ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

August 2025 Patch Tuesday forecast: Try, try again

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-49704
+1 in the same advisory: …49706
Authenticated Code Injection RCE in Microsoft SharePoint

CVE-2025-49704 is a code injection vulnerability (CWE-94) in Microsoft SharePoint that allows an authorized (authenticated) attacker to execute arbitrary code on the server over the network, by sending requests whose attacker-controlled input SharePoint executes as code. It can be chained with CVE-2025-49706, and Microsoft subsequently issued CVE-2025-53770 as a patch bypass of the original CVE-2025-49704 fix, meaning the CVE-2025-53770 updates provide stronger protection and should be treated as the definitive remediation. Successful exploitation yields remote code execution on the SharePoint server, and CISA added the flaw to the KEV on 2025-07-22 with known ransomware use. Organizations running on-premises SharePoint Server are affected; CISA directs owners of public-facing servers running EOL/EOS versions (SharePoint Server 2013 and earlier) to disconnect them, and operators of supported versions to apply the CISA and vendor mitigations and updates, with cloud SharePoint services governed by BOD 22-01. Exploitation is confirmed in the wild and EPSS assigns a 100% probability of exploitation within 30 days (top percentile), although no public proof-of-concept code is documented.

Do: Apply Microsoft's SharePoint Server updates for CVE-2025-53770, which supersede the original CVE-2025-49704 fixes with more robust protection, prioritizing internet-facing servers. Disconnect public-facing SharePoint servers running EOL/EOS versions (SharePoint Server 2013 and earlier), and for supported versions follow the CISA and vendor mitigations, with cloud services handled per BOD 22-01. Because in-the-wild exploitation and ransomware use are confirmed, hunt for indicators of compromise and ransomware activity on exposed SharePoint servers.

8.8
group max
100% KEV ransomware
  • Microsoft SharePoint CISA lists 'Microsoft SharePoint' without enumerating specific version ranges; the CISA KEV guidance targets on-premises SharePoint Server, calling out SharePoi
masstens of thousands of internet-exposed SharePoint servers per public scans, within a total on-premises install base plausibly exceeding 100,000 deployments…
CVE-2025-53770
Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises

CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation.

9.8100% KEV ransomware PoC ×3
  • Microsoft SharePoint Server (on-premises) Specific version ranges not enumerated in the source data; Microsoft SharePoint on-premises is affected. CISA notes SharePoint Server 2013 and earlier are EOL/E
mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users
CVE-2025-53771
Improper Authentication in Microsoft SharePoint Server Enables Network Spoofing

CVE-2025-53771 is an improper authentication flaw (CWE-287) in Microsoft's on-premises SharePoint Server that allows an unauthenticated remote attacker to conduct spoofing over the network. Per the CVSS vector, exploitation requires no privileges and no user interaction, so an attacker who can reach the SharePoint server over the network can trigger it directly. Successful exploitation lets the attacker impersonate an authenticated user or component, producing limited but real impact on confidentiality and integrity (CVSS 6.5, medium). Any organization running on-premises SharePoint Server is affected, particularly those exposing it to the internet; no specific version numbers are provided in the source data, so defenders should consult Microsoft's advisory for their edition. No public PoC exists and it is not yet in CISA's KEV, but exploitation likelihood is near-certain (EPSS 99.7%, 100th percentile), and Microsoft has confirmed active China-linked nation-state exploitation of the closely related SharePoint ToolShell vulnerability chain, which has hit roughly 400 organizations including U.S. federal agencies.

Do: Apply Microsoft's SharePoint Server security updates that ship this fix as soon as possible, prioritizing internet-facing servers, and treat this as urgent because it was patched alongside the actively exploited ToolShell chain. While patching, review authentication and web-server logs on SharePoint hosts for unexpected successful logons or anomalous requests that could indicate spoofing or compromise, and restrict network access to SharePoint (VPN, firewall rules, segmentation) if patching must be delayed.

6.5100%
  • Microsoft SharePoint Server (on-premises)
largeTens of thousands of internet-facing SharePoint Server deployments, with a total on-prem installed base plausibly in the hundreds of thousands (estimate)
CVE-2025-53786
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix.

On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment.

NVD description · AI analysis pending
8.07%
  • microsoft exchange server
  • microsoft exchange server subscription edition
CVE-2025-6558
Actively Exploited Input Validation Flaw in Chrome ANGLE/GPU Allows Sandbox Escape

CVE-2025-6558 is an improper input validation flaw (CWE-20) in the ANGLE graphics translation layer and GPU processing code of Google Chrome/Chromium prior to version 138.0.7204.157. A remote attacker can trigger it by convincing a user to open a crafted HTML page (user interaction is required), and successful exploitation potentially enables a sandbox escape from the browser's renderer with high impact on confidentiality, integrity, and availability. Per the CPE data, exposure extends beyond Chrome to Debian's Chromium package, Apple Safari and its operating systems (iOS, iPadOS, macOS, visionOS, watchOS), and the WebKitGTK and WPE WebKit ports, consistent with the shared ANGLE/WebKit code. Google fixed the issue in Chrome 138.0.7204.157, and CISA added the flaw to the KEV catalog on 2025-07-22, confirming active exploitation in the wild (ransomware use: unknown). EPSS assigns a 9.6% probability of exploitation within 30 days (95th percentile); no public proof-of-concept is known.

Do: Upgrade Google Chrome/Chromium to 138.0.7204.157 or later immediately, as the flaw is being actively exploited and is KEV-listed. Debian users should install the distribution's patched Chromium package, and operators of Apple platforms, WebKitGTK, or WPE WebKit deployments should apply the corresponding vendor security updates. Federal agencies must apply vendor mitigations per BOD 22-01 within the required timeframe or discontinue use if mitigations are unavailable.

8.810% KEV
  • Google Chrome prior to 138.0.7204.157
  • Google Chromium prior to 138.0.7204.157
  • Debian Linux (Chromium package)
  • +8 more
massbillions of users/installations (Chrome and Chromium-derived browsers)
Full article730 words · extracted from helpnetsecurity.com · click to collapse

July turned into a surprisingly busy month. It started slowly with a fairly ‘calm’ Patch Tuesday as I forecasted in my last blog. Although there were 130 new CVEs addressed across all the Microsoft releases, there was only one publicly disclosed CVE, so the risk was low. But a short time later, two CVEs in SharePoint were reported exploited, and the month started to heat up with hotfixes near the end of the month. Mix in some security configuration issues with Microsoft Exchange Server and some major updates from Google and Apple, and the month ended with lots of activity.

August 2025 Patch Tuesday forecast

CISA flags SharePoint flaws as Microsoft issues new fixes

It can take a few iterations to completely fix a vulnerability. Microsoft found this out with a recent round of SharePoint vulnerability fixes. Earlier this year in the Berlin Pwn2Own contest, a series of vulnerabilities called the ‘ToolShell’ chain were exploited and subsequently fixed in the Microsoft July 2025 Patch Tuesday updates. The key vulnerabilities a CVE-2025-49704 SharePoint Remote Code Execution Vulnerability and CVE-2025-49706 SharePoint Server Spoofing Vulnerability.

Not long after this release, Microsoft, Google, and others reported these fixes had been bypassed and many organizations had been compromised. On July 19th Microsoft released an update with a more ‘hardened’ fix with associated vulnerabilities CVE-2025-53770 and CVE-2025-53771. There are separate releases for Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019 and Microsoft SharePoint Enterprise Server 2016. In addition to applying the updates, Microsoft recommends you rotate the associated machine keys on the impacted servers.

There is reported ransomware that is taking advantage of this ToolShell attack chain and CISA has included them in their catalog of exploited vulnerabilities for immediate fix by federal agencies. Anticipate these hotfixes will be included in the August Patch Tuesday releases as well.

Zero-Day in Chromium, dozens of Apple CVEs fixed in latest releases

Microsoft issued CVE-2025-53786 to address security issues with respect to Microsoft Exchange Server in hybrid environments. This CVE ties together the April update and security hotfix with a series of instructions on securing on-premise Microsoft Exchange Server and Exchange Online. They share credentials and data such as calendars, email contact lists, etc. which can lead to compromise with little logging to show what happened. This Exchange Server blog, provides extensive details on the upcoming EOL of Exchange products as well as migration options to a more secure configuration.

There are a few other major non-Microsoft updates to be aware of since last July 2025 Patch Tuesday. Google continues with weekly updates to the Chromium browser with a release on July 16th to address several vulnerabilities including zero-day CVE-2025-6558. This vulnerability allowed a remote attacker to potentially perform a sandbox escape. Apple also released a series of major updates for its operating systems and applications. Of note, from these updates include Ventura 13.7.7 with 41 CVEs, Sonoma 14.7.7 with 50 CVEs, Sequioa 15.6 with 89 CVEs, and Safari for Ventura and Sonoma with 17 CVEs fixed.

August Patch Tuesday forecast

  • We know SharePoint will receive some important updates this month and don’t forget there is more to do than just applying the updates and walking away – you need to consider updating your machine keys. Expect all the usual OS and app updates, but it’s been a while so may see a security fix in.NET framework or maybe SQL Server this month.
  • Adobe continues with a steady stream of updates for the Creative Cloud suite of products so expect more this month with maybe Photoshop being the focus.
  • Apple released their major updates on July 29th, and since we haven’t heard of any major issues, we should have a break for another month or two. Just make sure you have all the latest updates deployed.
  • Google releases Chrome updates almost every Patch Tuesday but be aware they are often seen late in the day.
  • The last set of security releases from Mozilla was July 22nd, so we are due for the Firefox and Thunderbird updates along with their ESR versions.

Fixing vulnerabilities in software can often seem like plugging holes in a dam – just when you get one fixed, another leak appears. Microsoft found that out with these recent SharePoint vulnerabilities, but we’ve seen it before (remember Print NightMare) and we’ll see it again. Let’s just hope this time they don’t need to try, try again.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/08/08/august-2025-patch-tuesday-forecast/