Advisory

Microsoft August 2025 Patch Tuesday fixes 107 vulnerabilities, including 13 critical and one zero-day

Take action: This month prioritize patching of Microsoft Windows, Azure integration components and Microsoft Office. Those are impacted by the critical issues. Don't forget to update your Windows PCs/Laptops, since we all use them on the internet and this list of flaws will be abused by hackers.


Learn More

Microsoft has released its August 2025 Patch Tuesday security updates, patching 107 security flaws.

This Patch Tuesday fixes thirteen critical vulnerabilities, nine of which are remote code execution flaws, three are information disclosure vulnerabilities and one is categorized as an elevation of privileges:

  • CVE-2025-53793 (CVSS score N/A, Microsoft classifies as critical) - Azure Stack Hub Information Disclosure Vulnerability
  • CVE-2025-49707 (CVSS score N/A, Microsoft classifies as critical) - Azure Virtual Machines Spoofing Vulnerability
  • CVE-2025-53781 (CVSS score N/A, Microsoft classifies as critical)- Azure Virtual Machines Information Disclosure Vulnerability
  • CVE-2025-50176 (CVSS score N/A, Microsoft classifies as critical) - DirectX Graphics Kernel Remote Code Execution Vulnerability
  • CVE-2025-50165 (CVSS score N/A, Microsoft classifies as critical) - Windows Graphics Component Remote Code Execution Vulnerability
  • CVE-2025-53740 (CVSS score N/A, Microsoft classifies as critical) - Microsoft Office Remote Code Execution Vulnerability
  • CVE-2025-53731 (CVSS score N/A, Microsoft classifies as critical) - Microsoft Office Remote Code Execution Vulnerability
  • CVE-2025-48807 (CVSS score N/A, Microsoft classifies as critical) - Windows Hyper-V Remote Code Execution Vulnerability
  • CVE-2025-53766 (CVSS score N/A, Microsoft classifies as critical) - GDI+ Remote Code Execution Vulnerability
  • CVE-2025-50177 (CVSS score N/A, Microsoft classifies as critical) - Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
  • CVE-2025-53778 (CVSS score N/A, Microsoft classifies as critical) - Windows NTLM Elevation of Privilege Vulnerability
  • CVE-2025-53784 (CVSS score N/A, Microsoft classifies as critical) - Microsoft Word Remote Code Execution Vulnerability
  • CVE-2025-53733 (CVSS score N/A, Microsoft classifies as critical) - Microsoft Word Remote Code Execution Vulnerability 

The release also fixes one publicly disclosed zero-day flaw in Windows Kerberos authentication system, tracked as CVE-2025-53779 (CVSS score N/A, Microsoft classifies as medium) 

The vulnerability distribution includes:

  • 44 elevation of privilege vulnerabilities,
  • 35 remote code execution vulnerabilities
  • 18 information disclosure vulnerabilities
  • 9 spoofing vulnerabilities
  • 4 denial of service vulnerabilities

