Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Newegg’s Ryzen 7 9850X3D combo bundle offers over $500 in savings on three key components, including 64GB DDR5 RAM

    Tenku Pocket 8 micro laptop launched with 8-inch touch display and 8-core Intel Alder Lake-N CPU

    Endorfy Signum M30 Air and M30 ARGB arrive as brand-new micro ATX PC towers

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Tensions between the Pentagon and AI giant Anthropic reach a boiling point

      February 21, 2026

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026
    • Business

      How Smarsh built an AI front door for regulated industries — and drove 59% self-service adoption

      February 24, 2026

      Where MENA CIOs draw the line on AI sovereignty

      February 24, 2026

      Ex-President’s shift away from Xbox consoles to cloud gaming reportedly caused friction

      February 24, 2026

      Gartner: Why neoclouds are the future of GPU-as-a-Service

      February 21, 2026

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026
    • Crypto

      BitMine Buys $93 Million in ETH, but Ethereum Slides as Holders Resume Selling

      February 24, 2026

      XRP Ledger Sets Multiple Key Records in February Despite Price Decline

      February 24, 2026

      Bhutan Rolls Out Solana-Backed Visas Even As Demand Stays Weak

      February 24, 2026

      ZachXBT Teases Major Crypto Exposé Ahead of Feb. 26 — How Is Smart Money Positioned?

      February 24, 2026

      Acurast turns 225,000 smartphones into a secure AI network on Base

      February 24, 2026
    • Technology

      Newegg’s Ryzen 7 9850X3D combo bundle offers over $500 in savings on three key components, including 64GB DDR5 RAM

      February 25, 2026

      Tenku Pocket 8 micro laptop launched with 8-inch touch display and 8-core Intel Alder Lake-N CPU

      February 25, 2026

      Endorfy Signum M30 Air and M30 ARGB arrive as brand-new micro ATX PC towers

      February 25, 2026

      Ditch the Adobe subscription: This PDF editor is yours for life for $25

      February 25, 2026

      Her AI agent nuked 200 emails. This guardrail stops the next disaster

      February 25, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»June Patch Tuesday brings a lighter load for defenders
    Technology

    June Patch Tuesday brings a lighter load for defenders

    TechAiVerseBy TechAiVerseJune 11, 2025No Comments5 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    June Patch Tuesday brings a lighter load for defenders
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    June Patch Tuesday brings a lighter load for defenders

    Barely 70 vulnerabilities make the cut for Microsoft’s monthly security update, but an RCE flaw in WEBDAV and an EoP issue in Windows SMB Client still warrant close attention.

    By

    • Alex Scroxton,
      Security Editor

    Published: 10 Jun 2025 19:55

    Microsoft’s latest Patch Tuesday update landed on schedule around teatime on 10 June, with admins facing a much lighter load heading into the summer – at least lighter than of late – with barely 70 security flaws awaiting attention and just two potential zero-day common vulnerabilities and exposures (CVEs) in scope.

    The two most pressing issues for patching this month are CVE-2025-33053, a remote code execution (RCE) flaw in Web Distributed Authoring and Versioning (WEBDAV), and CVE-2025-33073, an elevation of privilege (EoP) vulnerability in Windows Server Message Block (SMB) Client. Both carry a CVSS score of 8.8.

    Microsoft revealed it has evidence that the first of these CVEs is already being exploited in the wild, although proof-of-concept code is not publicly available, while for the second, the opposite is true. It credited the RCE flaw to Alexandra Gofman and David Driker of Check Point Research, and the second to researchers with CrowdStrike, Synacktiv, SySS GmbH, and Google Project Zero.

    Of these two, CVE-2025-33053 probably presents the most pressing patching need. This is because in practice, the issue affects various tools that still incorporate the defunct Internet Explorer browser in a legacy capacity, hence Microsoft has been forced into the position of producing patches for long out-of-support platforms, dating back as far as Windows 8 and Server 2012.

    “This vulnerability allows attackers to execute remote code on affected systems when users click on malicious URLs,” explained Mike Walters, president and co-founder of patch management specialist Action1.

    “The exploit takes advantage of WebDAV’s file handling capabilities to run arbitrary code in the context of the current user. If the user holds administrative privileges, the impact can be severe.  

    “What makes this flaw particularly concerning is the widespread use of WebDAV in enterprise environments for remote file sharing and collaboration. Many organisations enable WebDAV for legitimate business needs – often without fully understanding the security risks it introduces,” said Walters.

    “The potential impact is extensive, with millions of organisations worldwide at risk. An estimated 70 to 80% of enterprises could be vulnerable – especially those lacking strict URL filtering or user training on phishing threats,” he added.

    Meanwhile, Ben Hopkins, cyber threat intelligence researcher at Immersive, ran the rule over the second potential zero-day, CVE-2023-33073.

    “It’s classified as an Elevation of Privilege vulnerability, which indicates that a successful exploit would allow an attacker to gain higher-level permissions on a compromised system,” explained Hopkins.

    “Threat actors highly seek out vulnerabilities of this nature. Once an attacker has gained an initial foothold on a machine, often through methods like phishing or exploiting another vulnerability, they can leverage privilege escalation flaws to gain deeper control.”

    He continued: “With elevated privileges, an attacker could potentially disable security tools, access and exfiltrate sensitive data, install persistent malware, or move laterally across the network to compromise additional systems.

    “Given the high severity rating and the critical role of SMB in Windows networking, organisations should prioritise applying the necessary security patches to mitigate the risk posed by this vulnerability.”

    10 critical flaws, hanging on the wall

    The Microsoft June Patch Tuesday update also includes no fewer 10 critical flaws – four affecting Microsoft Office, and one apiece in Microsoft SharePoint Server, Power Automate, Windows KDC Proxy Service (KPSSVC), Windows Netlogon, Windows Remote Desktop Services and Windows Schannel. Of these, eight – including all four office vulns – are RCE issues, and the other two enable privilege escalation.

    Kev Breen, senior director of threat research at Immersive, said defenders should put the Office vulnerabilities high on their list of priorities.

    “Listed as a use after free, heap-based buffer overflow, and type confusion RCE, these vulnerabilities would allow an attacker to craft a malicious document that, if sent and opened by a victim, would give the attacker access to run commands on the victim’s computer remotely,” said Breen.

    “Microsoft also says that ‘The Preview Pane’ is an attack vector, meaning that simply viewing the attachment in something like Outlook could be enough to trigger the exploit.

    “More concerning is that Microsoft says there are no updates available for Microsoft 365 at the time of release, and customers will be notified via a revision to this notice,” said Breen.

    “While this CVE is not actively being exploited, the risk remains high as threat actors have been known to quickly reverse engineer patches to create n-day exploits before organisations have a chance to roll out patches,” he added.

    Read more on Application security and coding requirements


    • Microsoft tackles 5 Windows zero-days on May Patch Tuesday

      By: Tom Walat


    • May Patch Tuesday brings five exploited zero-days to fix

      By: Alex Scroxton


    • Microsoft’s April 2025 bumper Patch Tuesday corrects 124 bugs

      By: Brian McKenna


    • Exploited Windows zero-day addressed on April Patch Tuesday

      By: Tom Walat

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleUnity launches new Audience Hub for privacy-first ad campaigns
    Next Article West Brom Building Society project to meet customers’ digital demands
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Newegg’s Ryzen 7 9850X3D combo bundle offers over $500 in savings on three key components, including 64GB DDR5 RAM

    February 25, 2026

    Tenku Pocket 8 micro laptop launched with 8-inch touch display and 8-core Intel Alder Lake-N CPU

    February 25, 2026

    Endorfy Signum M30 Air and M30 ARGB arrive as brand-new micro ATX PC towers

    February 25, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025693 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025279 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025160 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025122 Views
    Don't Miss
    Technology February 25, 2026

    Newegg’s Ryzen 7 9850X3D combo bundle offers over $500 in savings on three key components, including 64GB DDR5 RAM

    Newegg’s Ryzen 7 9850X3D combo bundle offers over $500 in savings on three key components,…

    Tenku Pocket 8 micro laptop launched with 8-inch touch display and 8-core Intel Alder Lake-N CPU

    Endorfy Signum M30 Air and M30 ARGB arrive as brand-new micro ATX PC towers

    Samsung Galaxy S26 series go official, 512GB base storage for Malaysia, from RM5199

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Newegg’s Ryzen 7 9850X3D combo bundle offers over $500 in savings on three key components, including 64GB DDR5 RAM

    February 25, 20262 Views

    Tenku Pocket 8 micro laptop launched with 8-inch touch display and 8-core Intel Alder Lake-N CPU

    February 25, 20262 Views

    Endorfy Signum M30 Air and M30 ARGB arrive as brand-new micro ATX PC towers

    February 25, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.