Microsoft Security Bulletin Re-Releases/Advisories

Discussion in 'Virus Software Updates (Read Only)' started by NICK ADSL UK, Jun 19, 2008.

  1. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    March 2025 Security Updates
    This release consists of the following 57 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?

    Windows exFAT File System CVE-2025-21180
    Azure Agent Installer CVE-2025-21199
    Windows MapUrlToZone CVE-2025-21247
    Windows Remote Desktop Services CVE-2025-24035
    .NET CVE-2025-24043
    Windows Win32 Kernel Subsystem CVE-2025-24044
    Windows Remote Desktop Services CVE-2025-24045
    Microsoft Streaming Service CVE-2025-24046
    Role: Windows Hyper-V CVE-2025-24048
    Azure CLI CVE-2025-24049
    Role: Windows Hyper-V CVE-2025-24050
    Windows Routing and Remote Access Service (RRAS) CVE-2025-24051
    Windows NTLM CVE-2025-24054
    Windows USB Video Driver CVE-2025-24055
    Windows Telephony Server CVE-2025-24056
    Microsoft Office CVE-2025-24057
    Windows Common Log File System Driver CVE-2025-24059
    Windows Mark of the Web (MOTW) CVE-2025-24061
    Role: DNS Server CVE-2025-24064
    Windows Kernel-Mode Drivers CVE-2025-24066
    Microsoft Streaming Service CVE-2025-24067
    ASP.NET Core & Visual Studio CVE-2025-24070
    Windows File Explorer CVE-2025-24071
    Microsoft Local Security Authority Server (lsasrv) CVE-2025-24072
    Microsoft Office Excel CVE-2025-24075
    Windows Cross Device Service CVE-2025-24076
    Microsoft Office Word CVE-2025-24077
    Microsoft Office Word CVE-2025-24078
    Microsoft Office Word CVE-2025-24079
    Microsoft Office CVE-2025-24080
    Microsoft Office Excel CVE-2025-24081
    Microsoft Office Excel CVE-2025-24082
    Microsoft Office CVE-2025-24083
    Windows Subsystem for Linux CVE-2025-24084
    Windows Win32 Kernel Subsystem CVE-2025-24983
    Windows NTFS CVE-2025-24984
    Windows Fast FAT Driver CVE-2025-24985
    Azure PromptFlow CVE-2025-24986
    Windows USB Video Driver CVE-2025-24987
    Windows USB Video Driver CVE-2025-24988
    Windows NTFS CVE-2025-24991
    Windows NTFS CVE-2025-24992
    Windows NTFS CVE-2025-24993
    Windows Cross Device Service CVE-2025-24994
    Kernel Streaming WOW Thunk Service Driver CVE-2025-24995
    Windows NTLM CVE-2025-24996
    Windows Kernel Memory CVE-2025-24997
    Visual Studio CVE-2025-24998
    Visual Studio CVE-2025-25003
    Microsoft Windows CVE-2025-25008
    Azure Arc CVE-2025-26627
    Microsoft Office CVE-2025-26629
    Microsoft Office Access CVE-2025-26630
    Visual Studio Code CVE-2025-26631
    Microsoft Management Console CVE-2025-26633
    Microsoft Edge (Chromium-based) CVE-2025-26643
    Remote Desktop Client CVE-2025-26645

    We are republishing 10 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    Synaptics, Inc. Microsoft Windows CVE-2024-9157 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1914 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1915 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1916 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1917 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1918 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1919 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1921 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1922 Yes No No
    Chrome Microsoft Edge (Chromium-based) CVE-2025-1923 Yes No No

    Security Update Guide Blog Posts
    Date Blog Post
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5053596 Windows 10, version 1809, Windows Server 2019
    5053598 Windows 11, version 24H2
    5053599 Windows Server 2022, 23H2 Edition (Server Core installation)
    5053602 Windows 11, version 22H2, Windows 11, version 23H2
    5053606 Windows 10, version 21H2, Windows 10, version 22H2
    5053888 Windows Server 2008 (Monthly Rollup)
    5053995 Windows Server 2008 (Security-only update)

    Released: Mar 11, 2025
    March 2025 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  2. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    April 2025 Security Updates
    This release consists of the following 126 Microsoft CVEs:

