CyberzSOC

Publication detail
← Back to advisories & guidance

2025-032: Multiple Vulnerabilities in Microsoft Products ↗ source

August 18, 2025 CERT-EU Advisory

Summary

On August 13, 2025, Microsoft released its August 2025 Patch Tuesday advisory addressing 111 security flows in various products among which 16 are rated as critical [1]. It is recommended updating as soon as possible, prioritising public facing and critical assets. Below are listed the notable vulnerabilities among those rated as critical by Microsoft: The vulnerability CVE-2025-50176, with a CVSS score of 7.8, is due to a type confusion flaw in the DirectX Graphics Kernel allowing an authenticated attacker to execute code locally [2]. The vulnerability CVE-2025-50165, with a CVSS score of 9.8, is due to the use of untrusted pointer dereference in Microsoft Graphics Component allowing an authenticated attacker to execute code over a network without user interaction [3]. The vulnerabilities CVE-2025-53740 and CVE-2025-53731, with a CVSS score of 8.4, are use after free security flaws in Microsoft Office, and allow a remote attacker to execute code locally. Microsoft confirmed that the Preview Pane is also an attack vector [4,5].

News Coverage

DateSourceArticle
2025-12-22 ESET WeLiveSecurity Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component CVE-2025-50165

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-50165 9.8 Critical Microsoft Windows 11 Version 24H2 Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2025-53766 9.8 Critical Microsoft Microsoft Office for Android Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVE-2025-53778 8.8 High Microsoft Windows 10 Version 1507 Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
CVE-2025-53731 8.4 High Microsoft Microsoft 365 Apps for Enterprise Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-53733 8.4 High Microsoft Microsoft 365 Apps for Enterprise Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-53740 8.4 High Microsoft Microsoft 365 Apps for Enterprise Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-53784 8.4 High Microsoft Microsoft 365 Apps for Enterprise Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-50177 8.1 High Microsoft Windows 10 Version 1507 Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2025-50176 7.8 High Microsoft Windows 11 version 22H2 Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally.
CVE-2025-48807 6.7 Medium Microsoft Windows 10 Version 1607 Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.