Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Stop Killing Games is a consumer-driven shake up for digital distribution as a whole | Opinion

    Goat Simulator creators reveal new studio Feeble Minds

    Wreckreation maker Three Fields Entertainment puts whole studio on redundancy notice

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Apple’s AI chief abruptly steps down

      December 3, 2025

      The issue that’s scrambling both parties: From the Politics Desk

      December 3, 2025

      More of Silicon Valley is building on free Chinese AI

      December 1, 2025

      From Steve Bannon to Elizabeth Warren, backlash erupts over push to block states from regulating AI

      November 23, 2025

      Insurance companies are trying to avoid big payouts by making AI safer

      November 19, 2025
    • Business

      Public GitLab repositories exposed more than 17,000 secrets

      November 29, 2025

      ASUS warns of new critical auth bypass flaw in AiCloud routers

      November 28, 2025

      Windows 11 gets new Cloud Rebuild, Point-in-Time Restore tools

      November 18, 2025

      Government faces questions about why US AWS outage disrupted UK tax office and banking firms

      October 23, 2025

      Amazon’s AWS outage knocked services like Alexa, Snapchat, Fortnite, Venmo and more offline

      October 21, 2025
    • Crypto

      HTX Research Releases New Report on Prediction Markets: From Structural Constraints to the Future of Attention-Based Financial Infrastructure

      December 4, 2025

      Monad (MON) Risks a Slide to Listing Lows as Big Players Walk Away — Last Hope At $0.028?

      December 4, 2025

      Peter Schiff to CZ: ‘Bitcoin Payments? They’re Just Liquidated Bets’

      December 4, 2025

      Tom Lee’s Relentless ETH Buying Puts BMNR Stock on a Possible 55% Breakout Path

      December 4, 2025

      Vienna Crypto Murder Shocks Europe as Kidnapping Wave Escalates

      December 4, 2025
    • Technology

      ‘AI is permeating everything we do’: How Guitar Center developed 2 AI tools this year

      December 4, 2025

      Media Briefing: Publishers turn to vertical video to compete with creators and grow ad revenue in 2026

      December 4, 2025

      From lawsuits to lobbying: How publishers are fighting AI

      December 4, 2025

      U.K. retailer Boots leads brand efforts to invest in ad creative’s data layer

      December 4, 2025

      Digiday+ Research Subscription Index 2025: Subscription strategies from Bloomberg, The New York Times, Vox and others

      December 4, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»June Patch Tuesday brings a lighter load for defenders
    Technology

    June Patch Tuesday brings a lighter load for defenders

    TechAiVerseBy TechAiVerseJune 11, 2025No Comments5 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    June Patch Tuesday brings a lighter load for defenders
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    June Patch Tuesday brings a lighter load for defenders

    Barely 70 vulnerabilities make the cut for Microsoft’s monthly security update, but an RCE flaw in WEBDAV and an EoP issue in Windows SMB Client still warrant close attention.

    By

    • Alex Scroxton,
      Security Editor

    Published: 10 Jun 2025 19:55

    Microsoft’s latest Patch Tuesday update landed on schedule around teatime on 10 June, with admins facing a much lighter load heading into the summer – at least lighter than of late – with barely 70 security flaws awaiting attention and just two potential zero-day common vulnerabilities and exposures (CVEs) in scope.

    The two most pressing issues for patching this month are CVE-2025-33053, a remote code execution (RCE) flaw in Web Distributed Authoring and Versioning (WEBDAV), and CVE-2025-33073, an elevation of privilege (EoP) vulnerability in Windows Server Message Block (SMB) Client. Both carry a CVSS score of 8.8.

    Microsoft revealed it has evidence that the first of these CVEs is already being exploited in the wild, although proof-of-concept code is not publicly available, while for the second, the opposite is true. It credited the RCE flaw to Alexandra Gofman and David Driker of Check Point Research, and the second to researchers with CrowdStrike, Synacktiv, SySS GmbH, and Google Project Zero.

    Of these two, CVE-2025-33053 probably presents the most pressing patching need. This is because in practice, the issue affects various tools that still incorporate the defunct Internet Explorer browser in a legacy capacity, hence Microsoft has been forced into the position of producing patches for long out-of-support platforms, dating back as far as Windows 8 and Server 2012.

    “This vulnerability allows attackers to execute remote code on affected systems when users click on malicious URLs,” explained Mike Walters, president and co-founder of patch management specialist Action1.

    “The exploit takes advantage of WebDAV’s file handling capabilities to run arbitrary code in the context of the current user. If the user holds administrative privileges, the impact can be severe.  

    “What makes this flaw particularly concerning is the widespread use of WebDAV in enterprise environments for remote file sharing and collaboration. Many organisations enable WebDAV for legitimate business needs – often without fully understanding the security risks it introduces,” said Walters.

    “The potential impact is extensive, with millions of organisations worldwide at risk. An estimated 70 to 80% of enterprises could be vulnerable – especially those lacking strict URL filtering or user training on phishing threats,” he added.

    Meanwhile, Ben Hopkins, cyber threat intelligence researcher at Immersive, ran the rule over the second potential zero-day, CVE-2023-33073.

    “It’s classified as an Elevation of Privilege vulnerability, which indicates that a successful exploit would allow an attacker to gain higher-level permissions on a compromised system,” explained Hopkins.

    “Threat actors highly seek out vulnerabilities of this nature. Once an attacker has gained an initial foothold on a machine, often through methods like phishing or exploiting another vulnerability, they can leverage privilege escalation flaws to gain deeper control.”

    He continued: “With elevated privileges, an attacker could potentially disable security tools, access and exfiltrate sensitive data, install persistent malware, or move laterally across the network to compromise additional systems.

    “Given the high severity rating and the critical role of SMB in Windows networking, organisations should prioritise applying the necessary security patches to mitigate the risk posed by this vulnerability.”

    10 critical flaws, hanging on the wall

    The Microsoft June Patch Tuesday update also includes no fewer 10 critical flaws – four affecting Microsoft Office, and one apiece in Microsoft SharePoint Server, Power Automate, Windows KDC Proxy Service (KPSSVC), Windows Netlogon, Windows Remote Desktop Services and Windows Schannel. Of these, eight – including all four office vulns – are RCE issues, and the other two enable privilege escalation.

    Kev Breen, senior director of threat research at Immersive, said defenders should put the Office vulnerabilities high on their list of priorities.

    “Listed as a use after free, heap-based buffer overflow, and type confusion RCE, these vulnerabilities would allow an attacker to craft a malicious document that, if sent and opened by a victim, would give the attacker access to run commands on the victim’s computer remotely,” said Breen.

    “Microsoft also says that ‘The Preview Pane’ is an attack vector, meaning that simply viewing the attachment in something like Outlook could be enough to trigger the exploit.

    “More concerning is that Microsoft says there are no updates available for Microsoft 365 at the time of release, and customers will be notified via a revision to this notice,” said Breen.

    “While this CVE is not actively being exploited, the risk remains high as threat actors have been known to quickly reverse engineer patches to create n-day exploits before organisations have a chance to roll out patches,” he added.

    Read more on Application security and coding requirements


    • Microsoft tackles 5 Windows zero-days on May Patch Tuesday

      By: Tom Walat


    • May Patch Tuesday brings five exploited zero-days to fix

      By: Alex Scroxton


    • Microsoft’s April 2025 bumper Patch Tuesday corrects 124 bugs

      By: Brian McKenna


    • Exploited Windows zero-day addressed on April Patch Tuesday

      By: Tom Walat

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleUnity launches new Audience Hub for privacy-first ad campaigns
    Next Article West Brom Building Society project to meet customers’ digital demands
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    ‘AI is permeating everything we do’: How Guitar Center developed 2 AI tools this year

    December 4, 2025

    Media Briefing: Publishers turn to vertical video to compete with creators and grow ad revenue in 2026

    December 4, 2025

    From lawsuits to lobbying: How publishers are fighting AI

    December 4, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025475 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025162 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202586 Views

    Is Libby Compatible With Kobo E-Readers?

    March 31, 202563 Views
    Don't Miss
    Gaming December 4, 2025

    Stop Killing Games is a consumer-driven shake up for digital distribution as a whole | Opinion

    Stop Killing Games is a consumer-driven shake up for digital distribution as a whole |…

    Goat Simulator creators reveal new studio Feeble Minds

    Wreckreation maker Three Fields Entertainment puts whole studio on redundancy notice

    Clair Obscur: Expedition 33 becomes 2025’s top third-party release on Xbox Game Pass

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Stop Killing Games is a consumer-driven shake up for digital distribution as a whole | Opinion

    December 4, 20250 Views

    Goat Simulator creators reveal new studio Feeble Minds

    December 4, 20250 Views

    Wreckreation maker Three Fields Entertainment puts whole studio on redundancy notice

    December 4, 20250 Views
    Most Popular

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views

    Volkswagen’s cheapest EV ever is the first to use Rivian software

    March 12, 20250 Views

    Startup studio Hexa acquires majority stake in Veevart, a vertical SaaS platform for museums

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.