlToZone CVE-2025-54107
    Capability Access Management Service (camsvc) CVE-2025-54108
    Windows Defender Firewall Service CVE-2025-54109
    Windows Kernel CVE-2025-54110
    Windows UI XAML Phone DatePickerFlyout CVE-2025-54111
    Microsoft Virtual Hard Drive CVE-2025-54112
    Windows Routing and Remote Access Service (RRAS) CVE-2025-54113
    Windows Connected Devices Platform Service CVE-2025-54114
    Role: Windows Hyper-V CVE-2025-54115
    Windows MultiPoint Services CVE-2025-54116
    Windows Local Security Authority Subsystem Service (LSASS) CVE-2025-54894
    Windows SPNEGO Extended Negotiation CVE-2025-54895
    Microsoft Office Excel CVE-2025-54896
    Microsoft Office SharePoint CVE-2025-54897
    Microsoft Office Excel CVE-2025-54898
    Microsoft Office Excel CVE-2025-54899
    Microsoft Office Excel CVE-2025-54900
    Microsoft Office Excel CVE-2025-54901
    Microsoft Office Excel CVE-2025-54902
    Microsoft Office Excel CVE-2025-54903
    Microsoft Office Excel CVE-2025-54904
    Microsoft Office Word CVE-2025-54905
    Microsoft Office CVE-2025-54906
    Microsoft Office Visio CVE-2025-54907
    Microsoft Office PowerPoint CVE-2025-54908
    Microsoft Office CVE-2025-54910
    Windows BitLocker CVE-2025-54911
    Windows BitLocker CVE-2025-54912
    Windows UI XAML Maps MapControlSettings CVE-2025-54913
    Windows Defender Firewall Service CVE-2025-54915
    Windows NTFS CVE-2025-54916
    Windows MapUrlToZone CVE-2025-54917
    Windows NTLM CVE-2025-54918
    Windows Win32K - GRFX CVE-2025-54919
    Graphics Kernel CVE-2025-55223
    Windows Win32K - GRFX CVE-2025-55224
    Windows Routing and Remote Access Service (RRAS) CVE-2025-55225
    Graphics Kernel CVE-2025-55226
    SQL Server CVE-2025-55227
    Windows Win32K - GRFX CVE-2025-55228
    Microsoft High Performance Compute Pack (HPC) CVE-2025-55232
    Windows SMB CVE-2025-55234
    Graphics Kernel CVE-2025-55236
    Microsoft Office CVE-2025-55243
    Xbox CVE-2025-55245
    Azure Arc CVE-2025-55316
    Microsoft AutoUpdate (MAU) CVE-2025-55317

    We are republishing 5 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    VulnCheck SQL Server CVE-2024-21907

    Chrome Microsoft Edge (Chromium-based) CVE-2025-9864
    Chrome Microsoft Edge (Chromium-based) CVE-2025-9865
    Chrome Microsoft Edge (Chromium-based) CVE-2025-9866
    Chrome Microsoft Edge (Chromium-based) CVE-2025-9867

    Security Update Guide Blog Posts
    Date Blog Post
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files

    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.

    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).


    KB Article Applies To
    5065306 Windows Server 2022 Hotpatch

    5065426 Windows 11, version 24H2
    5065432 Windows Server 2022
    5065474 Windows Server 2025 Hotpatch
    5065508 Windows Server 2008 (Monthly Rollup)
    5065511 Windows Server 2008 (Security-only update)
    Released: Sep 9, 2025

    September 2025 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  9. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    October 2025 Security Updates

    This release consists of the following 175 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?

    Agere Windows Modem Driver CVE-2025-24052
    Agere Windows Modem Driver CVE-2025-24990
    Microsoft PowerShell CVE-2025-25004
    Windows Failover Cluster CVE-2025-47979
    Azure Connected Machine Agent CVE-2025-47989
    Microsoft Brokering File System CVE-2025-48004
    Virtual Secure Mode CVE-2025-48813
    Microsoft Graphics Component CVE-2025-49708
    Windows Kernel CVE-2025-50152
    Windows Device Association Broker service CVE-2025-50174
    Windows Digital Media CVE-2025-50175
    Windows Hello CVE-2025-53139
    Windows Digital Media CVE-2025-53150
    Windows Virtualization-Based Security (VBS) Enclave CVE-2025-53717

    Xbox CVE-2025-53768
    Microsoft Exchange Server CVE-2025-53782
    Visual Studio CVE-2025-55240
    .NET CVE-2025-55247 7.3
    .NET, .NET Framework, Visual Studio CVE-2025-55248
    ASP.NET Core CVE-2025-55315
    Microsoft Configuration Manager CVE-2025-55320
    Azure Monitor CVE-2025-55321
    Windows Storage Management Provider CVE-2025-55325
    Connected Devices Platform Service (Cdpsvc) CVE-2025-55326
    Windows Hyper-V CVE-2025-55328
    Windows BitLocker CVE-2025-55330
    Windows PrintWorkflowUserSvc CVE-2025-55331
    Windows BitLocker CVE-2025-55332
    Windows BitLocker CVE-2025-55333
    Windows Kernel CVE-2025-55334
    Windows NTFS CVE-2025-55335

