Microsoft Patch Tuesday July 2025

Microsoft released patch Tuesday June 2025 as a monthly security update, addressing a total of 130 Microsoft Common Vulnerabilities and Exposures (CVEs) and republishing 10 non-Microsoft CVEs.

Vulnerability TypeCount
Remote Code Execution (RCE)41
Elevation of Privilege (EoP)53
Information Disclosure (ID)18
Denial of Service (DoS)5
Spoofing4
Data Tampering1
Security Feature Bypass8
Total130

The update covers a wide range of products and services, including Windows, Microsoft Office, SQL Server, Microsoft Edge (Chromium-based), and Visual Studio, among others.

This release includes critical and important vulnerabilities, with several allowing remote code execution (RCE). Notably, no zero-day vulnerabilities or actively exploited vulnerabilities were reported in this update.

Google News

Critical Vulnerabilities:

CVE-2025-47981 (Windows SPNEGO Extended Negotiation, CVSS 9.8): This vulnerability allows attackers to achieve high confidentiality, integrity, and availability impacts over a network without user interaction, making it a high-priority target for patching.

CVE-2025-49717 (SQL Server, CVSS 8.5): This vulnerability could allow attackers to execute code remotely with significant impact on affected systems.

Important Vulnerabilities:

These vulnerabilities span various Microsoft products and services, including Windows Kernel, Remote Desktop Client, Microsoft Office, Windows BitLocker, and Windows Routing and Remote Access Service (RRAS). Most have CVSS scores ranging from 5.5 to 8.8, indicating moderate to high severity.

A significant portion of the vulnerabilities 41 CVEs could potentially lead to remote code execution, allowing attackers to run arbitrary code on affected systems. Key examples include:

Microsoft confirmed that none of the vulnerabilities in this update are actively exploited or classified as zero-day vulnerabilities.

The Exploitability column for all CVEs lists “Exploitation Unlikely” or “Exploitation Less Likely,” indicating no known active exploitation at the time of release.

CVE IDDescriptionSeverityImpactExploitation Status
CVE-2025-36357AMD: CVE-2025-36357 Transient Scheduler Attack in L1 Data QueueCriticalInformation DisclosureNo
CVE-2025-36350AMD: CVE-2024-36350 Transient Scheduler Attack in Store QueueCriticalInformation DisclosureNo
CVE-2025-49717Microsoft SQL Server Remote Code Execution VulnerabilityCriticalRemote Code ExecutionNo
CVE-2025-49735Windows KDC Proxy Service (KPSSVC) Remote Code Execution VulnerabilityCriticalRemote Code ExecutionNo
CVE-2025-47980Windows Imaging Component Information Disclosure VulnerabilityCriticalInformation DisclosureNo
CVE-2025-47981SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution VulnerabilityCriticalRemote Code ExecutionNo
CVE-2025-48822Windows Hyper-V Discrete Device Assignment (DDA) Remote Code Execution VulnerabilityCriticalRemote Code ExecutionNo
CVE-2025-49695Microsoft Office Remote Code Execution VulnerabilityCriticalRemote Code ExecutionNo
CVE-2025-49696Microsoft Office Remote Code Execution VulnerabilityCriticalRemote Code ExecutionNo
CVE-2025-49697Microsoft Office Remote Code Execution VulnerabilityCriticalRemote Code ExecutionNo
CVE-2025-49698Microsoft Word Remote Code Execution VulnerabilityCriticalRemote Code ExecutionNo
CVE-2025-49702Microsoft Office Remote Code Execution VulnerabilityCriticalRemote Code ExecutionNo
CVE-2025-49703Microsoft Word Remote Code Execution VulnerabilityCriticalRemote Code ExecutionNo
CVE-2025-49704Microsoft SharePoint Remote Code Execution VulnerabilityCriticalRemote Code ExecutionNo
CVE-2025-26636Windows Kernel Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-33054Remote Desktop Spoofing VulnerabilityImportantSpoofingNo
CVE-2025-47159Windows Virtualization-Based Security (VBS) Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-21195Azure Service Fabric Runtime Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47971Microsoft Virtual Hard Disk Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47972Windows Input Method Editor (IME) Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47976Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47984Windows GDI Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-47985Windows Event Tracing Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47986Universal Print Management Service Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47987Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-48824Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49657Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49658Windows Transport Driver Interface (TDI) Translation Driver Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-49661Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49670Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49671Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-49672Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49674Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49676Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49677Microsoft Brokering File System Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49686Windows TCP/IP Driver Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49687Windows Input Method Editor (IME) Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49688Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49689Microsoft Virtual Hard Disk Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49690Capability Access Management Service (camsvc) Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49691Windows Miracast Wireless Display Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49694Microsoft Brokering File System Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47991Windows Input Method Editor (IME) Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47993Microsoft PC Manager Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47994Microsoft Office Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-48812Microsoft Excel Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-49711Microsoft Excel Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49716Windows Netlogon Denial of Service VulnerabilityImportantDenial of ServiceNo
CVE-2025-49719Microsoft SQL Server Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-49721Windows Fast FAT File System Driver Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49723Windows StateRepository API Server file Tampering VulnerabilityImportantTamperingNo
CVE-2025-49726Windows Notification Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49731Microsoft Teams Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47178Microsoft Configuration Manager Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49753Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49756Office Developer Platform Security Feature Bypass VulnerabilityImportantSecurity Feature BypassNo
CVE-2025-47973Microsoft Virtual Hard Disk Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47975Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-1980-0000Windows Kerberos Denial of Service VulnerabilityImportantDenial of ServiceNo
CVE-2025-47982Windows Storage VSP Driver Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47996Windows MBT Transport Driver Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47998Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-48000Windows Connected Devices Platform Service Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-48001BitLocker Security Feature Bypass VulnerabilityImportantSecurity Feature BypassNo
CVE-2025-48002Windows Hyper-V Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-48003BitLocker Security Feature Bypass VulnerabilityImportantSecurity Feature BypassNo
CVE-2025-48799Windows Update Service Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-48800BitLocker Security Feature Bypass VulnerabilityImportantSecurity Feature BypassNo
CVE-2025-48802Windows SMB Server Spoofing VulnerabilityImportantSpoofingNo
CVE-2025-48803Windows Virtualization-Based Security (VBS) Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-48804BitLocker Security Feature Bypass VulnerabilityImportantSecurity Feature BypassNo
CVE-2025-48805Microsoft MPEG-2 Video Extension Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-48806Microsoft MPEG-2 Video Extension Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-48808Windows Kernel Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-48809Windows Secure Kernel Mode Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-48810Windows Secure Kernel Mode Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-48811Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-48814Remote Desktop Licensing Service Security Feature Bypass VulnerabilityImportantSecurity Feature BypassNo
CVE-2025-48815Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-48816HID Class Driver Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-48817Remote Desktop Client Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-48818BitLocker Security Feature Bypass VulnerabilityImportantSecurity Feature BypassNo
CVE-2025-48819Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-48820Windows AppX Deployment Service Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-48821Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-48823Windows Cryptographic Services Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-49659Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49660Windows Event Tracing Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49663Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49664Windows User-Mode Driver Framework Host Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-49665Workspace Broker Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49666Windows Server Setup and Boot Event Collection Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49667Windows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49668Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49669Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49673Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49675Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49678NTFS Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49679Windows Shell Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49680Windows Performance Recorder (WPR) Denial of Service VulnerabilityImportantDenial of ServiceNo
CVE-2025-49681Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-49682Windows Media Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49683Microsoft Virtual Hard Disk Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49684Windows Storage Port Driver Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-49685Windows Search Service Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49693Microsoft Brokering File System Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49699Microsoft Office Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49700Microsoft Word Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49701Microsoft SharePoint Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49705Microsoft PowerPoint Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49706Microsoft SharePoint Server Spoofing VulnerabilityImportantSpoofingNo
CVE-2025-49714Visual Studio Code Python Extension Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49718Microsoft SQL Server Information Disclosure VulnerabilityImportantInformation DisclosureNo
CVE-2025-49722Windows Print Spooler Denial of Service VulnerabilityImportantDenial of ServiceNo
CVE-2025-49724Windows Connected Devices Platform Service Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49725Windows Notification Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49727Win32k Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49729Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49730Microsoft Windows QoS Scheduler Driver Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49732Windows Graphics Component Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49733Win32k Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47999Windows Hyper-V Denial of Service VulnerabilityImportantDenial of ServiceNo
CVE-2025-49737Microsoft Teams Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49738Microsoft PC Manager Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49739Visual Studio Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-49740Windows SmartScreen Security Feature Bypass VulnerabilityImportantSecurity Feature BypassNo
CVE-2025-49742Windows Graphics Component Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49744Windows Graphics Component Elevation of Privilege VulnerabilityImportantElevation of PrivilegeNo
CVE-2025-47988Azure Monitor Agent Remote Code Execution VulnerabilityImportantRemote Code ExecutionNo
CVE-2025-49760Windows Storage Spoofing VulnerabilityModerateSpoofingNo

Key Affected Products and Services

The vulnerabilities impact a broad array of Microsoft products, including:

  • Windows Components: Windows Kernel, Windows BitLocker, Windows SSDP Service, Windows Hyper-V, and Windows Routing and Remote Access Service (RRAS).
  • Microsoft Office Suite: Vulnerabilities in Excel, Word, PowerPoint, and SharePoint, with several allowing RCE or privilege escalation.
  • Cloud and Enterprise Services: Azure Monitor Agent, Microsoft Intune, and SQL Server.
  • Development Tools: Visual Studio and Visual Studio Code Python extension.
  • Browsers: Microsoft Edge (Chromium-based).

For 120 of the 130 Microsoft CVEs, Microsoft has provided FAQs to guide users on patching and mitigation strategies.

No workarounds are listed for any of the vulnerabilities, indicating that applying the security updates is the primary mitigation strategy.

Only two CVEs (CVE-2025-47981 and CVE-2025-49724) have specific mitigations listed, suggesting that most vulnerabilities require patching to address risks fully.

MSSP Pricing Guide: How to Cut Through the Noise and the Hidden Costs -> Get Your Free Guide

Balaji N
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.