Headlines

Microsoft issued patches for 66 CVE-rated vulnerabilities:

  • Two vulnerabilities are Zero Days with current exploits
  • Microsoft has also addressed the recent Chromium Zero Day (CVE-2025-5419)
  • Proof of Concept (PoC) exists for other vulnerabilities in the release

Several vulnerabilities affecting Office products, with High CVSS ratings.

Quorum Cyber Recommendations

Patching should be completed within your regular cycles and without delay. We do not at this time recommend expedited patching.

Microsoft Release Notes

June 2025 Security Updates – Release Notes – Security Update Guide – Microsoft

Key Vulnerability Details

TitleWeb Distributed Authoring and Versioning (WEBDAV) Remote Code Execution Vulnerability
CVECVE-2025-33053
CVSS8.8
Reason for ConcernZero day with public exploit.  Can be exploited via a single click on a malicious file.  Microsoft have issued updates for EOL OS types such as Windows 2008 and Windows 2012, as well as Internet Explorer.
Mitigations and other FactorsUser interaction is required for the vulnerability to be exploited.
CommentaryThis has been exploited against a defence company in Turkey with the intention of deploying data exfiltration malware.  Exploitation was done via a URL disguised as a PDF.
Threat Intelligence CommentCVE-2025-33053 is a zero-day WEBDAV vulnerability (CVSS 8.8) with a public exploit, requiring minimal user interaction to execute malicious code. It has been used to target a defence company in Turkey for data exfiltration via a disguised URL. Immediate patching and user awareness are essential to mitigate this threat.
LinkCVE-2025-33053 – Security Update Guide – Microsoft – Web Distributed Authoring and Versioning (WEBDAV) Remote Code Execution Vulnerability

 

TitleWindows SMB Client Elevation of Privilege Vulnerability
CVECVE-2025-33073
CVSS8.8
Reason for ConcernZero Day, publicly disclosed before being fixed.
Mitigations and other FactorsA user would need to be tricked into connecting with an attacker-controlled application server.
CommentaryWhile this is listed as a publicly disclosed Zero Day, Microsoft have listed the chances of exploitation as Less Likely.
Threat Intelligence CommentCVE-2025-33073 is a zero-day Windows SMB Client vulnerability (CVSS 8.8) that could lead to elevation of privilege if a user connects to an attacker-controlled server. Although publicly disclosed before a fix was available, Microsoft rates the likelihood of exploitation as low. Users should exercise caution and avoid connecting to untrusted servers to mitigate risk.
LinkCVE-2025-33073 – Security Update Guide – Microsoft – Windows SMB Client Elevation of Privilege Vulnerability

 

TitleChromium: CVE-2025-5419 Out of bounds read and write in V8
CVECVE-2025-5419
CVSS8.8
Reason for ConcernExploited zero day in Google Chrome.
Mitigations and other FactorsUser interaction is required.
CommentaryMicrosoft has issued an update to address the vulnerability in Edge.
Threat Intelligence CommentCVE-2025-5419 is an exploited zero-day vulnerability (CVSS 8.8) involving out-of-bounds read and write in Chromium’s V8 engine, affecting Google Chrome. User interaction is necessary for exploitation. Microsoft has released an update to mitigate this issue in Edge, highlighting the importance of keeping browsers updated to protect against potential attacks.
LinkCVE-2025-5419 – Security Update Guide – Microsoft – Chromium: CVE-2025-5419 Out of bounds read and write in V8

 

TitleMicrosoft Office Remote Code Execution Vulnerability
CVECVE-2025-47162
CVSS8.4
Reason for ConcernThis vulnerability can allow for remote code execution.  Microsoft have indicated that the Preview Pane can be used as an attack vector.
Mitigations and other FactorsAn attacker would need to connect to a target machine to exploit the vulnerability.
CommentaryMicrosoft have listed this as Exploitation More Likely as it seems to be relatively simple to exploit.

Updates to Microsoft 365 are not immediately available.

Threat Intelligence CommentCVE-2025-47162 is a Microsoft Office vulnerability (CVSS 8.4) that allows for remote code execution, with the Preview Pane serving as a potential attack vector. Exploitation is considered more likely due to its simplicity, though an attacker must connect to the target machine. Updates for Microsoft 365 are pending, so users should exercise caution with email attachments and use alternative security measures in the interim.
LinkCVE-2025-47162 – Security Update Guide – Microsoft – Microsoft Office Remote Code Execution Vulnerability

 

TitleMicrosoft Office Remote Code Execution Vulnerability
CVECVE-2025-47167
CVSS8.4
Reason for ConcernAccess of resource using incompatible type (‘type confusion’) in Microsoft Office allows an unauthorised attacker to execute code locally. The preview pane is an attack vector.
Mitigations and other FactorsWhile Microsoft has scored the vulnerability as User Interaction: None, it seems likely that a single click is required for exploitation.
CommentaryMicrosoft has listed this as Exploitation More Likely as it seems to be relatively simple to exploit.

Updates to Microsoft 365 are not immediately available.

Threat Intelligence CommentCVE-2025-47167 is a Microsoft Office vulnerability (CVSS 8.4) involving type confusion that permits unauthorised local code execution, with the Preview Pane as an attack vector. Although user interaction is officially rated as none, a single click may be required for exploitation. Microsoft notes the exploitation as more likely due to its simplicity, but updates for Microsoft 365 are not yet available. Users should be cautious with email attachments and consider interim security measures.
LinkCVE-2025-47167 – Security Update Guide – Microsoft – Microsoft Office Remote Code Execution Vulnerability

Additional Releases

Aside from Microsoft, the following vendors have issued updates for significant vulnerabilities:

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content