    Windows Cloud Files Mini Filter Driver CVE-2025-55336
    Windows BitLocker CVE-2025-55337
    Windows BitLocker CVE-2025-55338
    Windows NDIS CVE-2025-55339
    Windows Remote Desktop Protocol CVE-2025-55340
    Windows USB Video Driver CVE-2025-55676
    Windows Device Association Broker service CVE-2025-55677
    Windows DirectX CVE-2025-55678
    Windows Kernel CVE-2025-55679
    Windows Cloud Files Mini Filter Driver CVE-2025-55680
    Windows DWM CVE-2025-55681
    Windows BitLocker CVE-2025-55682
    Windows Kernel CVE-2025-55683
    Windows PrintWorkflowUserSvc CVE-2025-55684
    Windows PrintWorkflowUserSvc CVE-2025-55685
    Windows PrintWorkflowUserSvc CVE-2025-55686
    Windows Resilient File System (ReFS) CVE-2025-55687
    Windows PrintWorkflowUserSvc CVE-2025-55688
    Windows PrintWorkflowUserSvc CVE-2025-55689
    Windows PrintWorkflowUserSvc CVE-2025-55690
    Windows PrintWorkflowUserSvc CVE-2025-55691
    Windows Error Reporting CVE-2025-55692
    Windows Kernel CVE-2025-55693
    Windows Error Reporting CVE-2025-55694
    Windows WLAN Auto Config Service CVE-2025-55695
    NtQueryInformation Token function (ntifs.h) CVE-2025-55696
    Azure Local CVE-2025-55697
    Windows DirectX CVE-2025-55698
    Windows Kernel CVE-2025-55699
    Windows Routing and Remote Access Service (RRAS) CVE-2025-55700
    Microsoft Windows CVE-2025-55701

    Windows Ancillary Function Driver for WinSock CVE-2025-58714
    Microsoft Windows Speech CVE-2025-58715
    Microsoft Windows Speech CVE-2025-58716
    Windows Routing and Remote Access Service (RRAS) CVE-2025-58717
    Remote Desktop Client CVE-2025-58718
    Connected Devices Platform Service (Cdpsvc) CVE-2025-58719
    Windows Cryptographic Services CVE-2025-58720
    Windows DWM CVE-2025-58722
    Azure Connected Machine Agent CVE-2025-58724
    Windows COM CVE-2025-58725
    Windows SMB Server CVE-2025-58726
    Windows Connected Devices Platform Service CVE-2025-58727
    Windows Bluetooth Service CVE-2025-58728
    Windows Local Session Manager (LSM) CVE-2025-58729
    Inbox COM Objects CVE-2025-58730
    Inbox COM Objects CVE-2025-58731
    Inbox COM Objects CVE-2025-58732
    Inbox COM Objects CVE-2025-58733
    Inbox COM Objects CVE-2025-58734
    Inbox COM Objects CVE-2025-58735
    Inbox COM Objects CVE-2025-58736

    Windows Remote Desktop CVE-2025-58737
    Inbox COM Objects CVE-2025-58738
    Windows File Explorer CVE-2025-58739
    Windows High Availability Services CVE-2025-59184
    Windows Core Shell CVE-2025-59185
    Windows Kernel CVE-2025-59186
    Windows Kernel CVE-2025-59187
    Windows Failover Cluster CVE-2025-59188
    Microsoft Brokering File System CVE-2025-59189
    Microsoft Windows Search Component CVE-2025-59190
    Connected Devices Platform Service (Cdpsvc) CVE-2025-59191
    Storport.sys Driver CVE-2025-59192
    Windows Management Services CVE-2025-59193
    Windows Kernel CVE-2025-59194
    Microsoft Graphics Component CVE-2025-59195
    Windows SSDP Service CVE-2025-59196
    Windows ETL Channel CVE-2025-59197

    Microsoft Windows Search Component CVE-2025-59198
    Software Protection Platform (SPP) CVE-2025-59199
    Data Sharing Service Client CVE-2025-59200
    Network Connection Status Indicator (NCSI) CVE-2025-59201
    Windows Remote Desktop Services CVE-2025-59202
    Windows StateRepository API CVE-2025-59203
    Windows Management Services CVE-2025-59204
    Microsoft Graphics Component CVE-2025-59205
    Windows Resilient File System (ReFS) Deduplication Service CVE-2025-59206
    Windows Kernel CVE-2025-59207
    Windows MapUrlToZone CVE-2025-59208
    Windows Push Notification Core CVE-2025-59209
    Windows Resilient File System (ReFS) Deduplication Service CVE-2025-59210
    Windows Push Notification Core CVE-2025-59211
    Microsoft Configuration Manager CVE-2025-59213
    Windows File Explorer CVE-2025-59214

    Azure Entra ID CVE-2025-59218
    Microsoft Office Word CVE-2025-59221
    Microsoft Office Word CVE-2025-59222
    Microsoft Office Excel CVE-2025-59223
    Microsoft Office Excel CVE-2025-59224
    Microsoft Office Excel CVE-2025-59225
    Microsoft Office Visio CVE-2025-59226
    Microsoft Office CVE-2025-59227
    Microsoft Office SharePoint CVE-2025-59228
    Microsoft Office CVE-2025-59229
    Windows Remote Access Connection Manager CVE-2025-59230
    Microsoft Office Excel CVE-2025-59231
    Microsoft Office Excel CVE-2025-59232
    Microsoft Office Excel CVE-2025-59233
    Microsoft Office CVE-2025-59234
    Microsoft Office Excel CVE-2025-59235
    Microsoft Office Excel CVE-2025-59236
    Microsoft Office SharePoint CVE-2025-59237
    Microsoft Office PowerPoint CVE-2025-59238

    Windows Health and Optimized Experiences Service CVE-2025-59241
    Windows Ancillary Function Driver for WinSock CVE-2025-59242
    Microsoft Office Excel CVE-2025-59243
    Windows Core Shell CVE-2025-59244
    Azure Entra ID CVE-2025-59246
    Azure PlayFab CVE-2025-59247
    Microsoft Exchange Server CVE-2025-59248
    Microsoft Exchange Server CVE-2025-59249
    JDBC Driver for SQL Server CVE-2025-59250
    Copilot CVE-2025-59252
    Microsoft Windows Search Component CVE-2025-59253
    Windows DWM Core Library CVE-2025-59254
    Windows DWM Core Library CVE-2025-59255
    Windows Local Session Manager (LSM) CVE-2025-59257
    Active Directory Federation Services CVE-2025-59258
    Windows Local Session Manager (LSM) CVE-2025-59259
    Microsoft Failover Cluster Virtual Driver CVE-2025-59260
    Microsoft Graphics Component CVE-2025-59261
    Redis Enterprise CVE-2025-59271
    Copilot CVE-2025-59272

    Windows Authentication Methods CVE-2025-59275
    Windows Authentication Methods CVE-2025-59277
    Windows Authentication Methods CVE-2025-59278
    Windows SMB Client CVE-2025-59280
    XBox Gaming Services CVE-2025-59281
    Inbox COM Objects CVE-2025-59282
    Windows NTLM CVE-2025-59284
    Azure Monitor Agent CVE-2025-59285
    Copilot CVE-2025-59286
    Windows Server Update Service CVE-2025-59287
    GitHub CVE-2025-59288
    Windows Bluetooth Service CVE-2025-59289
    Windows Bluetooth Service CVE-2025-59290
    Confidential Azure Container Instances CVE-2025-59291
    Confidential Azure Container Instances CVE-2025-59292
    Windows Taskbar Live CVE-2025-59294
    Internet Explorer CVE-2025-59295
    Azure Monitor Agent CVE-2025-59494
    Microsoft Defender for Linux CVE-2025-59497
    Windows Remote Procedure Call CVE-2025-59502


    We are republishing 21 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    MITRE Microsoft Graphics Component CVE-2016-9535
    AMD AMD Restricted Memory Page CVE-2025-0033
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11205
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11206
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11207
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11208
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11209
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11210
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11211
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11212
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11213
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11215
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11216
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11219
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11458
    Chrome Microsoft Edge (Chromium-based) CVE-2025-11460
    CERT/CC TCG TPM2.0 CVE-2025-2884
    MITRE Windows Secure Boot CVE-2025-47827
    GitHub Visual Studio CVE-2025-54132 No No No
    MITRE Microsoft Windows Codecs Library CVE-2025-54957
    MITRE Games CVE-2025-59489

    Security Update Guide Blog Posts
    Date Blog Post
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5066835 Windows 11, version 24H2, Windows 11, version 25H2
    5066874 Windows Server 2008 (Monthly Rollup)
    5066877 Windows Server 2008 (Security-only update)
    Released: Oct 14, 2025

    October 2025 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  10. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    November 2025 Security Updates

    This release consists of the following 63 Microsoft CVEs:


    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?

    Nuance PowerScribe CVE-2025-30398

    Microsoft Configuration Manager CVE-2025-47179
    Microsoft Office Excel CVE-2025-59240
    SQL Server CVE-2025-59499
    Azure Monitor Agent CVE-2025-59504
    Windows Smart Card CVE-2025-59505
    Windows DirectX CVE-2025-59506
    Windows Speech CVE-2025-59507
    Windows Speech CVE-2025-59508
    Windows Speech CVE-2025-59509
    Windows Routing and Remote Access Service (RRAS) CVE-2025-59510
    Windows WLAN Service CVE-2025-59511
    Customer Experience Improvement Program (CEIP) CVE-2025-59512
    Windows Bluetooth RFCOM Protocol Driver CVE-2025-59513
    Microsoft Streaming Service CVE-2025-59514
    Windows Broadcast DVR User Service CVE-2025-59515
    Windows Remote Desktop CVE-2025-60703
    Windows Kerberos CVE-2025-60704
    Windows Client-Side Caching (CSC) Service CVE-2025-60705
    Role: Windows Hyper-V CVE-2025-60706
    Multimedia Class Scheduler Service (MMCSS) CVE-2025-60707
    Storvsp.sys Driver CVE-2025-60708
    Windows Common Log File System Driver CVE-2025-60709
    Host Process for Windows Tasks CVE-2025-60710
    Windows Routing and Remote Access Service (RRAS) CVE-2025-60713
    Windows OLE CVE-2025-60714
    Windows Routing and Remote Access Service (RRAS) CVE-2025-60715
    Windows DirectX CVE-2025-60716
    Windows Broadcast DVR User Service CVE-2025-60717
    Windows Administrator Protection CVE-2025-60718
    Windows Ancillary Function Driver for WinSock CVE-2025-60719
    Windows TDX.sys CVE-2025-60720
    Windows Administrator Protection CVE-2025-60721
    OneDrive for Android CVE-2025-60722
    Windows DirectX CVE-2025-60723
    Microsoft Graphics Component CVE-2025-60724
    Microsoft Office Excel CVE-2025-60726
    Microsoft Office Excel CVE-2025-60727
    Microsoft Office Excel CVE-2025-60728
    Microsoft Office CVE-2025-62199
    Microsoft Office Excel CVE-2025-62200
    Microsoft Office Excel CVE-2025-62201
    Microsoft Office Excel CVE-2025-62202
    Microsoft Office Excel CVE-2025-62203
    Microsoft Office SharePoint CVE-2025-62204
    Microsoft Office Word CVE-2025-62205
    Microsoft Dynamics 365 (on-premises) CVE-2025-62206
    Windows License Manager CVE-2025-62208
    Windows License Manager CVE-2025-62209
    Dynamics 365 Field Service (online) CVE-2025-62210
    Dynamics 365 Field Service (online) CVE-2025-62211
    Windows Ancillary Function Driver for WinSock CVE-2025-62213
    Visual Studio CVE-2025-62214
    Windows Kernel CVE-2025-62215
    Microsoft Office CVE-2025-62216
    Windows Ancillary Function Driver for WinSock CVE-2025-62217
    Microsoft Wireless Provisioning System CVE-2025-62218
    Microsoft Wireless Provisioning System CVE-2025-62219
    Windows Subsystem for Linux GUI CVE-2025-62220
    Visual Studio Code CoPilot Chat Extension CVE-2025-62222
    Visual Studio Code CoPilot Chat Extension CVE-2025-62449
    Windows Routing and Remote Access Service (RRAS) CVE-2025-62452
    GitHub Copilot and Visual Studio Code CVE-2025-62453

    We are republishing 5 non-Microsoft CVEs:


    CNA Tag CVE FAQs? Workarounds? Mitigations?
    Chrome Microsoft Edge (Chromium-based) CVE-2025-12725

    Chrome Microsoft Edge (Chromium-based) CVE-2025-12726
    Chrome Microsoft Edge (Chromium-based) CVE-2025-12727
    Chrome Microsoft Edge (Chromium-based) CVE-2025-12728
    Chrome Microsoft Edge (Chromium-based) CVE-2025-12729

    Security Update Guide Blog Posts


    Date Blog Post
    October 31, 2025 You asked, we delivered: Introducing new features for an improved security experience

    October 28, 2025 Understanding CVE-2025-55315: What CISOs, security engineers, and sysadmins should know
    October 22, 2025 Toward greater transparency: Introducing machine-readable Vulnerability Exploitability Xchange (VEX) for Azure Linux and beyond
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.

    Known Issues


    KB Article Product
    5068779 Windows Server 2022, 23H2 Edition (Server Core installation)

    5068787 Windows Server 2022
    5068840 Windows Server 2022 Hotpatch
    5068906 Windows Server 2008 (Monthly Rollup)
    5068966 Windows Server 2025 Hotpatch
    5071726 Windows Server 2025
    5002800 SharePoint Server Subscription Edition
    5002803 SharePoint Server 2019
    5002805 SharePoint Server 2016


    Released: Nov 11, 2025

    November 2025 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  11. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Microsoft December 2025 Security Updates

    This release consists of the following 57 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?
    Windows PowerShell CVE-2025-54100

    Windows Projected File System CVE-2025-55233
    Windows Storage VSP Driver CVE-2025-59516
    Windows Storage VSP Driver CVE-2025-59517
    Windows Cloud Files Mini Filter Driver CVE-2025-62221
    Microsoft Edge for iOS CVE-2025-62223
    Windows Cloud Files Mini Filter Driver CVE-2025-62454
    Windows Message Queuing CVE-2025-62455
    Windows Resilient File System (ReFS) CVE-2025-62456
    Windows Cloud Files Mini Filter Driver CVE-2025-62457
    Windows Win32K - GRFX CVE-2025-62458
    Windows Projected File System Filter Driver CVE-2025-62461
    Windows Projected File System CVE-2025-62462
    Windows DirectX CVE-2025-62463
    Windows Projected File System CVE-2025-62464
    Windows DirectX CVE-2025-62465
    Windows Client-Side Caching (CSC) Service CVE-2025-62466
    Windows Projected File System CVE-2025-62467
    Windows Defender Firewall Service CVE-2025-62468
    Microsoft Brokering File System CVE-2025-62469
    Windows Common Log File System Driver CVE-2025-62470
    Windows Remote Access Connection Manager CVE-2025-62472
    Windows Routing and Remote Access Service (RRAS) CVE-2025-62473
    Windows Remote Access Connection Manager CVE-2025-62474
    Windows Routing and Remote Access Service (RRAS) CVE-2025-62549
    Azure Monitor Agent CVE-2025-62550
    Microsoft Office Access CVE-2025-62552
    Microsoft Office Excel CVE-2025-62553
    Microsoft Office CVE-2025-62554
    Microsoft Office Word CVE-2025-62555
    Microsoft Office Excel CVE-2025-62556
    Microsoft Office CVE-2025-62557
    Microsoft Office Word CVE-2025-62558
    Microsoft Office Word CVE-2025-62559
    Microsoft Office Excel CVE-2025-62560
    Microsoft Office Excel CVE-2025-62561
    Microsoft Office Outlook CVE-2025-62562
    Microsoft Office Excel CVE-2025-62563
    Microsoft Office Excel CVE-2025-62564
    Windows Shell CVE-2025-62565
    Windows Hyper-V CVE-2025-62567
    Microsoft Brokering File System CVE-2025-62569
    Windows Camera Frame Server Monitor CVE-2025-62570
    Windows Installer CVE-2025-62571
    Application Information Services CVE-2025-62572
    Windows DirectX CVE-2025-62573
    Windows Shell CVE-2025-64658
    Windows Shell CVE-2025-64661
    Microsoft Exchange Server CVE-2025-64666
    Microsoft Exchange Server CVE-2025-64667
    Microsoft Graphics Component CVE-2025-64670
    Copilot CVE-2025-64671
    Microsoft Office SharePoint CVE-2025-64672
    Storvsp.sys Driver CVE-2025-64673
    Windows Routing and Remote Access Service (RRAS) CVE-2025-64678
    Windows DWM Core Library CVE-2025-64679
    Windows DWM Core Library CVE-2025-64680

    We are republishing 13 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    Chrome Microsoft Edge (Chromium-based) CVE-2025-13630

    Chrome Microsoft Edge (Chromium-based) CVE-2025-13631
    Chrome Microsoft Edge (Chromium-based) CVE-2025-13632
    Chrome Microsoft Edge (Chromium-based) CVE-2025-13633
    Chrome Microsoft Edge (Chromium-based) CVE-2025-13634
    Chrome Microsoft Edge (Chromium-based) CVE-2025-13635
    Chrome Microsoft Edge (Chromium-based) CVE-2025-13636
    Chrome Microsoft Edge (Chromium-based) CVE-2025-13637
    Chrome Microsoft Edge (Chromium-based) CVE-2025-13638
    Chrome Microsoft Edge (Chromium-based) CVE-2025-13639
    Chrome Microsoft Edge (Chromium-based) CVE-2025-13640
    Chrome Microsoft Edge (Chromium-based) CVE-2025-13720
    Chrome Microsoft Edge (Chromium-based) CVE-2025-13721

    Security Update Guide Blog Posts
    Date Blog Post
    October 31, 2025 You asked, we delivered: Introducing new features for an improved security experience

    October 28, 2025 Understanding CVE-2025-55315: What CISOs, security engineers, and sysadmins should know
    October 22, 2025 Toward greater transparency: Introducing machine-readable Vulnerability Exploitability Xchange (VEX) for Azure Linux and beyond
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide
    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.

    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).


    KB Article Applies To
    5071413 Windows Server 2022 Hotpatch

    5072014 Windows Server 2025 Hotpatch
    5071504 Windows Server 2008 (Monthly Rollup)
    5071507 Windows Server 2008 (Security-only update)
    5071542 Windows Server 23H2
    5071547 Windows Server 2022
    5072033 Windows 11, version 24H2, Windows 11, version 25H2, Server 2025
    Released: Dec 9, 2025

    December 2025 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  12. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    January 2026 Security Updates

    This release consists of the following 112 Microsoft CVEs:

    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?
    Windows Deployment Services CVE-2026-0386
    SQL Server CVE-2026-20803
    Windows Hello CVE-2026-20804 7.7
    Desktop Window Manager CVE-2026-20805
    Printer Association Object CVE-2026-20808
    Windows Kernel Memory CVE-2026-20809
    Windows Ancillary Function Driver for WinSock CVE-2026-20810
    Windows Win32K - ICOMP CVE-2026-20811
    Windows LDAP - Lightweight Directory Access Protocol CVE-2026-20812
    Graphics Kernel CVE-2026-20814
    Capability Access Management Service (camsvc) CVE-2026-20815
    Windows Installer CVE-2026-20816
    Windows Error Reporting CVE-2026-20817
    Windows Kernel CVE-2026-20818
    Windows Virtualization-Based Security (VBS) Enclave CVE-2026-20819
    Windows Common Log File System Driver CVE-2026-20820
    Windows Remote Procedure Call CVE-2026-20821
    Microsoft Graphics Component CVE-2026-20822
    Windows File Explorer CVE-2026-20823
    Windows Remote Assistance CVE-2026-20824
    Windows Hyper-V CVE-2026-20825
    Tablet Windows User Interface (TWINUI) Subsystem CVE-2026-20826
    Tablet Windows User Interface (TWINUI) Subsystem CVE-2026-20827
    Windows Internet Connection Sharing (ICS) CVE-2026-20828
    Windows TPM CVE-2026-20829
    Capability Access Management Service (camsvc) CVE-2026-20830
    Windows Ancillary Function Driver for WinSock CVE-2026-20831
    Windows Remote Procedure Call Interface Definition Language (IDL) CVE-2026-20832
    Windows Kerberos CVE-2026-20833
    Windows Shell CVE-2026-20834
    Capability Access Management Service (camsvc) CVE-2026-20835
    Graphics Kernel CVE-2026-20836
    Windows Media CVE-2026-20837
    Windows Kernel CVE-2026-20838 5.5
    Windows Client-Side Caching (CSC) Service CVE-2026-20839
    Windows NTFS CVE-2026-20840
    Windows DWM CVE-2026-20842
    Windows Routing and Remote Access Service (RRAS) CVE-2026-20843
    Windows Clipboard Server CVE-2026-20844
    Windows Shell CVE-2026-20847
    Windows SMB Server CVE-2026-20848
    Windows Kerberos CVE-2026-20849
    Capability Access Management Service (camsvc) CVE-2026-20851
    Windows Hello CVE-2026-20852
    Windows WalletService CVE-2026-20853
    Windows Local Security Authority Subsystem Service (LSASS) CVE-2026-20854
    Windows Server Update Service CVE-2026-20856
    Windows Cloud Files Mini Filter Driver CVE-2026-20857
    Windows Management Services CVE-2026-20858
    Windows Kernel-Mode Drivers CVE-2026-20859
    Windows Ancillary Function Driver for WinSock CVE-2026-20860
    Windows Management Services CVE-2026-20861
    Windows Management Services CVE-2026-20862
    Windows Win32K - ICOMP CVE-2026-20863
    Connected Devices Platform Service (Cdpsvc) CVE-2026-20864
    Windows Management Services CVE-2026-20865
    Windows Management Services CVE-2026-20866
    Windows Management Services CVE-2026-20867
    Windows Routing and Remote Access Service (RRAS) CVE-2026-20868
    Windows Local Session Manager (LSM) CVE-2026-20869
    Windows Win32K - ICOMP CVE-2026-20870
    Desktop Window Manager CVE-2026-20871
    Windows NTLM CVE-2026-20872


    Windows Management Services CVE-2026-20873
    Windows Management Services CVE-2026-20874
    Windows Local Security Authority Subsystem Service (LSASS) CVE-2026-20875
    Windows Virtualization-Based Security (VBS) Enclave CVE-2026-20876
    Windows Management Services CVE-2026-20877
    Windows Management Services CVE-2026-20918
    Windows SMB Server CVE-2026-20919
    Windows Win32K - ICOMP CVE-2026-20920
    Windows SMB Server CVE-2026-20921
    Windows NTFS CVE-2026-20922
    Windows Management Services CVE-2026-20923
    Windows Management Services CVE-2026-20924
    Windows NTLM CVE-2026-20925
    Windows SMB Server CVE-2026-20926
    Windows SMB Server CVE-2026-20927
    Windows HTTP.sys CVE-2026-20929
    Windows Telephony Service CVE-2026-20931
    Windows File Explorer CVE-2026-20932
    Windows SMB Server CVE-2026-20934
    Windows Virtualization-Based Security (VBS) Enclave CVE-2026-20935
    Windows NDIS CVE-2026-20936
    Windows File Explorer CVE-2026-20937
    Windows Virtualization-Based Security (VBS) Enclave CVE-2026-20938
    Windows File Explorer CVE-2026-20939
    Windows Cloud Files Mini Filter Driver CVE-2026-20940
    Host Process for Windows Tasks CVE-2026-20941
    Microsoft Office CVE-2026-20943
    Microsoft Office Word CVE-2026-20944
    Microsoft Office Excel CVE-2026-20946
    Microsoft Office SharePoint CVE-2026-20947
    Microsoft Office Word CVE-2026-20948
    Microsoft Office Excel CVE-2026-20949
    Microsoft Office Excel CVE-2026-20950
    Microsoft Office SharePoint CVE-2026-20951
    Microsoft Office CVE-2026-20952
    Microsoft Office CVE-2026-20953
    Microsoft Office Excel CVE-2026-20955
    Microsoft Office Excel CVE-2026-20956
    Microsoft Office Excel CVE-2026-20957
    Microsoft Office SharePoint CVE-2026-20958
    Microsoft Office SharePoint CVE-2026-20959
    Dynamic Root of Trust for Measurement (DRTM) CVE-2026-20962
    Microsoft Office SharePoint CVE-2026-20963
    Windows Admin Center CVE-2026-20965
    Inbox COM Objects CVE-2026-21219
    Capability Access Management Service (camsvc) CVE-2026-21221
    Azure Connected Machine Agent CVE-2026-21224
    Azure Core shared client library for Python CVE-2026-21226
    Windows Secure Boot CVE-2026-21265

    We are republishing 3 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    MITRE Corporation Agere Windows Modem Driver CVE-2023-31096
    MITRE Corporation Windows Motorola Soft Modem Driver CVE-2024-55414
    Chrome Microsoft Edge (Chromium-based) CVE-2026-0628

    Security Update Guide Blog Posts
    Date Blog Post
    October 31, 2025 You asked, we delivered: Introducing new features for an improved security experience
    October 28, 2025 Understanding CVE-2025-55315: What CISOs, security engineers, and sysadmins should know
    October 22, 2025 Toward greater transparency: Introducing machine-readable Vulnerability Exploitability Xchange (VEX) for Azure Linux and beyond
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5073379 Windows Server 2025
    5073450 Windows Server 23H2
    5073457 Windows Server 2022
    5074109 Windows 11, version 24H2, Windows 11, version 25H2
    Released: Jan 13, 2026

    January 2026 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  13. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    February 2026 Security Updates



    This release consists of the following 59 Microsoft CVEs:


    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?
    Windows Win32K - GRFX CVE-2023-2804

    Microsoft Edge for Android CVE-2026-0391
    Windows Notepad App CVE-2026-20841
    Windows GDI+ CVE-2026-20846 7.5
    .NET and Visual Studio CVE-2026-21218
    Windows Kernel CVE-2026-21222
    Azure Local CVE-2026-21228
    Power BI CVE-2026-21229
    Windows Kernel CVE-2026-21231
    Windows HTTP.sys CVE-2026-21232
    Windows Connected Devices Platform Service CVE-2026-21234
    Microsoft Graphics Component CVE-2026-21235
    Windows Ancillary Function Driver for WinSock CVE-2026-21236
    Windows Subsystem for Linux CVE-2026-21237
    Windows Ancillary Function Driver for WinSock CVE-2026-21238
    Windows Kernel CVE-2026-21239
    Windows HTTP.sys CVE-2026-21240
    Windows Ancillary Function Driver for WinSock CVE-2026-21241
    Windows Subsystem for Linux CVE-2026-21242
    Windows LDAP - Lightweight Directory Access Protocol CVE-2026-21243
    Role: Windows Hyper-V CVE-2026-21244
    Windows Kernel CVE-2026-21245
    Microsoft Graphics Component CVE-2026-21246
    Role: Windows Hyper-V CVE-2026-21247
    Role: Windows Hyper-V CVE-2026-21248
    Windows NTLM CVE-2026-21249
    Windows HTTP.sys CVE-2026-21250
    Windows Cluster Client Failover CVE-2026-21251
    Mailslot File System CVE-2026-21253
    Role: Windows Hyper-V CVE-2026-21255
    GitHub Copilot and Visual Studio CVE-2026-21256
    GitHub Copilot and Visual Studio CVE-2026-21257
    Microsoft Office Excel CVE-2026-21258
    Microsoft Office Excel CVE-2026-21259
    Microsoft Office Word CVE-2026-21260
    Microsoft Office Excel CVE-2026-21261
    Windows Storage CVE-2026-21508
    Windows Shell CVE-2026-21510
    Microsoft Office Outlook CVE-2026-21511
    Azure DevOps Server CVE-2026-21512
    Internet Explorer CVE-2026-21513
    Microsoft Office Word CVE-2026-21514
    Github Copilot CVE-2026-21516
    Windows App for Mac CVE-2026-21517
    .NET CVE-2026-21518
    Desktop Window Manager CVE-2026-21519
    Azure Compute Gallery CVE-2026-21522
    GitHub Copilot and Visual Studio CVE-2026-21523
    Windows Remote Access Connection Manager CVE-2026-21525
    Microsoft Exchange Server CVE-2026-21527
    Azure IoT SDK CVE-2026-21528
    Azure HDInsights CVE-2026-21529
    Azure SDK CVE-2026-21531
    Azure Function CVE-2026-21532
    Windows Remote Desktop CVE-2026-21533
    Microsoft Defender for Linux CVE-2026-21537
    Azure Compute Gallery CVE-2026-23655
    Azure Front Door (AFD) CVE-2026-24300
    Azure Arc CVE-2026-24302

    We are republishing 1 non-Microsoft CVEs:


    CNA Tag CVE FAQs? Workarounds? Mitigations?
    Chrome Microsoft Edge (Chromium-based) CVE-2026-1861 Yes No No


    Security Update Guide Blog Posts


    Date Blog Post
    October 31, 2025 You asked, we delivered: Introducing new features for an improved security experience

    October 28, 2025 Understanding CVE-2025-55315: What CISOs, security engineers, and sysadmins should know
    October 22, 2025 Toward greater transparency: Introducing machine-readable Vulnerability Exploitability Xchange (VEX) for Azure Linux and beyond
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.

    Known Issues


    KB Article Product
    5075942 Windows Server 2025 Hotpatch

    5075897 Windows Server 23H2
    5075899 Windows Server 2025
    5075906 Windows Server 2022

    Released: Feb 10, 2026

    February 2026 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  14. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    March 2026 Security Updates



    This release consists of the following 83 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?

