ThreatCluster
About Blog Help Contact
Login
  • Feed
  • Dashboard
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Cluster #1874

CC-4690 - Microsoft Releases August 2025 Security Updates

Threat Score:
68
18 articles
100.0% similarity
1 day ago
JSON CSV Text STIX IoCs
Splunk Elastic Sentinel Sigma YARA All Queries

Article Timeline

18 articles
Click to navigate
Aug 12
Aug 12
Aug 12
Aug 12
Aug 12
Aug 12
Aug 12
Aug 12
Aug 12
Aug 12
Aug 12
Aug 12
Aug 13
Aug 13
Aug 13
Aug 13
Aug 13
Aug 13
Oldest
Latest

Key Insights

1
Microsoft's August 2025 Patch Tuesday addressed 111 vulnerabilities across its products, including 13 rated as critical and 35 classified as remote code execution (RCE) vulnerabilities.
2
CVE-2025-50165, affecting the Windows Graphics Component, has a CVSS score of 9.8 and allows unauthorized code execution over a network.
3
CVE-2025-53779, a publicly disclosed elevation of privilege vulnerability in Windows Kerberos, has a CVSS score of 7.2 and enables attackers to potentially gain domain admin privileges.
4
Approximately 29,000 Exchange servers are reportedly vulnerable to CVE-2025-53786, which allows attackers to pivot from compromised Exchange servers into cloud environments.
5
Security experts recommend immediate patching, especially for organizations using hybrid or cloud environments, to mitigate risks from these vulnerabilities.
6
Despite the severity of these vulnerabilities, no active exploitation has been reported in the wild at the time of the patch release.

Threat Overview

On August 12, 2025, Microsoft released its Patch Tuesday updates addressing a total of 111 vulnerabilities across its ecosystem, including 13 rated as critical and 35 classified as remote code execution (RCE) vulnerabilities. The updates impact various Microsoft products, including Windows, Office, Azure, and Exchange Server. 'This month’s release highlights the ongoing battle against evolving cyber threats,' stated a Microsoft representative. Notably, CVE-2025-50165, affecting the Windows Graphics Component, carries a CVSS score of 9.8, enabling potential remote code execution via untrusted pointer dereferences. Meanwhile, CVE-2025-53779, an elevation of privilege vulnerability in Windows Kerberos, has a CVSS score of 7.2 and could allow attackers to gain domain administrator privileges. Security experts have identified approximately 29,000 vulnerable Exchange servers that could be exploited through CVE-2025-53786, which facilitates unauthorized access to cloud environments. Although the vulnerabilities are severe, Microsoft has indicated that there are currently no known exploits in the wild. Organizations are strongly advised to apply the patches immediately, particularly those operating in hybrid or cloud settings to protect against potential risks.

Tactics, Techniques & Procedures (TTPs)

T1203
Exploit Public-Facing Application - Attackers can exploit vulnerabilities in public-facing Microsoft products to execute code remotely [1][4].
T1068
Exploitation of Elevation of Privilege Vulnerabilities - Attackers can exploit elevation of privilege vulnerabilities to gain higher access levels on systems [5][12].
T1190
Exploit Public-Facing Application - Vulnerabilities in Microsoft Exchange Server allow attackers to pivot into cloud environments [4][9].
T1060
Resource Hijacking - Attackers may utilize compromised servers to gain unauthorized access to sensitive data [12].
T1548.001
Abuse Elevation Control Mechanism - Exploitation of the Kerberos elevation of privilege vulnerability enables attackers to escalate their privileges [17].
T1559
Access Token Manipulation - Attackers may manipulate access tokens to gain unauthorized administrative access [5].
T1075
Pass-the-Hash - Attackers can utilize stolen hashes to authenticate as a legitimate user, especially in Windows environments [5][12].

Timeline of Events

2025-08-06
Microsoft warns of CVE-2025-53786 affecting Exchange Server, allowing attackers to pivot to cloud environments [4].
2025-08-12
Microsoft releases Patch Tuesday updates addressing 111 vulnerabilities, including 13 critical ones [1][16].
2025-08-12
Security researchers highlight the need for immediate patching due to the severity of the vulnerabilities [3][10].
2025-08-12
Microsoft confirms no active exploitation of the vulnerabilities has been reported in the wild [17].
2025-08-12
Security community urges organizations to update their systems promptly to mitigate risks [8][10].

Source Citations

expert_quotes: {'Security experts': 'Articles 4, 10.', 'Microsoft representative': 'Article 1.'}
primary_findings: {'Vulnerability details and patches': 'Articles 1, 3, 4, 10, 16.', 'Exploitation evidence and risk assessment': 'Articles 5, 6, 12.'}
technical_details: {'Attack methods and vulnerability impact': 'Articles 9, 11, 17.'}
Powered by ThreatCluster AI
Generated 4 hours ago
Recent Analysis
AI analysis may contain inaccuracies

Related Articles

18 articles
1

CC-4690 - Microsoft Releases August 2025 Security Updates

NHS Digital Cyber Alerts • 8 hours ago

Microsoft Releases August 2025 Security Updates Scheduled updates for Microsoft products, including security updates for 111 vulnerabilities, of which one has been reported as publicly disclosed Summary Scheduled updates for Microsoft products, including security updates for 111 vulnerabilities, of which one has been reported as publicly disclosed Affected platforms The following platforms are known to be affected: Microsoft Windows Microsoft Windows Server Microsoft Office Microsoft Azure The f

Score
72
100.0% similarity
Read more
2
Microsoft’s Patch Tuesday: 100+ Updates Including Azure OpenAI Service, Memory Corruption Flaw

Microsoft’s Patch Tuesday: 100+ Updates Including Azure OpenAI Service, Memory Corruption Flaw

Techrepublic • 6 hours ago

Microsoft on Aug. 12 released security updates addressing more than 100 vulnerabilities across its products, including 13 rated critical. The patches include fixes for a graphics component flaw described as “extremely high-risk” and a maximum-severity vulnerability in Azure’s OpenAI service. “This month’s release highlights an upward trend in post-compromise vulnerabilities over code execution bugs,” wrote Satnam Narang, senior staff research engineer, Tenable, in an email to TechRepublic. “For

Score
72
100.0% similarity
Read more
3

Microsoft Teams CVE-2025-53783 Vulnerability Could Allow Remote Code Execution

The Cyber Express • 10 hours ago

Microsoft has disclosed a serious vulnerability in its collaboration platform, Microsoft Teams, that could open the door to Remote Code Execution (RCE) attacks. The flaw, tracked as CVE-2025-53783, carries a CVSS score of 7.5 and is categorized as “Important.” The issue arises from a heap-based buffer overflow, a well-known software weakness classified under CWE-122. In this type of vulnerability , an application writes more data to a buffer located in the heap than it was allocated to hold. Thi

Score
67
100.0% similarity
Read more
4

Patch Tuesday: Microsoft Fixes 107 Vulnerabilities, Including 13 RCE Flaws

Hackread • 23 hours ago

Microsoft’s August Patch Tuesday fixes 107 vulnerabilities, including 13 critical RCE flaws, impacting Windows, Office, Azure, and more,…

Score
63
100.0% similarity
Read more
5

Microsoft patches some very important vulnerabilities in August’s patch Tuesday

Malwarebytes Labs • 6 hours ago

In the August 2025 patch Tuesday round Microsoft fixed a total of 111 Microsoft vulnerabilities, some of which are very important.

Score
60
100.0% similarity
Read more
6
Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws

Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws

BleepingComputer • 1 day ago

Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws Lawrence Abrams August 12, 2025 01:43 PM 2 Today is Microsoft's August 2025 Patch Tuesday, which includes security updates for 107 flaws, including one publicly disclosed zero-day vulnerability in Windows Kerberos. This Patch Tuesday also fixes thirteen "Critical" vulnerabilities, nine of which are remote code execution vulnerabilities, three are information disclosure, and one is elevation of privileges. The number of bugs in eac

Score
54
95.0% similarity
Read more
7

Microsoft Patch Tuesday August 2025: 107 Vulnerabilities Patched, Including 35 RCE Flaws

