Microsoft August 2025 Patch Tuesday, (Tue, Aug 12th)
Microsoft's latest patch update addresses 111 vulnerabilities, with 17 deemed critical. One of these is a zero-day vulnerability in Windows Kerberos, allowing for domain administrator privilege escalation. A critical vulnerability in the Windows Graphics Component enables remote code execution by exploiting uninitialized function pointers when decoding JPEG images. The GDI+ component also has a critical remote code execution vulnerability, exploitable over the network by uploading specially crafted metafiles to web services. While Azure Portal has a critical elevation of privilege vulnerability, Microsoft has fully mitigated it. Another critical vulnerability in Windows NTLM allows privilege escalation to the SYSTEM level. Microsoft Office has a critical remote code execution vulnerability, exploitable through the Preview Pane when a user previews a compromised document. None of these vulnerabilities have been exploited in the wild, but prompt application of updates is strongly advised. The critical vulnerabilities present risks like remote code execution and elevation of privilege. These patches are essential for safeguarding systems against potential threats.