|
|
CVEs have been published or revised in the Security Update Guide
May 10, 2025
These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:
- Title: Chromium: CVE-2025-4050 Out of bounds memory access in DevTools
- Version: 1.1
- Reason for revision: Corrected CVE title. This is an informational change only.
- Originally released: May 1, 2025
- Last updated: May 9, 2025
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2025-4051 Insufficient data validation in DevTools
- Version: 1.1
- Reason for revision: Corrected CVE title. This is an informational change only.
- Originally released: May 1, 2025
- Last updated: May 9, 2025
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2025-4052 Inappropriate implementation in DevTools
- Version: 1.1
- Reason for revision: Corrected CVE title. This is an informational change only.
- Originally released: May 1, 2025
- Last updated: May 9, 2025
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2025-4096 Heap buffer overflow in HTML
- Version: 1.1
- Reason for revision: Corrected CVE title. This is an informational change only.
- Originally released: May 1, 2025
- Last updated: May 9, 2025
- Aggregate CVE severity rating:
- Customer action required: Yes
- Title: Chromium: CVE-2025-4372 Use after free in WebAudio
- Version: 1.0
- Reason for revision: Information published.
- Originally released: May 8, 2025
- Last updated: May 8, 2025
- Aggregate CVE severity rating:
Customer action required: Yes
|
|
https://msrc.microsoft.com/update-guide/releaseNote/2025-May
CVEs have been published or revised in the Security Update Guide
May 17, 2025
These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:
CVE-2025-26629
- Title: Microsoft Office Remote Code Execution Vulnerability
- Version: 1.2
- Reason for revision: To comprehensively address CVE-2025-26629, Microsoft has released May 2025 security updates for all affected versions of Microsoft Office. Customers running any of these versions should ensure that they have the latest build installed. For more information and to verify the build version, see https://learn.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates.
- Originally released: March 11, 2025
- Last updated: May 13, 2025
- Aggregate CVE severity rating: Important
- Customer action required: Yes
- Title: Web Threat Defense (WTD.sys) Denial of Service Vulnerability
- Version: 2.0
- Reason for revision: To comprehensively address CVE-2025-29971, Micrsoft has released HotPatch KB5061258 for Windows 11 Version 24H2 for x64-based Systems and Windows 11 Version 24H2 for ARM64-based Systems. Customers running these versions of Windows and who install the HotPatch updates should install KB5061258 to be protected from this vulnerability.
- Originally released: May 13, 2025
- Last updated: May 16, 2025
- Aggregate CVE severity rating: Important
- Customer action required: Yes
- Title: Microsoft Excel Remote Code Execution Vulnerability
- Version: 2.0
- Reason for revision: Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.
- Originally released: May 13, 2025
- Last updated: May 14, 2025
- Aggregate CVE severity rating: Important
- Customer action required: Yes
- Title: Microsoft Excel Remote Code Execution Vulnerability
- Version: 2.0
- Reason for revision: Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.
- Originally released: May 13, 2025
- Last updated: May 14, 2025
- Aggregate CVE severity rating: Important
- Customer action required: Yes
- Title: Microsoft Excel Remote Code Execution Vulnerability
- Version: 2.0
- Reason for revision: Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.
- Originally released: May 13, 2025
- Last updated: May 14, 2025
- Aggregate CVE severity rating: Important
- Customer action required: Yes
- Title: Microsoft Office Remote Code Execution Vulnerability
- Version: 2.0
- Reason for revision: Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.
- Originally released: May 13, 2025
- Last updated: May 14, 2025
- Aggregate CVE severity rating: Critical
- Customer action required: Yes
- Title: Microsoft Excel Remote Code Execution Vulnerability
- Version: 2.0
- Reason for revision: Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.
- Originally released: May 13, 2025
- Last updated: May 14, 2025
- Aggregate CVE severity rating: Important
- Customer action required: Yes
- Title: Microsoft Excel Remote Code Execution Vulnerability
- Version: 2.0
- Reason for revision: Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.
- Originally released: May 13, 2025
- Last updated: May 14, 2025
- Aggregate CVE severity rating: Important
- Customer action required: Yes
- Title: Microsoft Excel Remote Code Execution Vulnerability
- Version: 2.0
- Reason for revision: Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.
- Originally released: May 13, 2025
- Last updated: May 14, 2025
- Aggregate CVE severity rating: Important
- Customer action required: Yes
- Title: Microsoft Office Remote Code Execution Vulnerability
- Version: 2.0
- Reason for revision: Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.
- Originally released: May 13, 2025
- Last updated: May 14, 2025
- Aggregate CVE severity rating: Critical
- Customer action required: Yes
|
CVEs have been published or revised in the Security Update Guide
May 22, 2025
These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:
- Title: .NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability
- Version: 2.0
- Reason for revision: To comprehensively address CVE-2025-26646, Microsoft has released security updates on May 22, 2025 for Visual Studio 2022 version 17.10 In addition, updates .NET 8.0.313 and .NET 8.0.410 have been released for .NET SDKs 8.0.3xx and 8.0.4xx, respectively. For more information about the .NET updates see [KB5059200](https://support.microsoft.com/en-us/topic/-net-8-0-update-may-22-2025-kb5059200-8ace2b08-2644-454e-a43f-157c60835e49). Microsoft recommends customers install these update to be fully protected from the vulnerability.
- Originally released: May 13, 2025
- Last updated: May 22, 2025
- Aggregate CVE severity rating: Important
Customer action required: Yes
CVEs have been published or revised in the Security Update Guide
May 29, 2025
These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:
- Title: Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
- Version: 1.1
- Reason for revision: Added an FAQ and updated the CVSS score. This is an informational change only.
- Originally released: May 13, 2025
- Last updated: May 14, 2025
- Aggregate CVE severity rating: Critical
Customer action required: Yes
CVEs have been published or revised in the Security Update Guide
May 30, 2025
These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:
- Title: Windows Standards-Based Storage Management Service Denial of Service Vulnerability
- Version: 1.3
- Reason for revision: In the Security Updates table, corrected the Download and Article links for Windows Server 2012 R2 and Windows Server 2012 R2 (Server Core installation). This is an informational change only.
- Originally released: April 8, 2025
- Last updated: May 30, 2025
- Aggregate CVE severity rating: Important
Customer action required: Yes
Reply
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.