GB Hackers • 1 day ago

Microsoft has rolled out its August 2025 Patch Tuesday fixes, addressing a total of 107 vulnerabilities across its ecosystem. This month’s release stands out for its sheer volume and the inclusion of 35 remote code execution (RCE) bugs, which could allow attackers to run malicious code on affected systems. While none of these vulnerabilities are currently known to be exploited in the wild, the patches underscore the ongoing battle against evolving cyber threats. The Microsoft securityupdatesspan

Score
54
96.0% similarity
Read more
8
Elevation-of-Privilege Vulns Dominate Microsoft's Patch Tuesday

Elevation-of-Privilege Vulns Dominate Microsoft's Patch Tuesday

Dark Reading • 1 day ago

Application Security Vulnerabilities & Threats Threat Intelligence News Elevation-of-Privilege Vulns Dominate Microsoft's Patch TuesdayElevation-of-Privilege Vulns Dominate Microsoft's Patch TuesdayElevation-of-Privilege Vulns Dominate Microsoft's Patch Tuesday The company's August security update consisted of patches for 111 unique Common Vulnerabilities and Exposures (CVEs). August 12, 2025 The biggest concern for security teams in Microsoft's August 2025 patch update — the second consecutive

Score
52
100.0% similarity
Read more
9
Microsoft Patch Tuesday, August 2025 Edition

Microsoft Patch Tuesday, August 2025 Edition

Krebs on Security • 1 day ago

Microsofttoday released updates to fix more than 100 security flaws in itsWindowsoperating systems and other software. At least 13 of the bugs received Microsoft’s most-dire “critical” rating, meaning they could be abused by malware or malcontents to gain remote access to a Windows system with little or no help from users. August’s patch batch from Redmond includes an update forCVE-2025-53786, a vulnerability that allows an attacker to pivot from a compromisedMicrosoft Exchange Serverdirectly in

Score
50
100.0% similarity
Read more
10

Microsoft August 2025 Patch Tuesday, (Tue, Aug 12th)

ISC SANS • 1 day ago

Microsoft August 2025 Patch Tuesday This month's Microsoft patch update addresses a total of 111 vulnerabilities, with 17 classified as critical. Among these, one vulnerability was disclosed prior to the patch release, marking it as a zero-day. While none of the vulnerabilities have been exploited in the wild, the critical ones pose significant risks, including remote code execution and elevation of privilege. Users are strongly advised to apply the updates promptly to safeguard their systems ag

Score
50
92.0% similarity
Read more
11

Eight critical RCE flaws make Microsoft’s latest Patch Tuesday list

Computer Weekly IT Security • 1 day ago

No fewer than eight critical flaws that could allow a threat actor to achieve remote code execution (RCE) on a targeted system are listed in Microsoft’s August Patch Tuesday update , which once again tops out at over 100 common vulnerabilities and exposures (CVEs). GPT.display('halfpage') GPT.display('mu-1') Alongside the critical RCE bugs , which occur in a variety of Microsoft products and services including DirectX Graphics Kernel, GDI+, Hyper-V, Message Queuing, Office and Word, are a solita

Score
50
100.0% similarity
Read more
12

August Patch Tuesday: Microsoft addressing 111 vulnerabilities

Security Brief UK • 21 hours ago

August Patch Tuesday: Microsoft addressing 111 vulnerabilities Microsoft is addressing 111 vulnerabilities thisAugust 2025 Patch Tuesday, a volume which is around the recent average. In a neat parallel with last month, Microsoft is aware of public disclosure for a single one of the vulnerabilities published today, and claims no evidence of in-the-wild exploitation. Once again, the lone Patch Tuesday zero-day vulnerability is assessed as only moderate severity at time of publication, which brings

Score
50
100.0% similarity
Read more
13

Microsoft’s August 2025 Patch Tuesday Addresses 107 CVEs (CVE-2025-53779)

Tenable • 1 day ago

13 Critical 91 Important 2 Moderate 1 Low Microsoft addresses 107 CVEs, including one zero-day vulnerability that was publicly disclosed. Microsoft patched 107 CVEs in its August 2025 Patch Tuesday release, with 13 rated critical, 91 rated as important, one rated as moderate and one rated as low. This month’s update includes patches for: Azure File Sync Azure OpenAI Azure Portal Azure Stack Azure Virtual Machines Desktop Windows Manager GitHub Copilot and Visual Studio Graphics Kernel Kernel Str

Score
50
94.0% similarity
Read more
14
Microsoft Vulnerabilities Exposed by Check Point Research

Microsoft Vulnerabilities Exposed by Check Point Research

Check Point Blog • 1 day ago

Check Point Research uncovered six fresh vulnerabilities in Microsoft Windows, including one critical flaw with potential for wide-reaching impact. These weaknesses could trigger system crashes, enable arbitrary code execution, or expose sensitive data across networks. Following a responsible disclosure process, Check Point privately reported these issues to Microsoft, with the final patch delivered on August 12 Patch Tuesday. Check Point customers are already protected—our security solutions ac

Score
49
100.0% similarity
Read more
15

Microsoft Patch Tuesday August 2025 Released – 107 Vulnerabilities Fixed Including 36 RCE

Cybersecurity News • 1 day ago

Microsoft released its August Patch Tuesday security updates, addressing a total of 107 vulnerabilities across its product ecosystem. The update includes fixes for 90 vulnerabilities, classified as follows: 13 are Critical, 76 are Important, one is Moderate, and one is Low. Notably, none of these vulnerabilities are listed as actively exploited zero-days, which provides some […]

Score
49
93.0% similarity
Read more
16

Critical Patches Issued for Microsoft Products, August 12, 2025

CIS Security Advisories • 1 day ago

Critical Patches Issued for Microsoft Products, August 12, 2025 MS-ISAC ADVISORY NUMBER: DATE(S) ISSUED: OVERVIEW: Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have

Score
48
100.0% similarity
Read more
17

Microsoft Patches Over 100 Vulnerabilities

SecurityWeek • 18 hours ago

Microsoft’s August 2025 Patch Tuesday updates address critical vulnerabilities in Windows, Office, and Hyper-V.

Score
46
100.0% similarity
Read more
18

Patch Tuesday August 2025: 9 High-Risk Vulnerabilities Fixed by Microsoft

The Cyber Express • 1 day ago

Microsoft’s Patch Tuesday update for August 2025 includes fixes for 110 Microsoft vulnerabilities, including nine at higher risk for exploitation and an additional five vulnerabilities carrying 9+ severity ratings. The update, down from 130 vulnerabilities in July’s update , also included eight Chrome vulnerabilities in the Chromium-based Microsoft Edge. Highest-Rated Vulnerabilities: Fixed or at Lower Risk The highest-rated vulnerability – CVE-2025-53767 , a 10.0-severity Azure OpenAI Elevation

Score
44
100.0% similarity
Read more

Save to Folder

Choose a folder to save this cluster:

Cluster Intelligence

Key entities and indicators for this cluster

INDUSTRIES
Healthcare
Technology
Cloud Services
Cybersecurity
Information Technology
MITRE ATT&CK
T1548.001
T1068
T1071
T1210
T1203
ATTACK TYPES
Privilege Escalation
Elevation of Privilege
Remote Code Execution
PLATFORMS
Office
Exchange
Exchange Server
Azure
Microsoft Office
COMPANIES
NHS Digital
Immersive
Check Point
VULNERABILITIES
Privilege Escalation
Elevation of Privilege
Information Disclosure
Remote Code Execution
CVES
CVE-2025-53781
CVE-2025-53786
CVE-2025-53767
CVE-2025-53779
CVE-2025-50165
AGENCIES
CISA
SECURITY VENDORS
Tenable
CLUSTER INFORMATION
Cluster #1874
Created 1 day ago
Semantic Algorithm

We use cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.

Cookie Settings

Essential Cookies

Required for the website to function. Cannot be disabled.

  • Session management and authentication
  • Security and fraud prevention
  • Cookie consent preferences

Analytics Cookies

Help us understand how visitors interact with our website.

  • Plausible Analytics - Privacy-focused usage statistics
  • PostHog - Product analytics and feature tracking
  • Page views and user journey analysis

Performance Cookies

Help us monitor and improve website performance.

  • Page load time monitoring
  • Error tracking and debugging
  • Performance optimisation

Marketing Cookies

Used to track visitors across websites for marketing purposes.

  • Conversion tracking
  • Remarketing campaigns
  • Social media integration