Microsoft Monthly Security Update (July 2025)

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
WindowsMedium Risk Medium RiskInformation Disclosure
Spoofing
Elevation of Privilege
Remote Code Execution
Denial of Service
Data Manipulation
Security Restriction Bypass
 
AzureMedium Risk Medium RiskElevation of Privilege
Remote Code Execution
 
Extended Security Updates (ESU)Medium Risk Medium RiskElevation of Privilege
Information Disclosure
Remote Code Execution
Denial of Service
Security Restriction Bypass
 
Microsoft OfficeExtremely High Risk Extremely High RiskElevation of Privilege
Information Disclosure
Remote Code Execution
Security Restriction Bypass
Spoofing

CVE-2025-53770 is being exploited in the wild. An unauthorised attacker who successfully committed deserialization of untrusted data can initiate remote code execution in on-premises Microsoft SharePoint Server.

 

CVE-2025-53771 is being exploited in the wild. An authorised attacker can exploit this vulnerability to trigger spoofing due to improper limitation of a pathname to a restricted directory.

SQL ServerMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 
Developer ToolsMedium Risk Medium RiskRemote Code Execution
Elevation of Privilege
 
System CenterMedium Risk Medium RiskRemote Code Execution 
BrowserMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 
AppsMedium Risk Medium RiskElevation of Privilege 

 

Number of ‘Extremely High Risk’ product(s): 1

Number of ‘High Risk’ product(s): 0

Number of ‘Medium Risk’ product(s): 8

Number of ‘Low Risk’ product(s): 0

Evaluation of overall ‘Risk Level’: Extremely High Risk

 

[Updated on 2025-07-21]

Updated Description, Risk Level, Solutions and Related Links.

 

[Updated on 2025-07-22]

Updated Solutions.

RISK: Extremely High Risk

TYPE: Operating Systems – Windows OS

TYPE: Windows OS

Impact

  • Remote Code Execution
  • Elevation of Privilege
  • Information Disclosure
  • Denial of Service
  • Security Restriction Bypass
  • Spoofing
  • Data Manipulation

System / Technologies affected

  • Windows
  • Azure
  • Extended Security Updates (ESU)
  • Microsoft Office
  • SQL Server
  • Developer Tools
  • System Center
  • Browser
  • Apps

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

For CVE-2025-53770 and CVE-2025-53771 :


Vulnerability Identifier


Source


Related Link

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.