Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Microsoft Patches ‘Wormable’ Critical Flaw, Discloses ‘Whopping’ Number Of Bug Fixes

CRN by CRN
July 8, 2025
Home News
Share on FacebookShare on Twitter


The 130 CVEs (Common Vulnerabilities and Exposures) disclosed in Microsoft’s monthly release of security fixes includes a remote code execution flaw that ‘definitely’ should be prioritized for patching, writes Trend Micro’s Dustin Childs.

The huge quantity of CVEs (Common Vulnerabilities and Exposures) disclosed by Microsoft Tuesday includes a critical-severity remote code execution flaw that should be given a high priority for patching, according to a Trend Micro researcher.

The flaws received patches as part of Microsoft’s monthly release of software bug fixes, unofficially known as “Patch Tuesday.”

[Related: 5 Things To Know On The SafePay Ransomware Group]

Microsoft released fixes for a total of 130 CVEs on Tuesday, a “whopping” number of patches for a single month, wrote Dustin Childs, head of threat awareness for Trend Micro’s Zero Day Initiative, in a blog post.

As usual, the patches address vulnerabilities that affect numerous Microsoft product categories including Windows, Office, Azure, .NET, Visual Studio, Windows BitLocker, Windows Hyper-V and Microsoft Edge.

Among the highest-risk flaws is a Windows remote code execution vulnerability (tracked at CVE-2025-47981) that “many will be talking about” in the security community for a number of reasons, Childs wrote in the post.

That’s because the flaw “allows remote, unauthenticated attackers to execute code simply by sending a malicious message to an affected system,” he wrote. “Since there’s no user interaction, and since the code executes with elevated privileges, this bug falls into the wormable class of bugs.”

Additionally, Microsoft “gives this [flaw] its highest exploitability index rating, which means they expect attacks within 30 days,” Childs wrote. “Definitely test and deploy these patches quickly.”

The vulnerability has received a severity rating of 9.8 out of 10.0.

In total, 10 of the newly disclosed vulnerabilities patched in the software updates Tuesday are rated as “critical” issues in terms of severity, he noted.

Other critical vulnerabilities disclosed Tuesday include remote code execution flaws affecting Microsoft Office, SharePoint and SQL Server.

Those flaws include a SharePoint remote code execution vulnerability (tracked at CVE-2025-49704) with a severity rating of 8.8 of out 10.0, as well as a SQL Server remote code execution vulnerability (tracked at CVE-2025-49717) with a severity rating of 8.5 out of 10.0.



Source link

Tags: CybersecurityVulnerabilities
CRN

CRN

Next Post
20 Tech Companies Hiring In The IT Channel: July 2025

20 Tech Companies Hiring In The IT Channel: July 2025

Recommended.

HPE CEO Antonio Neri On Layoffs, Tariffs And ‘Massive Opportunities’ With Private Cloud AI, Gen12, Alletra MP

HPE CEO Antonio Neri On Layoffs, Tariffs And ‘Massive Opportunities’ With Private Cloud AI, Gen12, Alletra MP

March 7, 2025
TNL Mediagene Announces Conclusion of GIZMART’s Debut Project “Keychron Nape Pro,” Surpassing ¥300 Million in GMV

TNL Mediagene Announces Conclusion of GIZMART’s Debut Project “Keychron Nape Pro,” Surpassing ¥300 Million in GMV

January 13, 2026

Trending.

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

March 10, 2026
Huawei lanceert Next Generation FAN-oplossing

Huawei lanceert Next Generation FAN-oplossing

March 7, 2026
Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

February 26, 2026
Half of Google’s software development now AI-generated | Computer Weekly

Half of Google’s software development now AI-generated | Computer Weekly

February 5, 2026
Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

March 24, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio