Headlines
Microsoft issued patches for 66 CVE-rated vulnerabilities:
- Two vulnerabilities are Zero Days with current exploits
- Microsoft has also addressed the recent Chromium Zero Day (CVE-2025-5419)
- Proof of Concept (PoC) exists for other vulnerabilities in the release
Several vulnerabilities affecting Office products, with High CVSS ratings.
Quorum Cyber Recommendations
Patching should be completed within your regular cycles and without delay. We do not at this time recommend expedited patching.
Microsoft Release Notes
June 2025 Security Updates – Release Notes – Security Update Guide – Microsoft
Key Vulnerability Details
| Title | Web Distributed Authoring and Versioning (WEBDAV) Remote Code Execution Vulnerability |
| CVE | CVE-2025-33053 |
| CVSS | 8.8 |
| Reason for Concern | Zero day with public exploit. Can be exploited via a single click on a malicious file. Microsoft have issued updates for EOL OS types such as Windows 2008 and Windows 2012, as well as Internet Explorer. |
| Mitigations and other Factors | User interaction is required for the vulnerability to be exploited. |
| Commentary | This has been exploited against a defence company in Turkey with the intention of deploying data exfiltration malware. Exploitation was done via a URL disguised as a PDF. |
| Threat Intelligence Comment | CVE-2025-33053 is a zero-day WEBDAV vulnerability (CVSS 8.8) with a public exploit, requiring minimal user interaction to execute malicious code. It has been used to target a defence company in Turkey for data exfiltration via a disguised URL. Immediate patching and user awareness are essential to mitigate this threat. |
| Link | CVE-2025-33053 – Security Update Guide – Microsoft – Web Distributed Authoring and Versioning (WEBDAV) Remote Code Execution Vulnerability |
| Title | Windows SMB Client Elevation of Privilege Vulnerability |
| CVE | CVE-2025-33073 |
| CVSS | 8.8 |
| Reason for Concern | Zero Day, publicly disclosed before being fixed. |
| Mitigations and other Factors | A user would need to be tricked into connecting with an attacker-controlled application server. |
| Commentary | While this is listed as a publicly disclosed Zero Day, Microsoft have listed the chances of exploitation as Less Likely. |
| Threat Intelligence Comment | CVE-2025-33073 is a zero-day Windows SMB Client vulnerability (CVSS 8.8) that could lead to elevation of privilege if a user connects to an attacker-controlled server. Although publicly disclosed before a fix was available, Microsoft rates the likelihood of exploitation as low. Users should exercise caution and avoid connecting to untrusted servers to mitigate risk. |
| Link | CVE-2025-33073 – Security Update Guide – Microsoft – Windows SMB Client Elevation of Privilege Vulnerability |
| Title | Chromium: CVE-2025-5419 Out of bounds read and write in V8 |
| CVE | CVE-2025-5419 |
| CVSS | 8.8 |
| Reason for Concern | Exploited zero day in Google Chrome. |
| Mitigations and other Factors | User interaction is required. |
| Commentary | Microsoft has issued an update to address the vulnerability in Edge. |
| Threat Intelligence Comment | CVE-2025-5419 is an exploited zero-day vulnerability (CVSS 8.8) involving out-of-bounds read and write in Chromium’s V8 engine, affecting Google Chrome. User interaction is necessary for exploitation. Microsoft has released an update to mitigate this issue in Edge, highlighting the importance of keeping browsers updated to protect against potential attacks. |
| Link | CVE-2025-5419 – Security Update Guide – Microsoft – Chromium: CVE-2025-5419 Out of bounds read and write in V8 |
| Title | Microsoft Office Remote Code Execution Vulnerability |
| CVE | CVE-2025-47162 |
| CVSS | 8.4 |
| Reason for Concern | This vulnerability can allow for remote code execution. Microsoft have indicated that the Preview Pane can be used as an attack vector. |
| Mitigations and other Factors | An attacker would need to connect to a target machine to exploit the vulnerability. |
| Commentary | Microsoft have listed this as Exploitation More Likely as it seems to be relatively simple to exploit. Updates to Microsoft 365 are not immediately available. |
| Threat Intelligence Comment | CVE-2025-47162 is a Microsoft Office vulnerability (CVSS 8.4) that allows for remote code execution, with the Preview Pane serving as a potential attack vector. Exploitation is considered more likely due to its simplicity, though an attacker must connect to the target machine. Updates for Microsoft 365 are pending, so users should exercise caution with email attachments and use alternative security measures in the interim. |
| Link | CVE-2025-47162 – Security Update Guide – Microsoft – Microsoft Office Remote Code Execution Vulnerability |
| Title | Microsoft Office Remote Code Execution Vulnerability |
| CVE | CVE-2025-47167 |
| CVSS | 8.4 |
| Reason for Concern | Access of resource using incompatible type (‘type confusion’) in Microsoft Office allows an unauthorised attacker to execute code locally. The preview pane is an attack vector. |
| Mitigations and other Factors | While Microsoft has scored the vulnerability as User Interaction: None, it seems likely that a single click is required for exploitation. |
| Commentary | Microsoft has listed this as Exploitation More Likely as it seems to be relatively simple to exploit. Updates to Microsoft 365 are not immediately available. |
| Threat Intelligence Comment | CVE-2025-47167 is a Microsoft Office vulnerability (CVSS 8.4) involving type confusion that permits unauthorised local code execution, with the Preview Pane as an attack vector. Although user interaction is officially rated as none, a single click may be required for exploitation. Microsoft notes the exploitation as more likely due to its simplicity, but updates for Microsoft 365 are not yet available. Users should be cautious with email attachments and consider interim security measures. |
| Link | CVE-2025-47167 – Security Update Guide – Microsoft – Microsoft Office Remote Code Execution Vulnerability |
Additional Releases
Aside from Microsoft, the following vendors have issued updates for significant vulnerabilities:
- Adobe – multiple products: Adobe Security Bulletins and Advisories
- Fortinet – multiple products: PSIRT | FortiGuard Labs
- SAP – multiple products: SAP Security Patch Day – June 2025