Full list of patched vulnerabilities

TagCVE IDCVE TitleSeverity
Azure File SyncCVE-2025-53729Microsoft Azure File Sync Elevation of Privilege VulnerabilityImportant
Azure StackCVE-2025-53793Azure Stack Hub Information Disclosure VulnerabilityCritical
Azure StackCVE-2025-53765Azure Stack Hub Information Disclosure VulnerabilityImportant
Azure Virtual MachinesCVE-2025-49707Azure Virtual Machines Spoofing VulnerabilityCritical
Azure Virtual MachinesCVE-2025-53781Azure Virtual Machines Information Disclosure VulnerabilityCritical
Desktop Windows ManagerCVE-2025-53152Desktop Windows Manager Remote Code Execution VulnerabilityImportant
Desktop Windows ManagerCVE-2025-50153Desktop Windows Manager Elevation of Privilege VulnerabilityImportant
GitHub Copilot and Visual StudioCVE-2025-53773GitHub Copilot and Visual Studio Remote Code Execution VulnerabilityImportant
Graphics KernelCVE-2025-50176DirectX Graphics Kernel Remote Code Execution VulnerabilityCritical
Kernel Streaming WOW Thunk Service DriverCVE-2025-53149Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityImportant
Kernel Transaction ManagerCVE-2025-53140Windows Kernel Transaction Manager Elevation of Privilege VulnerabilityImportant
Microsoft Brokering File SystemCVE-2025-53142Microsoft Brokering File System Elevation of Privilege VulnerabilityImportant
Microsoft Dynamics 365 (on-premises)CVE-2025-49745Microsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityImportant
Microsoft Dynamics 365 (on-premises)CVE-2025-53728Microsoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityImportant
Microsoft Edge for AndroidCVE-2025-49755Microsoft Edge (Chromium-based) for Android Spoofing VulnerabilityLow
Microsoft Edge for AndroidCVE-2025-49736Microsoft Edge (Chromium-based) for Android Spoofing VulnerabilityModerate
Microsoft Exchange ServerCVE-2025-25005Microsoft Exchange Server Tampering VulnerabilityImportant
Microsoft Exchange ServerCVE-2025-25006Microsoft Exchange Server Spoofing VulnerabilityImportant
Microsoft Exchange ServerCVE-2025-25007Microsoft Exchange Server Spoofing VulnerabilityImportant
Microsoft Exchange ServerCVE-2025-53786Microsoft Exchange Server Hybrid Deployment Elevation of Privilege VulnerabilityImportant
Microsoft Exchange ServerCVE-2025-33051Microsoft Exchange Server Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2025-49743Windows Graphics Component Elevation of Privilege VulnerabilityImportant
Microsoft Graphics ComponentCVE-2025-50165Windows Graphics Component Remote Code Execution VulnerabilityCritical
Microsoft OfficeCVE-2025-53732Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2025-53740Microsoft Office Remote Code Execution VulnerabilityCritical
Microsoft OfficeCVE-2025-53731Microsoft Office Remote Code Execution VulnerabilityCritical
Microsoft Office ExcelCVE-2025-53759Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-53737Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-53739Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-53735Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-53741Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office PowerPointCVE-2025-53761Microsoft PowerPoint Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2025-53760Microsoft SharePoint Elevation of Privilege VulnerabilityImportant
Microsoft Office SharePointCVE-2025-49712Microsoft SharePoint Remote Code Execution VulnerabilityImportant
Microsoft Office VisioCVE-2025-53730Microsoft Office Visio Remote Code Execution VulnerabilityImportant
Microsoft Office VisioCVE-2025-53734Microsoft Office Visio Remote Code Execution VulnerabilityImportant
Microsoft Office WordCVE-2025-53738Microsoft Word Remote Code Execution VulnerabilityImportant
Microsoft Office WordCVE-2025-53736Microsoft Word Information Disclosure VulnerabilityImportant
Microsoft Office WordCVE-2025-53784Microsoft Word Remote Code Execution VulnerabilityCritical
Microsoft Office WordCVE-2025-53733Microsoft Word Remote Code Execution VulnerabilityCritical
Microsoft TeamsCVE-2025-53783Microsoft Teams Remote Code Execution VulnerabilityImportant
Remote Access Point-to-Point Protocol (PPP) EAP-TLSCVE-2025-50159Remote Access Point-to-Point Protocol (PPP) EAP-TLS Elevation of Privilege VulnerabilityImportant
Remote Desktop ServerCVE-2025-50171Remote Desktop Spoofing VulnerabilityImportant
Role: Windows Hyper-VCVE-2025-50167Windows Hyper-V Elevation of Privilege VulnerabilityImportant
Role: Windows Hyper-VCVE-2025-53155Windows Hyper-V Elevation of Privilege VulnerabilityImportant
Role: Windows Hyper-VCVE-2025-49751Windows Hyper-V Denial of Service VulnerabilityImportant
Role: Windows Hyper-VCVE-2025-53723Windows Hyper-V Elevation of Privilege VulnerabilityImportant
Role: Windows Hyper-VCVE-2025-48807Windows Hyper-V Remote Code Execution VulnerabilityCritical
SQL ServerCVE-2025-49758Microsoft SQL Server Elevation of Privilege VulnerabilityImportant
SQL ServerCVE-2025-24999Microsoft SQL Server Elevation of Privilege VulnerabilityImportant
SQL ServerCVE-2025-53727Microsoft SQL Server Elevation of Privilege VulnerabilityImportant
