NG Solution Team
Technology

Did Microsoft Address Over 130 Vulnerabilities in July’s Patch Tuesday?

Microsoft has released its Patch Tuesday updates for July 2025, tackling a total of 137 vulnerabilities across various products. Among these fixes, one zero-day vulnerability and fourteen critical issues have been addressed, including ten vulnerabilities with critical severity. Notably, nine of these could lead to remote code execution, while one involves information disclosure.

Key vulnerabilities include several in Microsoft Office that could allow unauthorized code execution through the Preview Pane, and a serious heap-based buffer overflow flaw in Windows SPNEGO Extended Negotiation with a CVSS score of 9.8. Additionally, a zero-day vulnerability in SQL Server, which had seen active exploitation attempts, has been patched to prevent information disclosure.

In total, Microsoft has resolved 119 other important vulnerabilities, covering a range of issues such as denial of service, privilege escalation, information disclosure, remote code execution, security feature bypass, spoofing, and tampering. Some of these vulnerabilities achieve a high CVSS score of 8.8, particularly those affecting the Windows Routing and Remote Access Service (RRAS) with potential for remote code execution.

Users are urged to ensure their systems are updated, as Microsoft automatically rolls out these security updates to eligible devices. However, manual checks are recommended to confirm all updates are installed, especially for enterprise users to protect against potential threats from unpatched vulnerabilities.

Related posts

Is the government negotiating with China over rare earth magnet supply issues?

Jessica Williams

Is Android 17 the biggest update ever, powering Samsung’s One UI 9?

Emily Brown

What can we expect from Samsung’s Galaxy S25 FE and Tab S11 series launch in India today?

David Jones

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy