Back to News
Market Impact: 0.15

Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws

MSFTCHKPGOOGGOOGLADBECSCOFTNTHPEQCOMSAP
Technology & InnovationCybersecurity & Data Privacy
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws

Microsoft's June 2025 Patch Tuesday addresses 66 security flaws, including one actively exploited zero-day (CVE-2025-33053, a WEBDAV remote code execution vulnerability used by the APT group Stealth Falcon) and one publicly disclosed zero-day (CVE-2025-33073, a Windows SMB Client Elevation of Privilege Vulnerability). The update also includes fixes for ten critical vulnerabilities, primarily remote code execution and elevation of privilege bugs, requiring immediate attention from IT and security teams to mitigate potential exploits.

Analysis

Microsoft's June 2025 Patch Tuesday addressed a substantial 66 security flaws, critically including one actively exploited zero-day vulnerability (CVE-2025-33053) and another publicly disclosed zero-day (CVE-2025-33073). The actively exploited flaw, a Web Distributed Authoring and Versioning (WEBDAV) remote code execution vulnerability discovered by Check Point Research, was reportedly utilized by the APT group "Stealth Falcon" in cyberattacks against a defense company in Turkey, underscoring the immediate threat posed before the patch. The update also rectified ten "Critical" vulnerabilities, of which eight were remote code execution flaws and two were elevation of privileges bugs, all of which are of high concern for system integrity. While Microsoft's patching is a regular operational activity, the nature of these vulnerabilities, particularly the zero-days and the specific exploitation by an APT group, emphasizes the dynamic and persistent cyber threat environment faced by Microsoft and its extensive enterprise and consumer user base. The concurrent security updates from other major technology firms such as Adobe, Cisco, Google, HPE, Qualcomm, and SAP further illustrate a widespread industry response to ongoing cybersecurity challenges during June 2025, highlighting the pervasive nature of these risks across the tech sector.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

mildly positive

Sentiment Score

0.20

Ticker Sentiment

ADBE0.20
CHKP0.70
CSCO0.20
FTNT0.20
GOOG0.40
GOOGL0.40
HPE0.20
MSFT0.60
QCOM0.20