Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws

Gandalf_The_Grey

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Forum Veteran
Apr 24, 2016
7,714
6
82,065
8,389
54
The Netherlands
Today is Microsoft's May 2025 Patch Tuesday, which includes security updates for 72 flaws, including five actively exploited and two publicly disclosed zero-day vulnerabilities.

This Patch Tuesday also fixes six "Critical" vulnerabilities, five being remote code execution vulnerabilities and another an information disclosure bug.

The number of bugs in each vulnerability category is listed below:
  • 17 Elevation of Privilege Vulnerabilities
  • 2 Security Feature Bypass Vulnerabilities
  • 28 Remote Code Execution Vulnerabilities
  • 15 Information Disclosure Vulnerabilities
  • 7 Denial of Service Vulnerabilities
  • 2 Spoofing Vulnerabilities
This count does not include Azure, Dataverse, Mariner, and Microsoft Edge flaws that were fixed earlier this month.

To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5058411 and KB5058405 cumulative updates and the Windows 10 KB5058379 update.
 
ZDI: The May 2025 Security Update Review
It’s the second Tuesday of the month, and the final patch Tuesday before Pwn2Own Berlin. I know several contestants are sweating it out and hoping their entries are patched out. While they quiver with anticipation, take a break from your scheduled activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our YouTube channel. It should be posted within a couple of hours after the release.

Adobe Patches for May 2025

As of 1:30PM Central time, Adobe has not released its patches for May. This blog will be updated once they do.

Microsoft Patches for May 2025

This month, Microsoft released a reasonable 75 new CVEs in Windows and Windows Components, Office and Office Components, .NET and Visual Studio, Azure, Nuance PowerScribe, Remote Desktop Gateway Service, and Microsoft Defender. Three of these bugs were reported through the Trend ZDI program. With the additional third-party CVEs being documented, it brings the combined total to 82 CVEs.

Of the patches released today, 12 are rated Critical, and the rest are rated Important in severity. This number of fixes isn’t unusual for May, but it does put Microsoft ahead of where they were at this point last year in regards to CVEs released. It’s also unusual to see so many Office-related bugs getting patched in a single month. Perhaps this is a harbinger of attacks we can expect to see later this year.

Microsoft lists five bugs as being under active attack at the time of release, with two others being publicly known.
Looking Ahead

The next Patch Tuesday of 2025 will be on June 10. Assuming I survive the next few days, I’ll be back with my analysis and thoughts about the release. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!
 
Updated Windows 11 last night on 24 H2, the install went fine, though & I don't think its me but on 'My PC' the colours seem darker showing drive space left for example are a darker blue on the theme I'm on - Not an issue but different???? (have I lost it finally?) :)
 

You may also like...