Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Microsoft Patch Tuesday Release Fixes ‘Unusual’ Number Of Office Bugs: Researcher

CRN by CRN
May 13, 2025
Home News
Share on FacebookShare on Twitter


While the total number of vulnerabilities addressed in the monthly release of Microsoft security updates is modest, there’s a comparatively high number of Office-related bugs fixed in the release, writes Trend Micro’s Dustin Childs.

While the total number of vulnerabilities fixed in Microsoft’s monthly security updates Tuesday is modest, there’s a comparatively high number of Office-related bugs disclosed in the release, according to a Trend Micro researcher.

Those vulnerabilities include two critical-severity remote code execution flaws, which were addressed as part of Microsoft’s monthly release of software bug fixes, unofficially known as “Patch Tuesday.”

[Related: Microsoft Debuts Security Copilot Agents: Five Big Things To Know]

The tech giant fixed 75 new CVEs (Common Vulnerabilities and Exposures) in the release — 12 of which are rated as critical and five of which have seen exploitation in attacks, according to Microsoft.

As usual, the patches address vulnerabilities that affect numerous Microsoft product segments including Windows, Office, Azure, Hyper-V, Microsoft Defender, .NET, Visual Studio, Nuance PowerScribe and Remote Desktop Gateway Service.

In total, “this number of fixes isn’t unusual for May, but it does put Microsoft ahead of where they were at this point last year in regards to CVEs released,” wrote Dustin Childs, head of threat awareness for Trend Micro’s Zero Day Initiative, in a post Tuesday.

“It’s also unusual to see so many Office-related bugs getting patched in a single month,” Childs wrote. “Perhaps this is a harbinger of attacks we can expect to see later this year.”

CRN has reached out to Microsoft for comment.

The five vulnerabilities that have seen exploitation in attacks so far are all rated as “important” in terms of severity.

The exploited bugs include three privilege elevation CVEs affecting Windows as well as vulnerabilities affecting Windows DWM (Desktop Window Manager) and the Microsoft Scripting Engine.

While neither of the critical vulnerabilities affecting Office have seen exploitation, the potential for the bugs to be exploited for remote execution of code should make them a priority for patching, Childs wrote.

Additionally, “there’s no user interaction required here, so simply receiving a specially crafted file in the Preview Pane would allow for code execution,” he wrote.

Meanwhile, in terms of other code execution vulnerabilities disclosed by Microsoft Tuesday, “we see a plethora of Office-related bugs, including nine for Excel alone,” Childs wrote, though he noted that “these are only the open-and-own variety, and the Preview Pane is not an attack vector.”



Source link

Tags: CyberattacksCybersecurityVulnerabilities
CRN

CRN

Next Post
Mike Rowe Teams Up with PureTalk to Champion Wireless that Stands for Something

Mike Rowe Teams Up with PureTalk to Champion Wireless that Stands for Something

Recommended.

vivo Announces Robotics Lab and Showcases its First Mixed Reality Headset at the Boao Forum 2025

vivo Announces Robotics Lab and Showcases its First Mixed Reality Headset at the Boao Forum 2025

March 25, 2025
Engine Overhaul: dbt Labs Adds New Fusion Engine, AI-Powered Features To Its Data Development Platform

Engine Overhaul: dbt Labs Adds New Fusion Engine, AI-Powered Features To Its Data Development Platform

May 30, 2025

Trending.

VIDIZMO Earns Microsoft Solutions Partner Designations for All Three Areas of Azure, Solidifying its Expertise in Delivering AI Solutions

VIDIZMO Earns Microsoft Solutions Partner Designations for All Three Areas of Azure, Solidifying its Expertise in Delivering AI Solutions

June 28, 2025
Tilson Continues to Perform for Clients; Shares Substantial Progress in Chapter 11 Process

Tilson Continues to Perform for Clients; Shares Substantial Progress in Chapter 11 Process

June 27, 2025
OneClik Malware Targets Energy Sector Using Microsoft ClickOnce and Golang Backdoors

OneClik Malware Targets Energy Sector Using Microsoft ClickOnce and Golang Backdoors

June 27, 2025
DHS Warns Pro-Iranian Hackers Likely to Target U.S. Networks After Iranian Nuclear Strikes

DHS Warns Pro-Iranian Hackers Likely to Target U.S. Networks After Iranian Nuclear Strikes

June 23, 2025
Le nombre d’utilisateurs de la 5G-A atteint les dix millions en Chine : Huawei présente le développement de la 5G-A et la valeur de l’IA basée sur des scénarios

Le nombre d’utilisateurs de la 5G-A atteint les dix millions en Chine : Huawei présente le développement de la 5G-A et la valeur de l’IA basée sur des scénarios

June 27, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio