Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sentry launches MCP monitoring tool

      August 14, 2025

      10 Benefits of Hiring a React.js Development Company (2025–2026 Edition)

      August 13, 2025

      From Line To Layout: How Past Experiences Shape Your Design Career

      August 13, 2025

      Hire React.js Developers in the US: How to Choose the Right Team for Your Needs

      August 13, 2025

      I’ve tested every Samsung Galaxy phone in 2025 – here’s the model I’d recommend on sale

      August 14, 2025

      Google Photos just put all its best editing tools a tap away – here’s the shortcut

      August 14, 2025

      Claude can teach you how to code now, and more – how to try it

      August 14, 2025

      One of the best work laptops I’ve tested has MacBook written all over it (but it’s even better)

      August 14, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Controlling Execution Flow with Laravel’s Sleep Helper

      August 14, 2025
      Recent

      Controlling Execution Flow with Laravel’s Sleep Helper

      August 14, 2025

      Generate Secure Temporary Share Links for Files in Laravel

      August 14, 2025

      This Week in Laravel: Filament 4, Laravel Boost, and Junie Review

      August 14, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      KDE Plasma 6 on Wayland: the Payoff for Years of Plumbing

      August 14, 2025
      Recent

      KDE Plasma 6 on Wayland: the Payoff for Years of Plumbing

      August 14, 2025

      FOSS Weekly #25.33: Debian 13 Released, Torvalds vs RISC-V, Arch’s New Tool, GNOME Perfection and More Linux Stuff

      August 14, 2025

      Ultimate ChatGPT-5 Prompt Guide: 52 Ideas for Any Task

      August 14, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Patch Tuesday August 2025: 9 High-Risk Vulnerabilities Fixed by Microsoft

    Patch Tuesday August 2025: 9 High-Risk Vulnerabilities Fixed by Microsoft

    August 12, 2025

    Patch Tuesday August 2025

    Microsoft’s Patch Tuesday update for August 2025 includes fixes for 110 Microsoft vulnerabilities, including nine at higher risk for exploitation and an additional five vulnerabilities carrying 9+ severity ratings.

    The update, down from 130 vulnerabilities in July’s update, also included eight Chrome vulnerabilities in the Chromium-based Microsoft Edge.

    Highest-Rated Vulnerabilities: Fixed or at Lower Risk

    The highest-rated vulnerability – CVE-2025-53767, a 10.0-severity Azure OpenAI Elevation of Privilege vulnerability – has already been fully mitigated by Microsoft, as has CVE-2025-53792, a 9.1-rated Azure Portal Elevation of Privilege vulnerability.

    Three other 9+ rated vulnerabilities – CVE-2025-50171, a Remote Desktop Spoofing vulnerability, CVE-2025-50165, a Windows Graphics Component Remote Code Execution vulnerability, and CVE-2025-53766, a GDI+ Remote Code Execution vulnerability – were judged by Microsoft to be at lower risk of exploitation.

    The Patch Tuesday August 2025 update also includes 13 8.8-rated vulnerabilities – found in SQL Server, SharePoint, Windows Routing and Remote Access Service (RRAS), Windows Media, Windows Message Queuing, and Web Deploy – that Microsoft judged to be at lower risk of exploitation. One 8.8-severity vulnerability – in NTLM – was judged to be at higher risk.

    Patch Tuesday August 2025: High-risk Vulnerabilities

    Among the 10 vulnerabilities judged to be at higher risk of exploitation, CVE-2025-53786 is an 8.0-severity Exchange Server Hybrid Deployment Elevation of Privilege vulnerability that Microsoft warned about last week. About 28,000 Exchange instances remain unpatched, according to the Shadowserver foundation.

    Other high-risk vulnerabilities in the Patch Tuesday August 2025 update include:

    • CVE-2025-53778, an 8.8-rated Windows NTLM Elevation of Privilege vulnerability
    • CVE-2025-53156, a 5.5-severity Windows Storage Port Driver Information Disclosure vulnerability
    • CVE-2025-53147, a 7.0-rated Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
    • CVE-2025-53132, an 8.0-severity Win32k Elevation of Privilege vulnerability
    • CVE-2025-50177, an 8.1-rated Microsoft Message Queuing (MSMQ) Remote Code Execution vulnerability
    • CVE-2025-50168, a 7.8-rated Win32k Elevation of Privilege vulnerability
    • CVE-2025-50167, a 7.0-severity Windows Hyper-V Elevation of Privilege vulnerability
    • CVE-2025-49743, a 6.7-severity Windows Graphics Component Elevation of Privilege vulnerability

    Fortinet and SAP were also among the vendors releasing Patch Tuesday updates today.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleFree Online Bipolar Test – BipolarTest.net
    Next Article BlackSuit Ransomware’s Infrastructure Dismantled; Crypto Worth $1M Seized

    Related Posts

    Development

    Controlling Execution Flow with Laravel’s Sleep Helper

    August 14, 2025
    Development

    Generate Secure Temporary Share Links for Files in Laravel

    August 14, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Spotlighting Trailblazers in Tech: Three Perficient Leaders Honored As 2025 CRN Women of the Channel

    Development

    CVE-2025-42997 – SAP Gateway Client Information Disclosure

    Common Vulnerabilities and Exposures (CVEs)

    Vim Command Line Text Editor Vulnerability Let Attackers Overwrite Sensitive Files

    Security

    CVE-2024-40113 – Sitecom WLX-2006 Default Credentials Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    FBI investigating apparent ISIS attacks on Western websites

    April 9, 2025

    A number of seemingly unconnected Western websites were hacked over the weekend, with messages claiming…

    The Rise of AI-Generated Video: Transforming the Future of Marketing Strategy🎬

    June 2, 2025

    CVE-2025-48936 – Zitadel Host Header Injection Vulnerability

    May 30, 2025

    Text Expander

    May 30, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.