By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Eight critical RCE flaws make Microsoft’s latest Patch Tuesday list | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Eight critical RCE flaws make Microsoft’s latest Patch Tuesday list | Computer Weekly
News

Eight critical RCE flaws make Microsoft’s latest Patch Tuesday list | Computer Weekly

News Room
Last updated: 2025/08/12 at 9:11 PM
News Room Published 12 August 2025
Share
SHARE

No fewer than eight critical flaws that could allow a threat actor to achieve remote code execution (RCE) on a targeted system are listed in Microsoft’s August Patch Tuesday update, which once again tops out at over 100 common vulnerabilities and exposures (CVEs).

Alongside the critical RCE bugs, which occur in a variety of Microsoft products and services including DirectX Graphics Kernel, GDI+, Hyper-V, Message Queuing, Office and Word, are a solitary elevation of privilege (EoP) flaw in Windows NTLM, two information disclosure vulnerabilities in Hyper-V and Azure Stack Hub, and a spoofing vulnerability in Hyper-V.

The latest monthly drop contains no full zero-day exploits, bar one EoP vulnerability in Windows Kerberos, CVE-2025-53779, that by itself does not quite meet all the criteria as while exploit code has been made public, there is no evidence any threat actor has yet taken advantage of it.

This stems from a path traversal flaw in which Kerberos improperly validates path inputs when handling the relatively new delegated Managed Service Account (dMSA) feature in Windows Server 2025. This in turn enables an attacker to create improper delegation relationships, impersonate privileged accounts, escalate to domain admin privileges, and potentially gain control of the Active Directory domain.

However in order to do so they would need to already have elevated access to certain attributes of the dMSA, so exploitation is supposedly less likely, according to Microsoft.

This said, Mike Walters, president and co-founder of Action1, said the danger from CVE-2025-53779 grows when combined with other techniques and as such, large organisations with complex Active Directory environments, those that lean into dMSAs for service account management, and high-risk targets like banks, government agencies or hospitals, should take heed.

“The combination of a path traversal issue in a core authentication component like Kerberos and its potential high impact is concerning,” said Walters.

“The need for high privileges may create a false sense of security, as accounts with these rights are common in decentralised IT environments. Once compromised, they can quickly lead to full domain takeover. 

“The presence of functional exploit code means attackers may pursue this flaw despite Microsoft’s assessment. Vulnerabilities in core authentication mechanisms are attractive additions to advanced attack chains, especially in targeting high-value environments,” he warned.

SharePoint flaws should be addressed

Although less immediately dangerous in their scope, defenders may also wish to pay attention to a pair of vulnerabilities in SharePoint, CVE-2025-53760, which enables EoP, and CVE-2025-49712, which enables RCE.

These come hot on the heels of the so-called ToolShell vulnerabilities in SharePoint – which were so serious they received an out-of-synch patch in July, and were exploited in short-order by China-linked threat actors against government targets.

Qualys Threat Unit senior manager for security research, Saeed Abbasi, said CVE-2025-49712 in particular warranted some concern.

“This RCE demands authentication but pairs dangerously with known auth bypasses,” explained Abbasi.

“Attackers chaining this with prior flaws could achieve full server compromise, and data exfiltration. It’s not yet exploited in the wild, but history shows these evolve fast. Exposed SharePoint instances are prime footholds for lateral movement.

“Prioritise and patch all SharePoint updates, rotate keys, and eliminate internet exposure. Delaying invites regulatory scrutiny and breaches since SharePoint’s exploit streak isn’t over,” added Abbasi.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Unfold Savings: The Samsung Galaxy Z Flip 7 FE Phone Just Dropped by $200
Next Article What The TikTok Ban Means For Brands & Creators (Updated)
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Stellantis-backed Leapmotor narrows quarterly losses, keeps to target · TechNode
Computing
Apple Rejects Elon Musk’s App Store Bias Claims. Is He Too Busy Fighting With Altman to Notice?
News
New York claims Zelle’s shoddy security enabled a billion dollars in scams
News
I Turned My Phone’s Back Tap into Productivity Gold and Now I Get More Done
Computing

You Might also Like

News

Apple Rejects Elon Musk’s App Store Bias Claims. Is He Too Busy Fighting With Altman to Notice?

7 Min Read
News

New York claims Zelle’s shoddy security enabled a billion dollars in scams

3 Min Read
News

Grab Beats Solo Buds now that they’re back down near their Prime Day price

2 Min Read
News

SonicWall launches Generation 8 firewalls with unified management and built-in zero trust security – News

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?