Patch Tuesday 2025
The latest Patch Tuesday 2025 coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft’s August Patches Slam Shut 107+ Holes, Including Public Kerberos Flaw and Critical GDI+ RCE
On August 12, 2025, Microsoft’s monthly Patch Tuesday arrived with a payload heavy enough to keep IT admins working through the night. The security slate covers at least 107 distinct...
Microsoft’s August Patches Fix Kerberos dMSA Vulnerability That Lets Attackers Escalate to Domain Admin
A newly disclosed vulnerability in Windows Server 2025’s delegated Managed Service Accounts (dMSA) feature allows an attacker with initial access to specific Kerberos secrets to escalate to full...
KB5063709 Update Fixes Windows 10 ESU Enrollment Crash, Adds Secure Boot Anti-Rollback
Microsoft has released cumulative update KB5063709 for Windows 10 versions 21H2 and 22H2, pushing system builds to 19044.6216 and 19045.6216, respectively. The August 2025 Patch Tuesday rollout...
Critical Heap Overflow in Windows RRAS: Patch Now to Protect VPN Gateways from Remote Code Execution
Microsoft’s June–July 2025 security updates address a critical heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) that could allow remote code execution against...
How CVE-2025-53148 Can Leak Your VPN Secrets: Windows RRAS Patch and Mitigation Guide
Microsoft’s latest Patch Tuesday brought to light CVE-2025-53148, a serious information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS). The flaw, categorized as a...
CVE-2025-53137: Microsoft’s AFD.sys Patch Stops Local Attackers from Hijacking SYSTEM
A use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), tracked as CVE-2025-53137, hands any local attacker with a toehold on a machine a direct path to SYSTEM...
Urgent Fix: Hyper-V Race Condition CVE-2025-50167 Lets Attackers Seize Host Control
Microsoft has confirmed a dangerous race condition in Windows Hyper-V that gives an attacker with low-level access a path to full host compromise, escalating privileges to the kernel level. Tagged...
137 Fixes and a Win32K Type-Confusion Bug: Microsoft’s Mammoth July Patch Tuesday
Microsoft’s July 2025 security update is a behemoth, shipping patches for 137 vulnerabilities, including a zero-day in SQL Server and a heap of critical remote code execution flaws. But buried in...
Microsoft Patches Actively Exploited Windows DWM Use-After-Free Vulnerability CVE-2025-30400
A critical vulnerability in Windows Desktop Window Manager (DWM) gave attackers a direct path to SYSTEM privileges, and Microsoft confirmed it was being exploited in real-world attacks before May...
Critical SQL Server Patches Land, but CVE Confusion Causes Headaches for Admins
Microsoft’s July 2025 Patch Tuesday brought a cluster of security updates for SQL Server that fix critical vulnerabilities, including a heap-based buffer overflow leading to remote code execution,...
Patch Now: Windows RRAS Heap Overflow CVE-2025-49657 Opens Door to Unauthenticated RCE
Microsoft’s July 2025 Patch Tuesday delivered a critical update for a heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS), tracked as CVE-2025-49657. A remote,...
Windows 11 KB5062663 Update Patches ReFS Memory Exhaustion and Hibernation Bugs
Microsoft’s latest optional preview update for Windows 11, KB5062663, delivers a crucial fix for a bug that could completely drain system memory when backup applications process large files on...