Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Turning User Research Into Real Organizational Change

      July 1, 2025

      June 2025: All AI updates from the past month

      June 30, 2025

      Building a culture that will drive platform engineering success

      June 30, 2025

      Gartner: More than 40% of agentic AI projects will be canceled in the next few years

      June 30, 2025

      I FINALLY got my hands on my most anticipated gaming laptop of 2025 — and it’s a 14-inch monster

      July 1, 2025

      This gimbal-tracking webcam has TWO cameras and a great price — but it may not be “private” enough

      July 1, 2025

      I spent two months using the massive Area-51 gaming rig — both a powerful beast PC and an RGB beauty queen

      July 1, 2025

      “Using AI is no longer optional” — Did Microsoft just make Copilot mandatory for its staff as a critical performance metric?

      July 1, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      June report 2025

      July 1, 2025
      Recent

      June report 2025

      July 1, 2025

      Make your JS functions smarter and cleaner with default parameters

      July 1, 2025

      Best Home Interiors in Hyderabad – Top Designers & Affordable Packages

      July 1, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      I FINALLY got my hands on my most anticipated gaming laptop of 2025 — and it’s a 14-inch monster

      July 1, 2025
      Recent

      I FINALLY got my hands on my most anticipated gaming laptop of 2025 — and it’s a 14-inch monster

      July 1, 2025

      This gimbal-tracking webcam has TWO cameras and a great price — but it may not be “private” enough

      July 1, 2025

      I spent two months using the massive Area-51 gaming rig — both a powerful beast PC and an RGB beauty queen

      July 1, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Microsoft Patch Tuesday June 2025: One Zero-Day, Nine High-risk Flaws Fixed

    Microsoft Patch Tuesday June 2025: One Zero-Day, Nine High-risk Flaws Fixed

    June 11, 2025

    Microsoft Patch Tuesday June 2025

    Microsoft’s Patch Tuesday updates for June 2025 include fixes for an actively exploited zero-day vulnerability and nine additional flaws at high risk of exploitation.

    In all, the Microsoft Patch Tuesday June 2025 release note included fixes for 68 vulnerabilities, plus three non-Microsoft CVEs affecting Windows Secure Boot and Chromium-based Edge.

    The highest-rated vulnerability included in the update – a 9.8-severity Power Automate Elevation of Privilege vulnerability (CVE-2025-47966) – was fixed earlier this month.

    Microsoft Patch Tuesday June 2025: Zero-Day, High-risk Flaws

    The exploited zero-day – CVE-2025-33053, an 8.8-rated Web Distributed Authoring and Versioning (WebDAV) Remote Code Execution vulnerability – was reported by Check Point researchers, who discovered the flaw being used in an attempted cyberattack against a defense company in Turkey.

    In the attack, the advanced persistent threat (APT) group Stealth Falcon used a .url file that exploited the zero-day vulnerability to execute malware from a threat actor-controlled WebDAV server, the researchers said.

    The nine vulnerabilities designated “Exploitation More Likely” by Microsoft include:

    • CVE-2025-32713, a 7.8-rated Windows Common Log File System Driver Elevation of Privilege vulnerability. It’s the third straight Patch Tuesday with at least one high-risk CLFS vulnerability, following the April and May updates.
    • CVE-2025-32714, a 7.8-rated Windows Installer Elevation of Privilege vulnerability
    • CVE-2025-32717, an 8.4-severity Microsoft Word Remote Code Execution vulnerability
    • CVE-2025-33070, an 8.1-rated Windows Netlogon Elevation of Privilege vulnerability
    • CVE-2025-33071, an 8.1-severity Windows Kerberos Key Distribution Center Proxy Service (KPSSVC) Remote Code Execution vulnerability
    • CVE-2025-47162, an 8.4-rated Microsoft Office Remote Code Execution vulnerability (Heap-based Buffer Overflow)
    • CVE-2025-47164, which is also an 8.4-rated Microsoft Office Remote Code Execution vulnerability (Use After Free)
    • CVE-2025-47167, another 8.4-severity Microsoft Office Remote Code Execution vulnerability (Type Confusion)
    • CVE-2025-47962, a 7.8-rated Windows SDK Elevation of Privilege vulnerability

    Other Vendors Issuing Patch Tuesday Fixes

    Microsoft isn’t the only vendor issuing fixes on the second Tuesday of each month, as many others have taken up the practice too.

    Other noteworthy patch announcements were issued by:

    • Ivanti, which patched three Ivanti Workspace Control flaws
    • SAP, which included a 9.6-severity NetWeaver Application Server for ABAP Missing Authorization Check vulnerability (CVE-2025-42989)
    • Fortinet, which fixed an OS Command Injection vulnerability

     

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleBreaking Down Apple’s Liquid Glass: The Tech, The Hype, and The Reality
    Next Article 295 Malicious IPs Launch Coordinated Brute-Force Attacks on Apache Tomcat Manager

    Related Posts

    Security

    Google fixes fourth actively exploited Chrome zero-day of 2025

    July 1, 2025
    Security

    Sudo local privilege escalation vulnerabilities fixed (CVE-2025-32462, CVE-2025-32463)

    July 1, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Off-Policy Reinforcement Learning RL with KL Divergence Yields Superior Reasoning in Large Language Models

    Machine Learning

    CVE-2025-48999 – DataEase SQL Injection Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Identity Security Has an Automation Problem—And It’s Bigger Than You Think

    Development

    Discovering novel algorithms with AlphaTensor

    Artificial Intelligence

    Highlights

    Critical ScreenConnect Vulnerability Let Attackers Inject Malicious Code

    April 26, 2025

    Critical ScreenConnect Vulnerability Let Attackers Inject Malicious Code

    ConnectWise has released an urgent security patch for its ScreenConnect remote access software to address a serious vulnerability that could allow attackers to execute malicious code on affected syste …
    Read more

    Published Date:
    Apr 26, 2025 (4 hours, 15 minutes ago)

    Vulnerabilities has been mentioned in this article.

    CVE-2025-3935

    CVE-2024-1709

    CVE-2024-1708

    Microsoft confirms Windows 11 24H2 0x80240069 svchost.exe_wuauserv crashes

    April 30, 2025

    CVE-2025-4096 – Google Chrome Heap Buffer Overflow

    May 5, 2025

    Microsoft’s Copilot Vision is now free for all Edge users – here’s how it works

    April 17, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.