• Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
No Result
View All Result
Home Cyber

June 2025 Microsoft Patch Tuesday: Essential Security Updates Unveiled

Jane Doe by Jane Doe
June 11, 2025
in Cyber
June 2025 Microsoft Patch Tuesday: Essential Security Updates Unveiled
Share on FacebookShare on Twitter

Microsoft has rolled out its massive security updates on the June patch day, fixing a total of 66 security vulnerabilities, including one known Zero-day issue, in its products.

This month’s wave of Patch Tuesday updates serves as a critical reminder of the importance of immediate patching, with fixes for one actively exploited zero-day vulnerability and nine other critical issues.

The actively used zero-day, tracked as CVE-2025-33053, impacts Web Distributed Authoring and Versioning (WebDAV) and could lead to remote code execution without authentication and by simply getting the user to click on a malicious link.

Read

App Store Power and Censorship: How Apple and Google Shape Your Digital Future

Google Sets Sights on Defying Gravity with Antigravity Project

This “Important”-rated vulnerability, rated with a Common Vulnerability Scoring System (CVSS) of 8.8, is somewhat of a high-risk, mostly if you have an internet-facing WebDAV server. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this exposure to its Catalog of Known Exploited Vulnerabilities, and is urging federal agencies to fix it by July 1, 2025.

There are nine critical vulnerabilities in total that you will want to watch for, some of the most concerning due to the outsize impact they could have to the victim:

Microsoft Office Remote Code Execution (CVE-2025-47162, CVE-2025-47164, CVE-2025-47167, CVE-2025-47953): These types of vulnerabilities enable an attacker to remotely run code on your machine without any user interaction, typically through local attacks.

Windows Remote Desktop Services Remote Code Execution (CVE-2025-32710): An attacker could exploit this issue to remotelyexecute arbitrary code without authentication.

Windows Cryptographic Services (Schannel) Remote Code Execution (CVE-2025-29828): An unauthenticated remote attacker could exploit a memory condition in the implementation of the Transport Layer Security (TLS) in Schannel to remotely execute code.

Windows Netlogon Elevation of Privilege (CVE-2025-33070) and Power Automate Elevation of Privilege (CVE-2025-47966): These could allow an attacker to elevate as privileges on the network.

Noteworthy fixes also include an elevation of privilege vulnerability in Windows SMB Client (CVE-2025-33073) publicly disclosed with proof-of-concept code. Updates for June 2025 address some of these:Windows and Windows Components, Microsoft Office versions,. NET and Visual Studio along with Windows Cryptographic Service.

Microsoft recommends all users and administrators to install these updates immediately to protect their system against any potential threats to their system and avoid any exploitation of their networks.

Previous Post

Guarding Against Zero-Click Threats: Phones Targeted by Chinese Hackers

Next Post

2025 Cyber Crime Data: What the Latest Statistics Reveal

Jane Doe

Jane Doe

More Articles

Operation WrtHug Hijacks Tens of Thousands ASUS Routers
Latest News

Operation WrtHug Hijacks Tens of Thousands ASUS Routers

Massive Infection: Tens of thousands of end-of-life ASUS WRT routers compromised worldwide, mainly in Taiwan, the US, and Russia. Exploit...

by Sumit Chauhan
November 19, 2025
WhatsApp Worm Delivers Brazilian Banking Trojan
Cyber

WhatsApp Worm Delivers Brazilian Banking Trojan

Worm Spread: Python-scripted WhatsApp worm targets Brazil, hijacking accounts to send a Delphi-based banking trojan, Eternidade Stealer. Infection Path: Starts...

by Sumit Chauhan
November 19, 2025
FBI Sounds Alarm on Akira Ransomware’s 0 Million Haul
Cyber

FBI Sounds Alarm on Akira Ransomware’s $250 Million Haul

Ransom Total: $248.9 million from 321 victims—mostly US firms in tech, finance, healthcare since May 2023. Tactics: Double extortion—encrypts files,...

by Max Mueller
November 16, 2025
US Car Dealers Grind to Halt in CDK Ransomware Chaos
Cyber

US Car Dealers Grind to Halt in CDK Ransomware Chaos

Scale Hit: 15,000+ dealerships across US and Canada offline—sales, financing, service apps down for weeks. Financial Sting: $1.2 billion lost...

by Mayank Singh
November 16, 2025
Next Post
2025 Cyber Crime Data: What the Latest Statistics Reveal

2025 Cyber Crime Data: What the Latest Statistics Reveal

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Latest News

China Accuses US of Cyberattacks Using Microsoft Email Server Flaws

China Accuses US of Cyberattacks Using Microsoft Email Server Flaws

August 1, 2025
Online Scam Cases Continue to Rise Despite Crackdowns on Foreign Fraud Networks [Myanmar]

Online Scam Cases Continue to Rise Despite Crackdowns on Foreign Fraud Networks [Myanmar]

June 30, 2025
Stay Safe from Ransomware Using Skitnet Malware Techniques

Stay Safe from Ransomware Using Skitnet Malware Techniques

May 20, 2025
MMaDA-Parallel: Advanced Multimodal Model Revolutionizing Content Generation

MMaDA-Parallel: Advanced Multimodal Model Revolutionizing Content Generation

November 19, 2025
Anthropic Blocks AI Misuse for Cyberattacks

Anthropic Blocks AI Misuse for Cyberattacks

August 28, 2025
New VoIP Botnet Targets Routers Using Default Passwords

New VoIP Botnet Targets Routers Using Default Passwords

July 25, 2025
Aflac Incorporated Discloses Cybersecurity Incident

Aflac Incorporated Discloses Cybersecurity Incident

June 20, 2025
Sumtrix.com

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Navigate Site

  • About
  • Contact
  • Privacy Policy
  • Advertise

Follow Us

No Result
View All Result
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Our website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.