Skip to content

Security Update Review for Microsoft and Adobe's August 2025 Patch Tuesday

Microsoft's August 2025 security updates have been released on the second Tuesday of the month, ensuring system protection amidst potential online threats.

August 2025 Security Update Review: Microsoft and Adobe's Critical Fixes for Vulnerabilities
August 2025 Security Update Review: Microsoft and Adobe's Critical Fixes for Vulnerabilities

Security Update Review for Microsoft and Adobe's August 2025 Patch Tuesday

In the latest Patch Tuesday release on August 2, 2025, Microsoft addressed a total of 119 vulnerabilities, including a zero-day vulnerability in Windows Kerberos (CVE-2025-53779). Fortunately, no known active exploits or attempts to exploit this vulnerability were reported before its patch.

Among the vulnerabilities addressed, several flaws were fixed in various software, such as Spoofing, Denial of Service (DoS), Elevation of Privilege (EoP), Information Disclosure, and Remote Code Execution (RCE). Notably, CVE-2025-53731, CVE-2025-53740, and CVE-2025-53733 are Microsoft Office Remote Code Execution vulnerabilities, while CVE-2025-50165 is a Remote Code Execution vulnerability in the Windows Graphics Component.

Microsoft Edge (Chromium-based) saw ten vulnerabilities addressed in this Patch Tuesday, with CVE-2025-50168 being an Elevation of Privilege vulnerability in Win32k. Similarly, CVE-2025-53786 is an Elevation of Privilege vulnerability in Microsoft Exchange Server Hybrid Deployment, and CVE-2025-50177 is a Microsoft Message Queuing (MSMQ) Remote Code Execution vulnerability.

Adobe also released 13 security advisories to address 68 vulnerabilities in various Adobe products. Thirty-eight of these vulnerabilities were given critical severity ratings, emphasising the potential severity of the issues.

Additionally, CVE-2025-53147 is an Elevation of Privilege vulnerability in the Windows Ancillary Function Driver for WinSock, CVE-2025-53766 is a GDI+ Remote Code Execution vulnerability, and CVE-2025-53156 is an Information Disclosure vulnerability in the Windows Storage Port Driver.

In Azure Stack Hub, CVE-2025-53793 is an Information Disclosure vulnerability, while CVE-2025-53781 is an Azure Virtual Machines Information Disclosure vulnerability. CVE-2025-48807 is a Remote Code Execution vulnerability in Windows Hyper-V, and CVE-2025-49743 is an Elevation of Privilege vulnerability in Windows Graphics Component.

Lastly, CVE-2025-53778 is a Windows NTLM Elevation of Privilege vulnerability. The August 2025 Patch Tuesday also contained 13 critical and 91 important severity vulnerabilities.

Staying up-to-date with security patches is crucial for maintaining the security of your systems. Always ensure you have the latest updates installed to protect your digital assets.

Read also:

Latest