SQL ServerCVE-2025-49759Microsoft SQL Server Elevation of Privilege VulnerabilityImportant
SQL ServerCVE-2025-47954Microsoft SQL Server Elevation of Privilege VulnerabilityImportant
Storage Port DriverCVE-2025-53156Windows Storage Port Driver Information Disclosure VulnerabilityImportant
Web DeployCVE-2025-53772Web Deploy Remote Code Execution VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2025-53718Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2025-53134Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2025-49762Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2025-53147Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2025-53154Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2025-53137Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2025-53141Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Cloud Files Mini Filter DriverCVE-2025-50170Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityImportant
Windows Connected Devices Platform ServiceCVE-2025-53721Windows Connected Devices Platform Service Elevation of Privilege VulnerabilityImportant
Windows DirectXCVE-2025-53135DirectX Graphics Kernel Elevation of Privilege VulnerabilityImportant
Windows DirectXCVE-2025-50172DirectX Graphics Kernel Denial of Service VulnerabilityImportant
Windows Distributed Transaction CoordinatorCVE-2025-50166Windows Distributed Transaction Coordinator (MSDTC) Information Disclosure VulnerabilityImportant
Windows File ExplorerCVE-2025-50154Microsoft Windows File Explorer Spoofing VulnerabilityImportant
Windows GDI+CVE-2025-53766GDI+ Remote Code Execution VulnerabilityCritical
Windows InstallerCVE-2025-50173Windows Installer Elevation of Privilege VulnerabilityImportant
Windows KerberosCVE-2025-53779Windows Kerberos Elevation of Privilege VulnerabilityModerate
Windows KernelCVE-2025-49761Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2025-53151Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows Local Security Authority Subsystem Service (LSASS)CVE-2025-53716Local Security Authority Subsystem Service (LSASS) Denial of Service VulnerabilityImportant
Windows MediaCVE-2025-53131Windows Media Remote Code Execution VulnerabilityImportant
Windows Message QueuingCVE-2025-53145Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityImportant
Windows Message QueuingCVE-2025-53143Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityImportant
Windows Message QueuingCVE-2025-50177Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityCritical
Windows Message QueuingCVE-2025-53144Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityImportant
Windows NT OS KernelCVE-2025-53136NT OS Kernel Information Disclosure VulnerabilityImportant
Windows NTFSCVE-2025-50158Windows NTFS Information Disclosure VulnerabilityImportant
Windows NTLMCVE-2025-53778Windows NTLM Elevation of Privilege VulnerabilityCritical
Windows PrintWorkflowUserSvcCVE-2025-53133Windows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityImportant
Windows Push NotificationsCVE-2025-53725Windows Push Notifications Apps Elevation of Privilege VulnerabilityImportant
Windows Push NotificationsCVE-2025-53724Windows Push Notifications Apps Elevation of Privilege VulnerabilityImportant
Windows Push NotificationsCVE-2025-50155Windows Push Notifications Apps Elevation of Privilege VulnerabilityImportant
Windows Push NotificationsCVE-2025-53726Windows Push Notifications Apps Elevation of Privilege VulnerabilityImportant
Windows Remote Desktop ServicesCVE-2025-53722Windows Remote Desktop Services Denial of Service VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-50157Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-53153Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-50163Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-50162Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-50164Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-53148Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-53138Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-50156Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-49757Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-53719Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-53720Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-50160Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Security AppCVE-2025-53769Windows Security App Spoofing VulnerabilityImportant
Windows SMBCVE-2025-50169Windows SMB Remote Code Execution VulnerabilityImportant
Windows StateRepository APICVE-2025-53789Windows StateRepository API Server file Elevation of Privilege VulnerabilityImportant
Windows Subsystem for LinuxCVE-2025-53788Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege VulnerabilityImportant
Windows Win32K - GRFXCVE-2025-50161Win32k Elevation of Privilege VulnerabilityImportant
Windows Win32K - GRFXCVE-2025-53132Win32k Elevation of Privilege VulnerabilityImportant
Windows Win32K - ICOMPCVE-2025-50168Win32k Elevation of Privilege VulnerabilityImportant
Microsoft August 2025 Patch Tuesday fixes 107 vulnerabilities, including 13 critical and one zero-day