Sierpniowy Patch Tuesday firmy Microsoft z 2025 r. zawiera aktualizacje zabezpieczeń dla 107 luk, w tym jedną publicznie ujawnioną lukę typu zero-day w systemie Windows Kerberos.
Ten Patch Tuesday naprawia również trzynaście luk „krytycznych”, z których dziewięć to luki umożliwiające zdalne wykonanie kodu, trzy to ujawnienie informacji, a jedna to podniesienie uprawnień.
Liczba błędów w każdej kategorii luk jest wymieniona poniżej:
• 44 luki umożliwiające podniesienie uprawnień
• 35 luk umożliwiających zdalne wykonanie kodu
• 18 luk umożliwiających ujawnienie informacji
• 4 luki umożliwiające odmowę usługi (DMS)
• 9 luk umożliwiających podszywanie się
Tag | CVE ID | Tytuł CVE | Krytyczność |
Azure File Sync | CVE-2025-53729 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | Wysoka |
Azure Stack | CVE-2025-53793 | Azure Stack Hub Information Disclosure Vulnerability | Krytyczna |
Azure Stack | CVE-2025-53765 | Azure Stack Hub Information Disclosure Vulnerability | Wysoka |
Azure Virtual Machines | CVE-2025-49707 | Azure Virtual Machines Spoofing Vulnerability | Krytyczna |
Azure Virtual Machines | CVE-2025-53781 | Azure Virtual Machines Information Disclosure Vulnerability | Krytyczna |
Desktop Windows Manager | CVE-2025-53152 | Desktop Windows Manager Remote Code Execution Vulnerability | Wysoka |
Desktop Windows Manager | CVE-2025-50153 | Desktop Windows Manager Elevation of Privilege Vulnerability | Wysoka |
GitHub Copilot and Visual Studio | CVE-2025-53773 | GitHub Copilot and Visual Studio Remote Code Execution Vulnerability | Wysoka |
Graphics Kernel | CVE-2025-50176 | DirectX Graphics Kernel Remote Code Execution Vulnerability | Krytyczna |
Kernel Streaming WOW Thunk Service Driver | CVE-2025-53149 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Wysoka |
Kernel Transaction Manager | CVE-2025-53140 | Windows Kernel Transaction Manager Elevation of Privilege Vulnerability | Wysoka |
Microsoft Brokering File System | CVE-2025-53142 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Wysoka |
Microsoft Dynamics 365 (on-premises) | CVE-2025-49745 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Wysoka |
Microsoft Dynamics 365 (on-premises) | CVE-2025-53728 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | Wysoka |
Microsoft Edge for Android | CVE-2025-49755 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | Niska |
Microsoft Edge for Android | CVE-2025-49736 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | Średnia |
Microsoft Exchange Server | CVE-2025-25005 | Microsoft Exchange Server Tampering Vulnerability | Wysoka |
Microsoft Exchange Server | CVE-2025-25006 | Microsoft Exchange Server Spoofing Vulnerability | Wysoka |
Microsoft Exchange Server | CVE-2025-25007 | Microsoft Exchange Server Spoofing Vulnerability | Wysoka |
Microsoft Exchange Server | CVE-2025-53786 | Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability | Wysoka |
Microsoft Exchange Server | CVE-2025-33051 | Microsoft Exchange Server Information Disclosure Vulnerability | Wysoka |
Microsoft Graphics Component | CVE-2025-49743 | Windows Graphics Component Elevation of Privilege Vulnerability | Wysoka |
Microsoft Graphics Component | CVE-2025-50165 | Windows Graphics Component Remote Code Execution Vulnerability | Krytyczna |
Microsoft Office | CVE-2025-53732 | Microsoft Office Remote Code Execution Vulnerability | Wysoka |
Microsoft Office | CVE-2025-53740 | Microsoft Office Remote Code Execution Vulnerability | Krytyczna |
Microsoft Office | CVE-2025-53731 | Microsoft Office Remote Code Execution Vulnerability | Krytyczna |
Microsoft Office Excel | CVE-2025-53759 | Microsoft Excel Remote Code Execution Vulnerability | Wysoka |
Microsoft Office Excel | CVE-2025-53737 | Microsoft Excel Remote Code Execution Vulnerability | Wysoka |
Microsoft Office Excel | CVE-2025-53739 | Microsoft Excel Remote Code Execution Vulnerability | Wysoka |
Microsoft Office Excel | CVE-2025-53735 | Microsoft Excel Remote Code Execution Vulnerability | Wysoka |
Microsoft Office Excel | CVE-2025-53741 | Microsoft Excel Remote Code Execution Vulnerability | Wysoka |
Microsoft Office PowerPoint | CVE-2025-53761 | Microsoft PowerPoint Remote Code Execution Vulnerability | Wysoka |
Microsoft Office SharePoint | CVE-2025-53760 | Microsoft SharePoint Elevation of Privilege Vulnerability | Wysoka |
Microsoft Office SharePoint | CVE-2025-49712 | Microsoft SharePoint Remote Code Execution Vulnerability | Wysoka |
Microsoft Office Visio | CVE-2025-53730 | Microsoft Office Visio Remote Code Execution Vulnerability | Wysoka |
Microsoft Office Visio | CVE-2025-53734 | Microsoft Office Visio Remote Code Execution Vulnerability | Wysoka |
Microsoft Office Word | CVE-2025-53738 | Microsoft Word Remote Code Execution Vulnerability | Wysoka |
Microsoft Office Word | CVE-2025-53736 | Microsoft Word Information Disclosure Vulnerability | Wysoka |
Microsoft Office Word | CVE-2025-53784 | Microsoft Word Remote Code Execution Vulnerability | Krytyczna |
Microsoft Office Word | CVE-2025-53733 | Microsoft Word Remote Code Execution Vulnerability | Krytyczna |
Microsoft Teams | CVE-2025-53783 | Microsoft Teams Remote Code Execution Vulnerability | Wysoka |
Remote Access Point-to-Point Protocol (PPP) EAP-TLS | CVE-2025-50159 | Remote Access Point-to-Point Protocol (PPP) EAP-TLS Elevation of Privilege Vulnerability | Wysoka |
Remote Desktop Server | CVE-2025-50171 | Remote Desktop Spoofing Vulnerability | Wysoka |
Role: Windows Hyper-V | CVE-2025-50167 | Windows Hyper-V Elevation of Privilege Vulnerability | Wysoka |
Role: Windows Hyper-V | CVE-2025-53155 | Windows Hyper-V Elevation of Privilege Vulnerability | Wysoka |
Role: Windows Hyper-V | CVE-2025-49751 | Windows Hyper-V Denial of Service Vulnerability | Wysoka |
Role: Windows Hyper-V | CVE-2025-53723 | Windows Hyper-V Elevation of Privilege Vulnerability | Wysoka |
Role: Windows Hyper-V | CVE-2025-48807 | Windows Hyper-V Remote Code Execution Vulnerability | Krytyczna |
SQL Server | CVE-2025-49758 | Microsoft SQL Server Elevation of Privilege Vulnerability | Wysoka |
SQL Server | CVE-2025-24999 | Microsoft SQL Server Elevation of Privilege Vulnerability | Wysoka |
SQL Server | CVE-2025-53727 | Microsoft SQL Server Elevation of Privilege Vulnerability | Wysoka |
SQL Server | CVE-2025-49759 | Microsoft SQL Server Elevation of Privilege Vulnerability | Wysoka |
SQL Server | CVE-2025-47954 | Microsoft SQL Server Elevation of Privilege Vulnerability | Wysoka |
Storage Port Driver | CVE-2025-53156 | Windows Storage Port Driver Information Disclosure Vulnerability | Wysoka |
Web Deploy | CVE-2025-53772 | Web Deploy Remote Code Execution Vulnerability | Wysoka |
Windows Ancillary Function Driver for WinSock | CVE-2025-53718 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Wysoka |
Windows Ancillary Function Driver for WinSock | CVE-2025-53134 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Wysoka |
Windows Ancillary Function Driver for WinSock | CVE-2025-49762 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Wysoka |
Windows Ancillary Function Driver for WinSock | CVE-2025-53147 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Wysoka |
Windows Ancillary Function Driver for WinSock | CVE-2025-53154 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Wysoka |
Windows Ancillary Function Driver for WinSock | CVE-2025-53137 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Wysoka |
Windows Ancillary Function Driver for WinSock | CVE-2025-53141 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Wysoka |
Windows Cloud Files Mini Filter Driver | CVE-2025-50170 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Wysoka |
Windows Connected Devices Platform Service | CVE-2025-53721 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | Wysoka |
Windows DirectX | CVE-2025-53135 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | Wysoka |
Windows DirectX | CVE-2025-50172 | DirectX Graphics Kernel Denial of Service Vulnerability | Wysoka |
Windows Distributed Transaction Coordinator | CVE-2025-50166 | Windows Distributed Transaction Coordinator (MSDTC) Information Disclosure Vulnerability | Wysoka |
Windows File Explorer | CVE-2025-50154 | Microsoft Windows File Explorer Spoofing Vulnerability | Wysoka |
Windows GDI+ | CVE-2025-53766 | GDI+ Remote Code Execution Vulnerability | Krytyczna |
Windows Installer | CVE-2025-50173 | Windows Installer Elevation of Privilege Vulnerability | Wysoka |
Windows Kerberos | CVE-2025-53779 | Windows Kerberos Elevation of Privilege Vulnerability | Średnia |
Windows Kernel | CVE-2025-49761 | Windows Kernel Elevation of Privilege Vulnerability | Wysoka |
Windows Kernel | CVE-2025-53151 | Windows Kernel Elevation of Privilege Vulnerability | Wysoka |
Windows Local Security Authority Subsystem Service (LSASS) | CVE-2025-53716 | Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | Wysoka |
Windows Media | CVE-2025-53131 | Windows Media Remote Code Execution Vulnerability | Wysoka |
Windows Message Queuing | CVE-2025-53145 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Wysoka |
Windows Message Queuing | CVE-2025-53143 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Wysoka |
Windows Message Queuing | CVE-2025-50177 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Krytyczna |
Windows Message Queuing | CVE-2025-53144 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Wysoka |
Windows NT OS Kernel | CVE-2025-53136 | NT OS Kernel Information Disclosure Vulnerability | Wysoka |
Windows NTFS | CVE-2025-50158 | Windows NTFS Information Disclosure Vulnerability | Wysoka |
Windows NTLM | CVE-2025-53778 | Windows NTLM Elevation of Privilege Vulnerability | Krytyczna |
Windows PrintWorkflowUserSvc | CVE-2025-53133 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Wysoka |
Windows Push Notifications | CVE-2025-53725 | Windows Push Notifications Apps Elevation of Privilege Vulnerability | Wysoka |
Windows Push Notifications | CVE-2025-53724 | Windows Push Notifications Apps Elevation of Privilege Vulnerability | Wysoka |
Windows Push Notifications | CVE-2025-50155 | Windows Push Notifications Apps Elevation of Privilege Vulnerability | Wysoka |
Windows Push Notifications | CVE-2025-53726 | Windows Push Notifications Apps Elevation of Privilege Vulnerability | Wysoka |
Windows Remote Desktop Services | CVE-2025-53722 | Windows Remote Desktop Services Denial of Service Vulnerability | Wysoka |
Windows Routing and Remote Access Service (RRAS) | CVE-2025-50157 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Wysoka |
Windows Routing and Remote Access Service (RRAS) | CVE-2025-53153 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Wysoka |
Windows Routing and Remote Access Service (RRAS) | CVE-2025-50163 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Wysoka |
Windows Routing and Remote Access Service (RRAS) | CVE-2025-50162 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Wysoka |
Windows Routing and Remote Access Service (RRAS) | CVE-2025-50164 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Wysoka |
Windows Routing and Remote Access Service (RRAS) | CVE-2025-53148 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Wysoka |
Windows Routing and Remote Access Service (RRAS) | CVE-2025-53138 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Wysoka |
Windows Routing and Remote Access Service (RRAS) | CVE-2025-50156 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Wysoka |
Windows Routing and Remote Access Service (RRAS) | CVE-2025-49757 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Wysoka |
Windows Routing and Remote Access Service (RRAS) | CVE-2025-53719 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Wysoka |
Windows Routing and Remote Access Service (RRAS) | CVE-2025-53720 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Wysoka |
Windows Routing and Remote Access Service (RRAS) | CVE-2025-50160 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Wysoka |
Windows Security App | CVE-2025-53769 | Windows Security App Spoofing Vulnerability | Wysoka |
Windows SMB | CVE-2025-50169 | Windows SMB Remote Code Execution Vulnerability | Wysoka |
Windows StateRepository API | CVE-2025-53789 | Windows StateRepository API Server file Elevation of Privilege Vulnerability | Wysoka |
Windows Subsystem for Linux | CVE-2025-53788 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | Wysoka |
Windows Win32K – GRFX | CVE-2025-50161 | Win32k Elevation of Privilege Vulnerability | Wysoka |
Windows Win32K – GRFX | CVE-2025-53132 | Win32k Elevation of Privilege Vulnerability | Wysoka |
Windows Win32K – ICOMP | CVE-2025-50168 | Win32k Elevation of Privilege Vulnerability | Wysoka |