惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Troy Hunt's Blog
Last Week in AI
Last Week in AI
D
DataBreaches.Net
大猫的无限游戏
大猫的无限游戏
Hugging Face - Blog
Hugging Face - Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Cyberwarzone
Cyberwarzone
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
WordPress大学
WordPress大学
Cisco Talos Blog
Cisco Talos Blog
Latest news
Latest news
月光博客
月光博客
博客园 - 司徒正美
C
CERT Recently Published Vulnerability Notes
L
LangChain Blog
Simon Willison's Weblog
Simon Willison's Weblog
The Register - Security
The Register - Security
T
The Blog of Author Tim Ferriss
V
V2EX
F
Fortinet All Blogs
AWS News Blog
AWS News Blog
T
Tor Project blog
V
Vulnerabilities – Threatpost
C
CXSECURITY Database RSS Feed - CXSecurity.com
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
小众软件
小众软件
L
Lohrmann on Cybersecurity
量子位
F
Full Disclosure
H
Hackread – Cybersecurity News, Data Breaches, AI and More
I
Intezer
NISL@THU
NISL@THU
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Jina AI
Jina AI
Scott Helme
Scott Helme
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
Cybersecurity and Infrastructure Security Agency CISA
C
Cyber Attacks, Cyber Crime and Cyber Security
博客园 - 三生石上(FineUI控件)
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Spread Privacy
Spread Privacy
N
Netflix TechBlog - Medium
P
Proofpoint News Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园_首页
P
Privacy & Cybersecurity Law Blog
T
Threat Research - Cisco Blogs
J
Java Code Geeks
S
Schneier on Security

Vulnerabilities – ThreatDown by Malwarebytes

April 2025 Patch Tuesday includes one zero-day March 2025 Patch Tuesday, severity over quantity What is Cross-Site Scripting (XSS)? - ThreatDown by Malwarebytes Why ransomware gangs want you to keep using that GPON router - ThreatDown by Malwarebytes Hybrid cloud environments are not safe from ransomware Windows MSHTML vulnerability actively exploited - ThreatDown by Malwarebytes Update now! Critical CVSS 10 vulnerability in Ivanti EPM - ThreatDown by Malwarebytes Update now! Four zero-days fixed in September Patch Tuesday - ThreatDown by Malwarebytes Ransomware gangs target SonicWall vulnerability
June 2025 Microsoft Patch Tuesday fixes two zero-days
Pieter Arntz · 2025-06-12 · via Vulnerabilities – ThreatDown by Malwarebytes
patch Tuesday header image

Microsoft’s June Patch Tuesday fixes 67 vulnerabilities, including two zero-days, one of which is being actively exploited.

June 2025’s Patch Tuesday fixed 67 Microsoft vulnerabilities, including two zero-days, one of which is being actively exploited. Compared to last month, that’s an improvement, but there is still plenty to cover.

Let’s start by looking at the one that’s actively being exploited.

CVE-2025-33053 (CVSS score 8.8 out of 10): a Web Distributed Authoring and Versioning (WEBDAV) Remote Code Execution (RCE) vulnerability, which Microsoft summarizes as:

External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network.

WEBDAV is an HTTP extension that lets users remotely manage files and directories on a server, which is not enabled by default.

For successful exploitation, it requires the target to click on a specially crafted URL. This vulnerability was exploited in an attack scenario where the cybercriminals used a .url file to execute malware from a WebDAV server controlled by the attacker.

Also noteworthy is a publicly disclosed zero-day vulnerability tracked as CVE-2025-33073 (CVSS score 8.8 out of 10), a vulnerability as a result of improper access control in Windows Server Message Block (SMB) which allows an authorized attacker to elevate privileges over a network.

SMB is the protocol that is implemented in most office and home networks to share files, printers, and other resources with each other.

Since there is a publicly available proof-of-concept (PoC), it is reasonable to assume that this elevation of privilege (EoP) vulnerability is likely to be exploited. To exploit this vulnerability, an attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

Other vendors

Adobe released security updates for

Google released its June 2025 Android security bulletin and fixed an actively exploited vulnerability in the Chrome browser.

Qualcomm released security updates for three actively exploited zero-day vulnerabilities.

SAP released the June 2025 Security updates.