Facefam ArticlesFacefam Articles
  • webmaster
    • How to
    • Developers
    • Hosting
    • monetization
    • Reports
  • Technology
    • Software
  • Downloads
    • Windows
    • android
    • PHP Scripts
    • CMS
  • REVIEWS
  • Donate
  • Join Facefam
Search

Archives

  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • January 2025
  • December 2024
  • November 2024

Categories

  • Advertiser
  • AI
  • android
  • betting
  • Bongo
  • Business
  • CMS
  • cryptocurrency
  • Developers
  • Development
  • Downloads
  • Entertainment
  • Entrepreneur
  • Finacial
  • General
  • Hosting
  • How to
  • insuarance
  • Internet
  • Kenya
  • monetization
  • Music
  • News
  • Phones
  • PHP Scripts
  • Reports
  • REVIEWS
  • RUSSIA
  • Software
  • Technology
  • Tips
  • Tragic
  • Ukraine
  • Uncategorized
  • USA
  • webmaster
  • webmaster
  • Windows
  • Women Empowerment
  • Wordpress
  • Wp Plugins
  • Wp themes
Facefam 2025
Notification Show More
Font ResizerAa
Facefam ArticlesFacefam Articles
Font ResizerAa
  • Submit a Post
  • Donate
  • Join Facefam social
Search
  • webmaster
    • How to
    • Developers
    • Hosting
    • monetization
    • Reports
  • Technology
    • Software
  • Downloads
    • Windows
    • android
    • PHP Scripts
    • CMS
  • REVIEWS
  • Donate
  • Join Facefam
Have an existing account? Sign In
Follow US
Technologywebmaster

Microsoft’s Patch Tuesday: 100+ Updates

Ronald Kenyatta
Last updated: August 13, 2025 7:54 pm
By
Ronald Kenyatta
ByRonald Kenyatta
Follow:
Share
5 Min Read
SHARE

Contents
1 ManageEngine Log360Memory corruption flaw deemed ‘extremely high-risk’More Microsoft newsMicrosoft closes Azure OpenAI elevation of privilege riskAdditional vulnerabilities Microsoft addressed this Patch TuesdayPatch Tuesday reminder and upcoming Windows 10 changes
Visualization of cyber attacks.
Image: CROCOTHERY/Adobe Stock

Microsoft on Aug. 12 released security updates addressing more than 100 vulnerabilities across its products, including 13 rated critical. The patches include fixes for a graphics component flaw described as “extremely high-risk” and a maximum-severity vulnerability in Azure’s OpenAI service.

“This month’s release highlights an upward trend in post-compromise vulnerabilities over code execution bugs,” wrote Satnam Narang, senior staff research engineer, Tenable, in an email to TechRepublic. “For the second consecutive month, elevation of privilege vulnerabilities represented the bulk of CVEs patched this month at 39.3% (41.4% in July).”

1
ManageEngine Log360

Employees per Company Size

Micro (0-49), Small (50-249), Medium (250-999), Large (1,000-4,999), Enterprise (5,000+)

Micro (0-49 Employees), Small (50-249 Employees), Medium (250-999 Employees), Large (1,000-4,999 Employees), Enterprise (5,000+ Employees)
Micro, Small, Medium, Large, Enterprise

Features

Activity Monitoring, Blacklisting, Dashboard, and more

Memory corruption flaw deemed ‘extremely high-risk’

Major vulnerabilities that Microsoft patched for this month include CVE-2025-50165. Action1 CEO and co-founder Alex Vovk called it “extremely high-risk.”

In an email to TechRepublic, Vovk said, “This is a particularly dangerous memory corruption vulnerability because it occurs at a core level of the operating system’s image processing pipeline, impacting many applications and services.”

CVE-2025-50165 affects the Microsoft Graphics Component, with an untrusted pointer dereference potentially allowing an attacker to execute code over the network. While Microsoft says exploitation of this vulnerability is “less likely,” Vovk said the CVSS score of 9.8 and “a perfect storm of attack conditions (network vector, low complexity, no privileges, and no user interaction required)” make this a high-priority vulnerability.

“This is a particularly dangerous memory corruption vulnerability because it occurs at a core level of the operating system’s image processing pipeline, impacting many applications and services,” said Vovk.

Ben McCarthy, lead cybersecurity engineer at Immersive, also highlighted this vulnerability.

“The attack vector is incredibly broad, as the vulnerability is triggered when the operating system processes a specially crafted JPEG image,” McCarthy said in an email to TechRepublic. “This means any application that renders images — from email clients generating previews and instant messaging apps displaying photos, to office documents with embedded pictures — can become an in for the attack.”

More Microsoft news

Microsoft closes Azure OpenAI elevation of privilege risk

Another vulnerability patched this month, CVE-2025-53767, is an elevation of privilege vulnerability in Azure’s OpenAI service with a maximum CVSS score of 10.

“Since its Azure OpenAI, end customers don’t have to take any action as Microsoft will have tackled the vulnerability on the Azure platform, but it’s an interesting note that highlights how AI technologies still require close monitoring, careful patching, and strong guardrails just like any other technology in an organization’s stack,” wrote Nick Carroll, cyber incident response manager at intelligence solutions house Nightwing, in an email to TechRepublic.

Additional vulnerabilities Microsoft addressed this Patch Tuesday

Other notable vulnerabilities patched this month include:

  • CVE-2025-53766: A Heap-based buffer overflow in Windows GDI+, with a CVSS score of 9.8 and no user interaction required to use it.
  • CVE-2025-53740 and CVE-2025-53731: Two use-after-free vulnerabilities in Microsoft Office.
  • CVE-2025-53784: A use-after-free vulnerability in Microsoft Word that could let an attacker run code as the current user.
  • CVE-2025-53733: A critical vulnerability in Microsoft Word that could lead to arbitrary code execution.
  • CVE-2025-53786: A vulnerability in Microsoft Exchange Server that requires installing a hotfix manually.
  • CVE-2025-53778: An elevation of privilege flaw in Windows NTLM.

Patch Tuesday reminder and upcoming Windows 10 changes

Patch Tuesday is a critical opportunity for organizations to verify they have applied all relevant updates to Microsoft products. Other vendors, including SAP and CISA, also released security advisories or patches on the second Tuesday of August.

Windows 10 will no longer receive free security updates after the upcoming Patch Tuesday on October 14. Users can either migrate to newer versions or enroll in Microsoft’s Extended Security Updates program to maintain protection.

In other security news, an exploit based on a flaw in WinRAR has been attributed to two Russia-linked threat groups.

TAGGED:MicrosoftsPatchTuesdayUpdates
Share This Article
Facebook Whatsapp Whatsapp Email Copy Link Print
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Reverse AI Agent Mistakes With Rubrik's Agent Rewind Reverse AI Agent Mistakes With Rubrik’s Agent Rewind
Next Article OpenAI's GPT-5 Touts Medical Benchmarks and Mental Health Guidelines GPT-4o Back as Default After Outcry
Leave a review

Leave a Review Cancel reply

Your email address will not be published. Required fields are marked *

Please select a rating!

Meta Strikes $10 Billion Cloud Deal With Google to Boost AI Capacity
NVIDIA CEO Dismisses Chip Security Allegations as China Orders Firms to Halt Purchases
Anthropic Folds Claude Code Into Business Plans With Governance Tools
Google Claims One Gemini AI Prompt Uses Five Drops of Water
Generate AI Business Infographics without the Fees

Recent Posts

  • Meta Strikes $10 Billion Cloud Deal With Google to Boost AI Capacity
  • NVIDIA CEO Dismisses Chip Security Allegations as China Orders Firms to Halt Purchases
  • Anthropic Folds Claude Code Into Business Plans With Governance Tools
  • Google Claims One Gemini AI Prompt Uses Five Drops of Water
  • Generate AI Business Infographics without the Fees

Recent Comments

  1. https://tubemp4.ru on Best Features of PHPFox Social Network Script
  2. Вулкан Платинум on Best Features of PHPFox Social Network Script
  3. Вулкан Платинум официальный on Best Features of PHPFox Social Network Script
  4. Best Quality SEO Backlinks on DDoS Attacks Now Key Weapons in Geopolitical Conflicts, NETSCOUT Warns
  5. http://boyarka-inform.com on Comparing Wowonder and ShaunSocial

You Might Also Like

IT Leader’s Guide to the Metaverse

August 21, 2025
State of AI Adoption in Financial Services: A TechRepublic Exclusive
Technologywebmaster

State of AI Adoption in Financial Services: A TechRepublic Exclusive

August 21, 2025
AI Underperforms in Reality, and the Stock Market is Feeling It
Technologywebmaster

AI Underperforms in Reality, and the Stock Market is Feeling It

August 21, 2025
Google Shows Off Pixel 10 Series and Pixel Watch 4
Technologywebmaster

Google Shows Off Pixel 10 Series and Pixel Watch 4

August 21, 2025
NVIDIA & NSF to Build Fully Open AI Models for Science
Technologywebmaster

NVIDIA & NSF to Build Fully Open AI Models for Science

August 20, 2025
Previous Next
Facefam ArticlesFacefam Articles
Facefam Articles 2025
  • Submit a Post
  • Donate
  • Join Facefam social
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Not a member? Sign Up