Microsoft Fixes 67 Security Flaws With June 2025 Security Update, Including Two Zero-Day Vulnerabilities

Microsoft has fixed a zero-day remote code execution vulnerability that was actively exploited.

Advertisement
Written by David Delima | Updated: 11 June 2025 16:33 IST
Highlights
  • Microsoft has fixed two zero-day security flaws affecting its products
  • One of the flaws was activelty exploited, according to the company
  • Microsoft fixed a second zero-day impacting the Windows SMB client

One of the security flaws patched by Microsoft was actively exploited before it was discovered

Photo Credit: Microsoft

Microsoft has rolled out fixes for several security flaws as part of the June 2025 Patch Tuesday release, including 11 vulnerabilities with a "critical" rating, and 56 others rated as "important". Two of the flaws patched by Microsoft are categorised as zero-day flaws, one of which was actively exploited before the company rolled out a fix. The Redmond company previously fixed multiple security flaws affecting Microsoft Edge, including a zero-day exploit that also affects the Google Chrome browser.

Microsoft Patches Previously Exploited WebDAV Zero-Day Flaw

According to Microsoft's release notes, the June 2025 security updates contain fixes for 67 security flaws impacting various products and services. The firm has fixed 14 flaws that could have led to an escalation of privilege, 26 remote code execution vulnerabilities, and 17 other issues that could have led to information disclosure.

Advertisement

The most notable security flaw detected by Microsoft is the CVE-2025-33053, which impacts an HTTP extension called Web Distributed Authoring and Versioning (WebDAV). Microsoft says that this zero-day security flaw has a CVSS score of 8.8, and that it has been actively exploited, by tricking users into clicking on a malicious URL.

This flaw was detected by Check Point researchers David Driker and Alexandra Gofman, and the cybersecurity firm says a known threat actor known as FruityArmor or Stealth Falcon was using the CVE-2025-33053 vulnerability. The security flaw allowed the hackers to remotely execute code on a target's computer, but making changes to the victim's working directory.

Advertisement

Microsoft has also patched another zero-day security flaw that affects the Windows SMB (Samba) client, and could allow a malicious user to gain elevated (or system) privileges on devices that are connected to the same local network. The issue was caused due to improper access control in the Windows SMB client, according to Microsoft.

Earlier this month, the company rolled out multiple security fixes for the Microsoft Edge browser, which were previously released by the Chromium project. One of these flaws, identified as CVE-2025-5419, is a zero-day security flaw that was exploited before it was patched by Google. Users who are running on the latest stable release (version 137.0.3296.62) should be protected against these security flaws.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy A57 5G: The Smart Choice for Buyers Seeking More Under Rs. 50,000
  2. Samsung Galaxy Z Fold 8 Ultra Listed on BIS Database, May Launch Soon
  3. Bhooth Bangla OTT Release Date: When and Where to Watch it Online?
  4. Realme P4R 5G Launched in India With an 8,000mAh Battery
  5. Redmi Note 17 Appears on Certification Website Ahead of Anticipated Debut
  6. Xiaomi 17T Goes on Sale in India With 50-Megapixel Leica-Tuned Triple Rear Cameras
  7. Lava Bold N2 5G Goes on Sale in India With 6,000mAh Battery: Price, Offers
  8. Oppo Reno 16 Indian Variant Surfaces on Benchmarking Site Ahead of Debut
  9. Samsung Galaxy S27 Surfaces on GSMA Database With This Model Number
  10. Shift Up Comments on Design of Stellar Blade: Blood Rain's New Protagonist
  1. MiCA Architect Urges EU to Focus on Tokenisation Before DeFi Regulation
  2. Xiaomi 17T Goes on Sale in India With 50-Megapixel Leica-Tuned Triple Rear Cameras: Price, Offers
  3. Lenovo IdeaPad Slim 3 Gen 11 Launched in India With Intel Core Ultra Series 3 Processor, 16GB RAM: Price, Features
  4. Samsung Galaxy S27 Listed on GSMA Database With Model Number Several Months Ahead of Anticipated Release: Report
  5. Bitcoin Drops Below $61,300 as Investors Remain Cautious Ahead of US Inflation Data
  6. Google Rolls Out Gemini 3.5 Live Translate for Real-Time Multilingual Conversations
  7. Resurrection OTT Release: Where to Watch Bi Gan’s Sci-Fi Fantasy Film Online
  8. Bhooth Bangla OTT Release Date Confirmed: When and Where to Watch Akshay Kumar’s Horror-Comedy Online?
  9. Realme P4R 5G Launched in India With 8,000mAh Battery, MediaTek Dimensity 6300 SoC: Price, Features
  10. Meta Reportedly Directed to Offer Free WhatsApp Access to Rival AI Chatbots in the EU
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.