    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?
    Visual Studio Code CVE-2025-20570
    Windows Standards-Based Storage Management Service CVE-2025-21174
    Windows Local Security Authority (LSA) CVE-2025-21191
    Windows NTFS CVE-2025-21197
    Windows Routing and Remote Access Service (RRAS) CVE-2025-21203
    Windows Update Stack CVE-2025-21204
    Windows Telephony Service CVE-2025-21205
    Windows Telephony Service CVE-2025-21221
    Windows Telephony Service CVE-2025-21222
    Windows DWM Core Library CVE-2025-24058
    Windows DWM Core Library CVE-2025-24060
    Windows DWM Core Library CVE-2025-24062
    Windows DWM Core Library CVE-2025-24073
    Windows DWM Core Library CVE-2025-24074
    Microsoft Edge (Chromium-based) CVE-2025-25000
    Microsoft Edge (Chromium-based) CVE-2025-25001
    Azure Local Cluster CVE-2025-25002
    Azure Local Cluster CVE-2025-26628
    Windows Hello CVE-2025-26635
    Windows BitLocker CVE-2025-26637
    Windows USB Print Driver CVE-2025-26639
    Windows Digital Media CVE-2025-26640
    Windows Cryptographic Services CVE-2025-26641
    Microsoft Office CVE-2025-26642
    Windows Hello CVE-2025-26644
    Windows Kerberos CVE-2025-26647
    Windows Kernel CVE-2025-26648
    Windows Secure Channel CVE-2025-26649
    Windows Local Session Manager (LSM) CVE-2025-26651
    Windows Standards-Based Storage Management Service CVE-2025-26652
    Windows LDAP - Lightweight Directory Access Protocol CVE-2025-26663
    Windows Routing and Remote Access Service (RRAS) CVE-2025-26664
    Windows upnphost.dll CVE-2025-26665
    Windows Media CVE-2025-26666
    Windows Routing and Remote Access Service (RRAS) CVE-2025-26667
    Windows Routing and Remote Access Service (RRAS) CVE-2025-26668
    Windows Routing and Remote Access Service (RRAS) CVE-2025-26669
    Windows LDAP - Lightweight Directory Access Protocol CVE-2025-26670
    Windows Remote Desktop Services CVE-2025-26671
    Windows Routing and Remote Access Service (RRAS) CVE-2025-26672
    Windows LDAP - Lightweight Directory Access Protocol CVE-2025-26673
    Windows Media CVE-2025-26674
    Windows Subsystem for Linux CVE-2025-26675
    Windows Routing and Remote Access Service (RRAS) CVE-2025-26676
    Windows Defender Application Control (WDAC) CVE-2025-26678
    RPC Endpoint Mapper Service CVE-2025-26679
    Windows Standards-Based Storage Management Service CVE-2025-26680
    Windows Win32K - GRFX CVE-2025-26681
    ASP.NET Core CVE-2025-26682
    Windows TCP/IP CVE-2025-26686
    Windows Win32K - GRFX CVE-2025-26687
    Microsoft Virtual Hard Drive CVE-2025-26688
    Windows Digital Media CVE-2025-27467
    Windows LDAP - Lightweight Directory Access Protocol CVE-2025-27469
    Windows Standards-Based Storage Management Service CVE-2025-27470
    Microsoft Streaming Service CVE-2025-27471
    Windows Mark of the Web (MOTW) CVE-2025-27472
    Windows HTTP.sys CVE-2025-27473
    Windows Routing and Remote Access Service (RRAS) CVE-2025-27474
    Windows Update Stack CVE-2025-27475
    Windows Digital Media CVE-2025-27476
    Windows Telephony Service CVE-2025-27477
    Windows Local Security Authority (LSA) CVE-2025-27478
    Windows Kerberos CVE-2025-27479
    Remote Desktop Gateway Service CVE-2025-27480
    Windows Telephony Service CVE-2025-27481
    Remote Desktop Gateway Service CVE-2025-27482
    Windows NTFS CVE-2025-27483
    Windows Universal Plug and Play (UPnP) Device Host CVE-2025-27484
    Windows Standards-Based Storage Management Service CVE-2025-27485
    Windows Standards-Based Storage Management Service CVE-2025-27486
    Remote Desktop Client CVE-2025-27487
    Azure Local CVE-2025-27489
    Windows Bluetooth Service CVE-2025-27490
    Windows Hyper-V CVE-2025-27491
    Windows Secure Channel CVE-2025-27492
    Windows Installer CVE-2025-27727
    Windows Kernel-Mode Drivers CVE-2025-27728
    Windows Shell CVE-2025-27729
    Windows Digital Media CVE-2025-27730
    OpenSSH for Windows CVE-2025-27731
    Windows Win32K - GRFX CVE-2025-27732
    Windows NTFS CVE-2025-27733
    Windows Virtualization-Based Security (VBS) Enclave CVE-2025-27735
    Windows Power Dependency Coordinator CVE-2025-27736
    Windows Security Zone Mapping CVE-2025-27737
    Windows Resilient File System (ReFS) CVE-2025-27738
    Windows Kernel CVE-2025-27739
    Windows Active Directory Certificate Services CVE-2025-27740
    Windows NTFS CVE-2025-27741
    Windows NTFS CVE-2025-27742
    System Center CVE-2025-27743
    Microsoft Office CVE-2025-27744
    Microsoft Office CVE-2025-27745
    Microsoft Office CVE-2025-27746
    Microsoft Office Word CVE-2025-27747
    Microsoft Office CVE-2025-27748
    Microsoft Office CVE-2025-27749
    Microsoft Office Excel CVE-2025-27750
    Microsoft Office Excel CVE-2025-27751
    Microsoft Office Excel CVE-2025-27752
    Microsoft Office CVE-2025-29791
    Microsoft Office CVE-2025-29792
    Microsoft Office SharePoint CVE-2025-29793
    Microsoft Office SharePoint CVE-2025-29794
    Microsoft Edge for iOS CVE-2025-29796
    Microsoft AutoUpdate (MAU) CVE-2025-29800
    Microsoft AutoUpdate (MAU) CVE-2025-29801
    Visual Studio CVE-2025-29802
    Visual Studio Tools for Applications and SQL Server Management Studio CVE-2025-29803
    Visual Studio CVE-2025-29804
    Outlook for Android CVE-2025-29805
    Windows Cryptographic Services CVE-2025-29808
    Windows Kerberos CVE-2025-29809
    Active Directory Domain Services CVE-2025-29810
    Windows Mobile Broadband CVE-2025-29811
    Windows Kernel Memory CVE-2025-29812
    Microsoft Edge (Chromium-based) CVE-2025-29815
    Microsoft Office Word CVE-2025-29816
    Power Automate CVE-2025-29817
    Azure Portal Windows Admin Center CVE-2025-29819
    Microsoft Office Word CVE-2025-29820
    Dynamics Business Central CVE-2025-29821
    Microsoft Office OneNote CVE-2025-29822
    Microsoft Office Excel CVE-2025-29823
    Windows Common Log File System Driver CVE-2025-29824

    We are republishing 9 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3066
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3067
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3068
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3069
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3070
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3071
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3072
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3073
    Chrome Microsoft Edge (Chromium-based) CVE-2025-3074

    Security Update Guide Blog Posts
    Date Blog Post
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5055518 Windows 10, version 21H2, Windows 10, version 22H2
    5055519 Windows 10, version 1809, Windows Server 2019
    5055523 Windows 11, version 24H2
    5055526 Windows Server 2022
    5055527 Windows Server 2022, 23H2 Edition (Server Core installation)
    5055528 Windows 11, version 22H2, Windows 11, version 23H2
    5055596 Windows Server 2008 (Security-only update)
    5055609 Windows Server 2008 (Monthly Rollup)
    Released: Apr 8, 2025
    April 2025 Security Updates - Release Notes - Security Update Guide - Microsoft
     
  3. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    May 2025 Security Updates
    This release consists of the following 78 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?

    Visual Studio Code CVE-2025-21264
    Windows Kernel CVE-2025-24063
    .NET, Visual Studio, and Build Tools for Visual Studio CVE-2025-26646
    Remote Desktop Gateway Service CVE-2025-26677
    Microsoft Defender for Endpoint CVE-2025-26684
    Microsoft Defender for Identity CVE-2025-26685
    Windows Secure Kernel Mode CVE-2025-27468
    Windows Hardware Lab Kit CVE-2025-27488
    Azure DevOps CVE-2025-29813
    Microsoft Edge (Chromium-based) CVE-2025-29825
    Microsoft Dataverse CVE-2025-29826
    Azure Automation CVE-2025-29827
    Windows Trusted Runtime Interface Driver CVE-2025-29829
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29830
    Remote Desktop Gateway Service CVE-2025-29831
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29832
    Windows Virtual Machine Bus CVE-2025-29833
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29835
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29836
    Windows Installer CVE-2025-29837
    Windows Drivers CVE-2025-29838
    Windows File Server CVE-2025-29839
    Windows Media CVE-2025-29840
    Universal Print Management Service CVE-2025-29841
    UrlMon CVE-2025-29842
    Windows LDAP - Lightweight Directory Access Protocol CVE-2025-29954
    Role: Windows Hyper-V CVE-2025-29955
    Windows SMB CVE-2025-29956
    Windows Deployment Services CVE-2025-29957
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29958
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29959
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29960
    Windows Routing and Remote Access Service (RRAS) CVE-2025-29961
    Windows Media CVE-2025-29962
    Windows Media CVE-2025-29963
    Windows Media CVE-2025-29964
    Windows Remote Desktop CVE-2025-29966
    Remote Desktop Gateway Service CVE-2025-29967
    Active Directory Certificate Services (AD CS) CVE-2025-29968
    Windows Fundamentals CVE-2025-29969
    Microsoft Brokering File System CVE-2025-29970
    Web Threat Defense (WTD.sys) CVE-2025-29971
    Azure Storage Resource Provider CVE-2025-29972
    Azure File Sync CVE-2025-29973
    Windows Kernel CVE-2025-29974
    Microsoft PC Manager CVE-2025-29975
    Microsoft Office SharePoint CVE-2025-29976
    Microsoft Office Excel CVE-2025-29977
    Microsoft Office PowerPoint CVE-2025-29978
    Microsoft Office Excel CVE-2025-29979
    Microsoft Office Excel CVE-2025-30375
    Microsoft Office Excel CVE-2025-30376
    Microsoft Office CVE-2025-30377
    Microsoft Office SharePoint CVE-2025-30378
    Microsoft Office Excel CVE-2025-30379
    Microsoft Office Excel CVE-2025-30381
    Microsoft Office SharePoint CVE-2025-30382
    Microsoft Office Excel CVE-2025-30383
    Microsoft Office SharePoint CVE-2025-30384
    Windows Common Log File System Driver CVE-2025-30385
    Microsoft Office CVE-2025-30386
    Azure CVE-2025-30387
    Windows Win32K - GRFX CVE-2025-30388
    Microsoft Office Excel CVE-2025-30393
    Remote Desktop Gateway Service CVE-2025-30394
    Microsoft Scripting Engine CVE-2025-30397
    Windows DWM CVE-2025-30400
    Windows Common Log File System Driver CVE-2025-32701
    Visual Studio CVE-2025-32702
    Visual Studio CVE-2025-32703
    Microsoft Office Excel CVE-2025-32704
    Microsoft Office Outlook CVE-2025-32705
    Windows Common Log File System Driver CVE-2025-32706
    Windows NTFS CVE-2025-32707
    Windows Ancillary Function Driver for WinSock CVE-2025-32709
    Azure CVE-2025-33072
    Microsoft Dataverse CVE-2025-47732
    Microsoft Power Apps CVE-2025-47733

    We are republishing 5 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?
    Chrome Microsoft Edge (Chromium-based) CVE-2025-4050
    Chrome Microsoft Edge (Chromium-based) CVE-2025-4051
    Chrome Microsoft Edge (Chromium-based) CVE-2025-4052
    Chrome Microsoft Edge (Chromium-based) CVE-2025-4096
    Chrome Microsoft Edge (Chromium-based) CVE-2025-4372

    Security Update Guide Blog Posts
    Date Blog Post
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5058379 Windows 10, version 21H2, Windows 10, version 22H2
    5058384 Windows Server 2022, 23H2 Edition (Server Core installation)
    5058385 Windows Server 2022
    5058392 Windows 10, version 1809, Windows Server 2019
    5058405 Windows 11, version 22H2, Windows 11, version 23H2
    5058411 Windows 11, version 24H2
    5058429 Windows Server 2008 (Security-only update)
    5058449 Windows Server 2008 (Monthly Rollup)
    Released: May 13, 2025
    May 2025 Security Updates - Release Notes - Security Update Guide - Microsoft

     
  4. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    June 2025 Security Updates



    This release consists of the following 66 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?

    Windows Storage Management Provider CVE-2025-24065
    Windows Storage Management Provider CVE-2025-24068
    Windows Storage Management Provider CVE-2025-24069
    Windows Cryptographic Services CVE-2025-29828
    .NET and Visual Studio CVE-2025-30399
    Windows Remote Desktop Services CVE-2025-32710
    Windows Win32K - GRFX CVE-2025-32712
    Windows Common Log File System Driver CVE-2025-32713
    Windows Installer CVE-2025-32714
    Remote Desktop Client CVE-2025-32715
    Windows Media CVE-2025-32716
    Windows SMB CVE-2025-32718
    Windows Storage Management Provider CVE-2025-32719
    Windows Storage Management Provider CVE-2025-32720
    Windows Recovery Driver CVE-2025-32721
    Windows Storage Port Driver CVE-2025-32722
    Windows Local Security Authority Subsystem Service (LSASS) CVE-2025-32724
    Windows DHCP Server CVE-2025-32725
    Windows DHCP Server CVE-2025-33050
    Windows DWM Core Library CVE-2025-33052
    WebDAV CVE-2025-33053
    Windows Storage Management Provider CVE-2025-33055
    Microsoft Local Security Authority Server (lsasrv) CVE-2025-33056
    Windows Local Security Authority (LSA) CVE-2025-33057
    Windows Storage Management Provider CVE-2025-33058
    Windows Storage Management Provider CVE-2025-33059
    Windows Storage Management Provider CVE-2025-33060
    Windows Storage Management Provider CVE-2025-33061
    Windows Storage Management Provider CVE-2025-33062
    Windows Storage Management Provider CVE-2025-33063
    Windows Routing and Remote Access Service (RRAS) CVE-2025-33064
    Windows Storage Management Provider CVE-2025-33065
    Windows Routing and Remote Access Service (RRAS) CVE-2025-33066
    Windows Kernel CVE-2025-33067
    Windows Standards-Based Storage Management Service CVE-2025-33068
    App Control for Business (WDAC) CVE-2025-33069
    Windows Netlogon CVE-2025-33070
    Windows KDC Proxy Service (KPSSVC) CVE-2025-33071
    Windows SMB CVE-2025-33073 8.8
    Windows Installer CVE-2025-33075
    Windows Shell CVE-2025-47160
    Microsoft Office CVE-2025-47162
    Microsoft Office SharePoint CVE-2025-47163
    Microsoft Office CVE-2025-47164 8.4
    Microsoft Office Excel CVE-2025-47165
    Microsoft Office SharePoint CVE-2025-47166
    Microsoft Office CVE-2025-47167
    Microsoft Office Word CVE-2025-47168
    Microsoft Office Word CVE-2025-47169
    Microsoft Office Word CVE-2025-47170
    Microsoft Office Outlook CVE-2025-47171
    Microsoft Office SharePoint CVE-2025-47172
    Microsoft Office CVE-2025-47173
    Microsoft Office Excel CVE-2025-47174
    Microsoft Office PowerPoint CVE-2025-47175
    Microsoft Office Outlook CVE-2025-47176
    Microsoft Office CVE-2025-47953
    Windows Remote Access Connection Manager CVE-2025-47955
    Windows Security App CVE-2025-47956
    Microsoft Office Word CVE-2025-47957
    Visual Studio CVE-2025-47959
    Windows SDK CVE-2025-47962
    Power Automate CVE-2025-47966
    Microsoft AutoUpdate (MAU) CVE-2025-47968
    Windows Hello CVE-2025-47969
    Nuance Digital Engagement Platform CVE-2025-47977

    We are republishing 3 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?

    CERT/CC Windows Secure Boot CVE-2025-3052
    Chrome Microsoft Edge (Chromium-based) CVE-2025-5068
    Chrome Microsoft Edge (Chromium-based) CVE-2025-5419

    Security Update Guide Blog Posts
    Date Blog Post

    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5002735 Excel 2016
    5002736 SharePoint Server Subscription Edition
    5060533 Windows 10, version 21H2, Windows 10, version 22H2
    5060842 Windows 11, version 24H2
    5060999 Windows 11, version 22H2, Windows 11, version 23H2
    5061026 Windows Server 2008 (Monthly Rollup)
    5061072 Windows Server 2008 (Security-only update)


    Released: Jun 10, 2025
    June 2025 Security Updates - Release Notes - Security Update Guide - Microsoft
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds