Sumtrix
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
No Result
View All Result
Home Cyber

June 2025 Microsoft Patch Tuesday: Essential Security Updates Unveiled

by Jane Doe
June 11, 2025
in Cyber
A A
0
Share on FacebookShare on Twitter

Microsoft has rolled out its massive security updates on the June patch day, fixing a total of 66 security vulnerabilities, including one known Zero-day issue, in its products.

This month’s wave of Patch Tuesday updates serves as a critical reminder of the importance of immediate patching, with fixes for one actively exploited zero-day vulnerability and nine other critical issues.

The actively used zero-day, tracked as CVE-2025-33053, impacts Web Distributed Authoring and Versioning (WebDAV) and could lead to remote code execution without authentication and by simply getting the user to click on a malicious link.

This “Important”-rated vulnerability, rated with a Common Vulnerability Scoring System (CVSS) of 8.8, is somewhat of a high-risk, mostly if you have an internet-facing WebDAV server. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this exposure to its Catalog of Known Exploited Vulnerabilities, and is urging federal agencies to fix it by July 1, 2025.

Read Also

Global Connected Car Regulations Analysis Report 2025: Focus on Cybersecurity and Data Privacy

Black Hat SEO Poisoning Search Engine Results For AI

There are nine critical vulnerabilities in total that you will want to watch for, some of the most concerning due to the outsize impact they could have to the victim:

Microsoft Office Remote Code Execution (CVE-2025-47162, CVE-2025-47164, CVE-2025-47167, CVE-2025-47953): These types of vulnerabilities enable an attacker to remotely run code on your machine without any user interaction, typically through local attacks.

Windows Remote Desktop Services Remote Code Execution (CVE-2025-32710): An attacker could exploit this issue to remotelyexecute arbitrary code without authentication.

Windows Cryptographic Services (Schannel) Remote Code Execution (CVE-2025-29828): An unauthenticated remote attacker could exploit a memory condition in the implementation of the Transport Layer Security (TLS) in Schannel to remotely execute code.

Windows Netlogon Elevation of Privilege (CVE-2025-33070) and Power Automate Elevation of Privilege (CVE-2025-47966): These could allow an attacker to elevate as privileges on the network.

Noteworthy fixes also include an elevation of privilege vulnerability in Windows SMB Client (CVE-2025-33073) publicly disclosed with proof-of-concept code. Updates for June 2025 address some of these:Windows and Windows Components, Microsoft Office versions,. NET and Visual Studio along with Windows Cryptographic Service.

Microsoft recommends all users and administrators to install these updates immediately to protect their system against any potential threats to their system and avoid any exploitation of their networks.

Jane Doe

You May Also Likes!

Iranian-backed hackers go to work after U.S. strikes
Cyber

Cyber is now the third-largest economy in the world – June 2025 Report

by Jane Doe
June 25, 2025
Iranian-backed hackers go to work after U.S. strikes
Cyber

DHS warns of heightened cyber threat as US enters Iran conflict

by Jane Doe
June 25, 2025
Iranian-backed hackers go to work after U.S. strikes
Cyber

Leak of data belonging to 7.4 million Paraguayans traced back to infostealers

by Jane Doe
June 25, 2025
Iranian-backed hackers go to work after U.S. strikes
Cyber

Billions of login credentials have been leaked online, Cybernews researchers say

by Jane Doe
June 25, 2025
Iranian-backed hackers go to work after U.S. strikes
Cyber

Global cyber alert: Iranian hackers strike U.S. banks, defence and oil firms

by Jane Doe
June 25, 2025
Load More

Recommended

Enhance Your Cybersecurity on World Environment Day with KnowBe4’s Expert Guide

Enhance Your Cybersecurity on World Environment Day with KnowBe4’s Expert Guide

June 5, 2025
New Windows RAT Exploits Corrupted Headers for Stealthy Evasion

New Windows RAT Exploits Corrupted Headers for Stealthy Evasion

May 31, 2025
23andMe Faces £2.31 Million Fine From ICO for Insufficient Data Security

23andMe Faces £2.31 Million Fine From ICO for Insufficient Data Security

June 23, 2025

Kimsuky Exploits BlueKeep RDP Vulnerability to Breach Systems in South Korea and Japan

April 21, 2025
Iranian-backed hackers go to work after U.S. strikes

Global Connected Car Regulations Analysis Report 2025: Focus on Cybersecurity and Data Privacy

June 25, 2025
Iranian-backed hackers go to work after U.S. strikes

Black Hat SEO Poisoning Search Engine Results For AI

June 25, 2025
Iranian-backed hackers go to work after U.S. strikes

Cyber is now the third-largest economy in the world – June 2025 Report

June 25, 2025
Iranian-backed hackers go to work after U.S. strikes

DHS warns of heightened cyber threat as US enters Iran conflict

June 25, 2025
Sumtrix.com

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Navigate Site

  • About
  • Contact
  • Privacy Policy
  • Advertise

Follow Us

No Result
View All Result
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Our website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.