    System Center Operations Manager CVE-2026-20967
    SQL Server CVE-2026-21262
    Microsoft Devices Pricing Program CVE-2026-21536
    Azure Compute Gallery CVE-2026-23651
    GitHub Repo: zero-shot-scfoundation CVE-2026-23654
    Windows App Installer CVE-2026-23656
    Azure Portal Windows Admin Center CVE-2026-23660
    Azure IoT Explorer CVE-2026-23661
    Azure IoT Explorer CVE-2026-23662
    Azure IoT Explorer CVE-2026-23664
    Azure Linux Virtual Machines CVE-2026-23665
    Broadcast DVR CVE-2026-23667
    Microsoft Graphics Component CVE-2026-23668
    Windows Print Spooler Components CVE-2026-23669
    Windows Bluetooth RFCOM Protocol Driver CVE-2026-23671
    Windows Universal Disk Format File System Driver (UDFS) CVE-2026-23672
    Windows Resilient File System (ReFS) CVE-2026-23673
    Windows MapUrlToZone CVE-2026-23674
    Push Message Routing Service CVE-2026-24282
    Windows File Server CVE-2026-24283
    Windows Win32K CVE-2026-24285
    Windows Kernel CVE-2026-24287
    Windows Mobile Broadband CVE-2026-24288
    Windows Kernel CVE-2026-24289
    Windows Projected File System CVE-2026-24290
    Windows Accessibility Infrastructure (ATBroker.exe) CVE-2026-24291
    Connected Devices Platform Service (Cdpsvc) CVE-2026-24292
    Windows Ancillary Function Driver for WinSock CVE-2026-24293
    Windows SMB Server CVE-2026-24294
    Windows Device Association Service CVE-2026-24295
    Windows Device Association Service CVE-2026-24296
    Windows Kerberos CVE-2026-24297
    Windows Performance Counters CVE-2026-25165
    Windows System Image Manager CVE-2026-25166
    Microsoft Brokering File System CVE-2026-25167
    Microsoft Graphics Component CVE-2026-25168
    Microsoft Graphics Component CVE-2026-25169
    Role: Windows Hyper-V CVE-2026-25170
    Windows Authentication Methods CVE-2026-25171
    Windows Routing and Remote Access Service (RRAS) CVE-2026-25172
    Windows Routing and Remote Access Service (RRAS) CVE-2026-25173
    Windows Extensible File Allocation CVE-2026-25174
    Windows NTFS CVE-2026-25175
    Windows Ancillary Function Driver for WinSock CVE-2026-25176
    Active Directory Domain Services CVE-2026-25177
    Windows Ancillary Function Driver for WinSock CVE-2026-25178
    Windows Ancillary Function Driver for WinSock CVE-2026-25179
    Microsoft Graphics Component CVE-2026-25180
    Windows GDI+ CVE-2026-25181
    Windows Shell Link Processing CVE-2026-25185
    Windows Accessibility Infrastructure (ATBroker.exe) CVE-2026-25186
    Winlogon CVE-2026-25187 7
    Windows Telephony Service CVE-2026-25188
    Windows DWM Core Library CVE-2026-25189
    Windows GDI CVE-2026-25190
    Microsoft Office SharePoint CVE-2026-26105
    Microsoft Office SharePoint CVE-2026-26106
    Microsoft Office Excel CVE-2026-26107
    Microsoft Office Excel CVE-2026-26108
    Microsoft Office Excel CVE-2026-26109
    Microsoft Office CVE-2026-26110
    Windows Routing and Remote Access Service (RRAS) CVE-2026-26111
    Microsoft Office Excel CVE-2026-26112
    Microsoft Office CVE-2026-26113
    Microsoft Office SharePoint CVE-2026-26114
    SQL Server CVE-2026-26115
    SQL Server CVE-2026-26116
    Azure Windows Virtual Machine Agent CVE-2026-26117
    Azure MCP Server CVE-2026-26118
    Azure IoT Explorer CVE-2026-26121
    Azure Compute Gallery CVE-2026-26122
    Microsoft Authenticator CVE-2026-26123
    Azure Compute Gallery CVE-2026-26124 Payment Orchestrator Service CVE-2026-26125

    .NET CVE-2026-26127
    Windows SMB Server CVE-2026-26128
    ASP.NET Core CVE-2026-26130
    .NET CVE-2026-26131
    Windows Kernel CVE-2026-26132
    Microsoft Office CVE-2026-26134
    Azure Arc CVE-2026-26141
    Microsoft Office Excel CVE-2026-26144


    We are republishing 10 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    GitHub Microsoft Semantic Kernel Python SDK CVE-2026-26030
    Chrome Microsoft Edge (Chromium-based) CVE-2026-3536
    Chrome Microsoft Edge (Chromium-based) CVE-2026-3538
    Chrome Microsoft Edge (Chromium-based) CVE-2026-3539
    Chrome Microsoft Edge (Chromium-based) CVE-2026-3540
    Chrome Microsoft Edge (Chromium-based) CVE-2026-3541
    Chrome Microsoft Edge (Chromium-based) CVE-2026-3542
    Chrome Microsoft Edge (Chromium-based) CVE-2026-3543
    Chrome Microsoft Edge (Chromium-based) CVE-2026-3544
    Chrome Microsoft Edge (Chromium-based) CVE-2026-3545

    Security Update Guide Blog Posts
    Date Blog Post
    October 31, 2025 You asked, we delivered: Introducing new features for an improved security experience
    October 28, 2025 Understanding CVE-2025-55315: What CISOs, security engineers, and sysadmins should know
    October 22, 2025 Toward greater transparency: Introducing machine-readable Vulnerability Exploitability Xchange (VEX) for Azure Linux and beyond
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources



      • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
      • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
      • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
      • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    .


    Released: Mar 10, 2026
    March 2026 Security Updates - Release Notes - Security Update Guide - Microsoft
     
    Last edited: Mar 11, 2026

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds