Search

Microsoft Fixes 67 Security Flaws With June 2025 Security Update, Including Two Zero-Day Vulnerabilities

Microsoft has fixed a zero-day remote code execution vulnerability that was actively exploited.

Turbo Read
Advertisement
Highlights
  • Microsoft has fixed two zero-day security flaws affecting its products
  • One of the flaws was activelty exploited, according to the company
  • Microsoft fixed a second zero-day impacting the Windows SMB client
Microsoft Fixes 67 Security Flaws With June 2025 Security Update, Including Two Zero-Day Vulnerabilities

One of the security flaws patched by Microsoft was actively exploited before it was discovered

Photo Credit: Microsoft

Microsoft has rolled out fixes for several security flaws as part of the June 2025 Patch Tuesday release, including 11 vulnerabilities with a "critical" rating, and 56 others rated as "important". Two of the flaws patched by Microsoft are categorised as zero-day flaws, one of which was actively exploited before the company rolled out a fix. The Redmond company previously fixed multiple security flaws affecting Microsoft Edge, including a zero-day exploit that also affects the Google Chrome browser.

Microsoft Patches Previously Exploited WebDAV Zero-Day Flaw

According to Microsoft's release notes, the June 2025 security updates contain fixes for 67 security flaws impacting various products and services. The firm has fixed 14 flaws that could have led to an escalation of privilege, 26 remote code execution vulnerabilities, and 17 other issues that could have led to information disclosure.

The most notable security flaw detected by Microsoft is the CVE-2025-33053, which impacts an HTTP extension called Web Distributed Authoring and Versioning (WebDAV). Microsoft says that this zero-day security flaw has a CVSS score of 8.8, and that it has been actively exploited, by tricking users into clicking on a malicious URL.

This flaw was detected by Check Point researchers David Driker and Alexandra Gofman, and the cybersecurity firm says a known threat actor known as FruityArmor or Stealth Falcon was using the CVE-2025-33053 vulnerability. The security flaw allowed the hackers to remotely execute code on a target's computer, but making changes to the victim's working directory.

Microsoft has also patched another zero-day security flaw that affects the Windows SMB (Samba) client, and could allow a malicious user to gain elevated (or system) privileges on devices that are connected to the same local network. The issue was caused due to improper access control in the Windows SMB client, according to Microsoft.

Earlier this month, the company rolled out multiple security fixes for the Microsoft Edge browser, which were previously released by the Chromium project. One of these flaws, identified as CVE-2025-5419, is a zero-day security flaw that was exploited before it was patched by Google. Users who are running on the latest stable release (version 137.0.3296.62) should be protected against these security flaws.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Advertisement

Related Stories

Popular Mobile Brands
  1. Saiyaara is All Set to Stream on This OTT Platform in September
  2. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  3. iQOO 15 Tipped to Debut With 7,000mAh Battery and This Snapdragon Chip
  4. India's Indigenous Vikram Microprocessor Showcased at Semicon India 2025
  5. Realme 15T 5G India Launch Today: All You Need to Know
  6. Vivo Launches Y500 in China With a Massive 8,200mAh Battery
  7. Apple Hebbal: First-Ever Apple Store in Bengaluru is Now Open
  1. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  2. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
  3. YouTube Reportedly Cracks Down on Premium Family Plan Sharing With Location-Based Checks
  4. Redmi 15 5G, Redmi 14 Pro 5G Series Prices Dropped During Diwali With Xiaomi Sale
  5. Amazon Great Indian Festival Sale 2025: Deals and Discounts on Samsung Phones, Laptops, and More Teased
  6. El Salvador to Host First Government-Backed Bitcoin Conference in November
  7. OpenAI Shares New Safeguard Plans to Protect Teenagers and Users Facing Emotional Distress
  8. Samsung Galaxy Z TriFold Launch Date Leaked; Said to Debut Alongside Project Moohan XR Headset
  9. Kannappa OTT Release Date is Here: When and Where to Watch Vishnu Manchu-Starrer Film Online
  10. India’s AI Development Needs a Balanced Regulatory Approach, Says Jyotiraditya Scindia
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »