Microsoft Patch Tuesday addresses 81 vulnerabilities, none actively exploited
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-55234 +1 in the same advisory: …54918 | SMB Relay Elevation of Privilege in Microsoft Windows SMB Server CVE-2025-55234 is an improper authentication flaw (CWE-287) in the Microsoft SMB Server that leaves systems susceptible to credential relay attacks when SMB signing and Extended Protection for Authentication (EPA) are not enforced. It is configuration-dependent: an attacker who can induce an authenticated SMB connection, for example by tricking a user or machine into connecting to attacker-controlled resources, can relay the credentials to another host and authenticate as that user. Successful relaying grants the attacker the privileges of the relayed user, up to elevation of privilege on target systems, with high impact on confidentiality, integrity and availability. Affected systems span Windows 10 (1507 through 22H2), Windows 11 (22H2 through 24H2), and Windows Server 2008, 2012, 2016 and 2019, although only environments without SMB signing/EPA hardening are practically exploitable. As of the September 2025 Patch Tuesday release there is no known in-the-wild exploitation or public proof of concept, but EPSS assigns a 20.1% probability of exploitation within the next 30 days (97th percentile). Do: Install the September 2025 (or later) Microsoft security updates, which add SMB Server Hardening audit capabilities, and use the new audit events to identify clients, servers or legacy software that would break if SMB signing and EPA are enforced. After remediating incompatibilities, enable SMB Server signing and Extended Protection for Authentication on SMB servers to close the relay exposure, prioritizing domain controllers and file servers. Note that systems already enforcing both signing and EPA are not practically exposed. | 9.8 group max | 20% |
| masshundreds of millions of Windows 10/11 devices plus millions of Windows Server instances are potentially exposed, though only those lacking SMB signing/EPA… | ||
| CVE-2025-55232 | Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 9.8 | 2% |
| — |
Full article783 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The company is ahead of pace, disclosing about 100 more vulnerabilities at this point in the year than it did in 2024, according to a researcher.
Listen to this article
0:00
Learn more.
Microsoft addressed 81 vulnerabilities affecting its enterprise products and underlying Windows systems, but none have been actively exploited, the company said in its latest security update.
The company’s monthly bundle of patches includes one high-severity vulnerability and eight critical defects, including three designated as more likely to be exploited.
The most severe defect disclosed this month — CVE-2025-55232 — is a deserialization of untrusted data vulnerability affecting Microsoft High Performance Compute Pack with a CVSS rating of 9.8. Microsoft said exploitation is less likely, but researchers warned organizations to prioritize patching.
“A remote, unauthenticated attacker could achieve code execution on affected systems without user interaction, which makes this potentially wormable between systems with the HPC pack installed,” Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, said in a blog post.
Childs noted that Microsoft has disclosed about 100 more vulnerabilities at this point in the year than it did in 2024. “We’ll see if this level of patches remains high throughout the rest of the year,” he added.
Of the critical defects addressed this month, researchers are particularly concerned about CVE-2025-54918 and CVE-2025-55234 — elevation of privilege vulnerabilities with 8.8 CVSS ratings. While not actively exploited, Microsoft said exploitation is more likely for both of the improper authentication defects.
CVE-2025-55234 affects the Windows Server Message Block protocol, allowing hackers to perform relay attacks and subject users to elevation of privilege attacks. Proof-of-concept exploit code exists for this defect, according to Action1, but exploitation requires user interaction and network access.
“At its core, the vulnerability exists because SMB sessions can be established without properly validating the authentication context when key hardening measures, such as SMB signing and extended protection for authentication, are not in place,” Mike Walters, president and co-founder of Action1, said in an email.
“The potential impact is massive,” he added. “Virtually all medium to large enterprises that rely on Active Directory and Windows Server infrastructure could be affected, which amounts to hundreds of thousands of organizations worldwide.”
CVE-2025-54918 affects Windows New Technology LAN Manager (NTLM), which are security protocols for user identity authentication. “This privilege escalation allows an authenticated threat actor to escalate to SYSTEM on affected systems over the network,” Childs said.
“While not a scope change, going from a standard Windows user to SYSTEM is handy. Microsoft also notes that exploit complexity is low, so expect to see threat actors target this one,” he added.
Alex Vovk, CEO and co-founder of Action1, said the defect allows attackers to bypass and potentially undermine security controls, presenting substantial risk in sophisticated attack scenarios. “After compromising one system, attackers could use it to move laterally through networks with elevated access,” Vovk said.
“Threat actors could exploit it to deploy ransomware across multiple systems. Its high confidentiality impact means it could be used in sophisticated data theft operations,” he added. “The elevated privileges gained could also allow attackers to install backdoors or establish persistent access.”
Microsoft flagged eight defects as more likely to be exploited this month, including three that affected the Windows Kernel. The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-september-2025/