Trinetri logo
Updated monthly

Microsoft Patch Tuesday
August 2025

Microsoft's August 2025 Patch Tuesday fixes 114 vulnerabilities across Windows, Microsoft Office and Azure - 19 rated Critical, 1 publicly disclosed before the patch shipped. No active exploitation this month, so lead with the 9 Critical remote code execution fixes.

Released August 12, 2025, 10:00 PT1 publicly disclosed76 KB articles to deploy

August 2025 Patch Tuesday at a glance

114
Microsoft CVEs
excl. Edge & Azure Linux
19
Critical
17% of the release
0
Actively exploited
none this month
1
Publicly disclosed
known before the patch
10.0
Highest CVSS
CVE-2025-53767
76
KB articles
what you actually deploy

Why this number differs from other roundups. Microsoft's August 2025 release document lists 288 entries. 157 are Azure Linux (Mariner) OS package updates and 17 are republished Chromium fixes for Edge - neither is a Microsoft product vulnerability. The 114 above is the real Patch Tuesday set. See the breakdown →

Priority order

Patch these first

Ranked by exploitation reality, not score alone. Nothing is under active attack this month, so the Critical remote-code-execution fixes lead.

Patch today

Exploited in the wild

Confirmed attacks are already happening. Emergency change window.

No actively exploited vulnerabilities in this release.

The numbers

What’s in this release

Where the 288 entries actually come from

Most roundups quote a single number. These are three unrelated release streams.

114 Microsoft products157 Azure Linux (Mariner)17 Edge (Chromium)

Severity

Microsoft channel only · 114 CVEs

August 2025 severity breakdown
Critical19
Important94
Moderate1
Low0

Impact type

What an attacker gains if it works

August 2025 impact breakdown
Elevation of Privilege47
Remote Code Execution36
Information Disclosure18
Spoofing8
Denial of Service4
Tampering1

Most-affected components

Where this month’s fixes concentrate - filter by any of them in the table below

Windows Routing and Remote Access Service (RRAS)12Windows Ancillary Function Driver for WinSock7Microsoft Exchange Server5Microsoft Office Excel5Role: Windows Hyper-V5SQL Server5Microsoft Office Word4Windows Message Queuing4Windows Push Notifications4Microsoft Office3Azure Stack2Azure Virtual Machines2
Every patch

Browse all 288 entries

Sorted by risk by default: exploited first, then publicly disclosed, then severity, then CVSS. Search by CVE, title, component or KB number.

Showing 114 of 114
114 Microsoft vulnerabilities in the August 2025 Patch Tuesday, sortable by severity, CVSS and exploit status.
TitleStatusKB
ModerateCVE-2025-53779Windows Kerberos Elevation of Privilege VulnerabilityEoP7.2DisclosedWindows Kerberos5063878 +1
CriticalCVE-2025-53778Windows NTLM Elevation of Privilege VulnerabilityEoP8.8More likelyWindows NTLM5063709 +15
CriticalCVE-2025-50177Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityRCE8.1More likelyWindows Message Queuing5063709 +15
ImportantCVE-2025-53786Microsoft Exchange Server Hybrid Deployment Elevation of Privilege VulnerabilityEoP8.0More likelyMicrosoft Exchange Server5047155 +3
ImportantCVE-2025-50168Win32k Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Win32K - ICOMP5063875 +3
ImportantCVE-2025-53132Win32k Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Win32K - GRFX5063709 +15
ImportantCVE-2025-50167Windows Hyper-V Elevation of Privilege VulnerabilityEoP7.0More likelyRole: Windows Hyper-V5063709 +11
ImportantCVE-2025-53147Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEoP7.0More likelyWindows Ancillary Function Driver for WinSock5063709 +15
ImportantCVE-2025-49743Windows Graphics Component Elevation of Privilege VulnerabilityEoP6.7More likelyMicrosoft Graphics Component5063709 +15
ImportantCVE-2025-53156Windows Storage Port Driver Information Disclosure VulnerabilityInfo Disc.5.5More likelyStorage Port Driver5063878 +2
CriticalCVE-2025-50165Windows Graphics Component Remote Code Execution VulnerabilityRCE9.8Microsoft Graphics Component5063878 +1
CriticalCVE-2025-53766GDI+ Remote Code Execution VulnerabilityRCE9.8Windows GDI+5063709 +15
CriticalCVE-2025-53733Microsoft Word Remote Code Execution VulnerabilityRCE8.4Microsoft Office Word5002763 +4
CriticalCVE-2025-53740Microsoft Office Remote Code Execution VulnerabilityRCE8.4Microsoft Office5002756
CriticalCVE-2025-49707Azure Virtual Machines Spoofing VulnerabilitySpoofing7.9Azure Virtual Machines
CriticalCVE-2025-50176DirectX Graphics Kernel Remote Code Execution VulnerabilityRCE7.8Graphics Kernel5063812 +5
CriticalCVE-2025-53781Azure Virtual Machines Information Disclosure VulnerabilityInfo Disc.7.7Azure Virtual Machines
CriticalCVE-2025-48807Windows Hyper-V Remote Code Execution VulnerabilityRCE6.7Role: Windows Hyper-V5065306 +8
CriticalCVE-2025-53774Microsoft 365 Copilot BizChat Information Disclosure VulnerabilityInfo Disc.6.5Microsoft 365 Copilot's Business Chat
ImportantCVE-2025-50171Remote Desktop Spoofing VulnerabilitySpoofing9.1Remote Desktop Server5063709 +6
ImportantCVE-2025-24999Microsoft SQL Server Elevation of Privilege VulnerabilityEoP8.8SQL Server5063756 +7
ImportantCVE-2025-47954Microsoft SQL Server Elevation of Privilege VulnerabilityEoP8.8SQL Server5063756 +1
ImportantCVE-2025-49712Microsoft SharePoint Remote Code Execution VulnerabilityRCE8.8Microsoft Office SharePoint5002769 +1
ImportantCVE-2025-49758Microsoft SQL Server Elevation of Privilege VulnerabilityEoP8.8SQL Server5063756 +7
ImportantCVE-2025-49759Microsoft SQL Server Elevation of Privilege VulnerabilityEoP8.8SQL Server5063756 +7
Your move

