2025年6月11日星期三

Microsoft Monthly Security Update (June 2025)

Microsoft Monthly Security Update (June 2025)

Release Date: 11 Jun 2025

RISK: Extremely High Risk

TYPE: Operating Systems - Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
Microsoft OfficeMedium Risk Medium RiskRemote Code Execution
Elevation of Privilege
 
WindowsExtremely High Risk Extremely High RiskRemote Code Execution
Elevation of Privilege
Information Disclosure
Denial of Service
Security Restriction Bypass
Spoofing

CVE-2025-33053 is being exploited in the wild. This vulnerability exist in Microsoft Windows Web Distributed Authoring and Versioning. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system.  Hence, the risk level of this vulnerability is rated as Extremely High Risk. 

 

Proof of Concept exploit code is publicly available for CVE-2025-33073, affecting the Windows Server Message Block client. Successful exploitation of this vulnerability could allow an authorized attacker to elevate privileges on the affected system. Hence, the risk level of this vulnerability is rated as Medium Risk.

Developer ToolsMedium Risk Medium RiskRemote Code Execution
Elevation of Privilege
 
Extended Security Updates (ESU)Extremely High Risk Extremely High RiskRemote Code Execution
Elevation of Privilege
Information Disclosure
Denial of Service
Security Restriction Bypass

CVE-2025-33053 is being exploited in the wild. This vulnerability exist in Microsoft Windows Web Distributed Authoring and Versioning. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system.  Hence, the risk level of this vulnerability is rated as Extremely High Risk. 

 

Proof of Concept exploit code is publicly available for CVE-2025-33073, affecting the Windows Server Message Block client. Successful exploitation of this vulnerability could allow an authorized attacker to elevate privileges on the affected system. Hence, the risk level of this vulnerability is rated as Medium Risk.

Microsoft DynamicsMedium Risk Medium RiskElevation of Privilege 
AzureLow Risk Low RiskSpoofing 

 

Number of 'Extremely High Risk' product(s): 2

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 3

Number of 'Low Risk' product(s): 1

Evaluation of overall 'Risk Level': Extremely High Risk


Impact

  • Remote Code Execution
  • Elevation of Privilege
  • Information Disclosure
  • Denial of Service
  • Security Restriction Bypass
  • Spoofing

System / Technologies affected

  • Microsoft Office
  • Windows
  • Developer Tools
  • Extended Security Updates (ESU)
  • Microsoft Dynamics
  • Azure

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2025年06月18日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...