What your IT team should do

The same five steps every month, in the order that reduces risk fastest.

Test the known-issue candidates

Check the Windows release health dashboard before promoting past ring 1, and have the rollback path written down before you need it. Kernel, networking and authentication fixes are the ones that historically break things.

12 Patch Management Best Practices for 2026

Verify installed state, then evidence it

Confirm the patch is actually present on each endpoint rather than trusting that "deployment succeeded". Keep the resulting report - it is the artefact auditors ask for, and reconstructing it later is far more work than capturing it now.

Patch Management: The Complete Guide

Trinetri does steps two through five automatically - detecting the 76 KB articles across every endpoint, staging them in rings, verifying installed state and producing the compliance evidence. See patch management →

Patch Tuesday FAQ

Patch Tuesday falls on the second Tuesday of every month, with updates going live at 10:00 a.m. Pacific Time. Microsoft introduced the practice in October 2003, following the Blaster worm, to cut distribution costs and give administrators a predictable cadence instead of patches arriving at random. The 10:00 a.m. timing is deliberate: it leaves a full working week to remediate before the weekend. Internally Microsoft calls it the "B" release; optional "C" and "D" preview releases follow later in the month. The next Patch Tuesday is September 8, 2026.

Microsoft fixed 114 vulnerabilities in August 2025, across Windows, Microsoft Office, Azure and Server Software. 19 are rated Critical, 1 were publicly disclosed before the patch shipped, and 0 were already being exploited. Note that Microsoft's release document lists 288 entries in total, but 157 of those are Azure Linux package updates and 17 are republished Chromium fixes for Edge, which is why other sources sometimes quote a much larger number.

Exploit Wednesday is the day after Patch Tuesday. Attackers compare the newly released patches against the previous version to locate the flaw each one fixes, then build working exploits from that difference - often within 24 to 48 hours. It is the reason the deployment window matters as much as the patch itself: every hour a Critical remote code execution fix sits undeployed is an hour of measurable exposure.

A workable target for most organisations: actively exploited vulnerabilities within 24 hours, publicly disclosed ones within 72 hours, remaining Critical fixes within seven days, and everything else within the month. CISA's Known Exploited Vulnerabilities catalogue sets binding deadlines for US federal agencies and is a reasonable benchmark for everyone else. Stage the rollout in rings rather than deploying everywhere at once, so a regression is caught on a pilot group instead of in production.

An out-of-band update is a patch released outside the monthly cycle because the risk will not wait for the next Patch Tuesday. Microsoft issues them for actively exploited flaws with no mitigation - most famously during the WannaCry outbreak in 2017, when it took the unusual step of patching versions of Windows that were already out of support.

Yes. Adobe aligned its releases with Patch Tuesday in November 2012, and both SAP's Security Patch Day and Oracle's quarterly Critical Patch Updates are coordinated to the same week. Part of the reason is defensive: staggered releases let attackers reverse-engineer one vendor's patch to find the same underlying flaw in another's still-unpatched product. For IT teams it means the second Tuesday is rarely just a Microsoft problem.

Edge is built on Chromium, so most of its security fixes originate with the Chromium project and are republished by Microsoft under their own CVE identifiers. They ship on Chromium's cadence rather than the Patch Tuesday cycle, and they are delivered by Edge's own updater rather than Windows Update. Counting the 17 Edge entries alongside Microsoft product fixes would inflate the headline number and imply work for your Windows Update rings that does not exist.

Stop the sprawl. Eliminate the guesswork.

Ready to See Autonomous Endpoint Management in Action?

Experience how Trinetri transforms endpoint chaos into clarity. Try the 30 minute demo session, our experts will walk you through how AI-powered automation, real-time visibility, and unified control can secure your entire hybrid environment, without the overhead.