ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Microsoft Patch Tuesday addresses 66 vulnerabilities, including an actively exploited zero

criticalVulnerability exploited in the wildimportance 60CVE-2025-33053CVE-2025-47966

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-33053
Remote Code Execution in Microsoft Windows Internet Shortcut Files (CVE-2025-33053)

CVE-2025-33053 is an external control of file name or path flaw (CWE-73) in how Windows processes Internet Shortcut (.url) files, allowing an unauthorized attacker to execute code over a network by making the shortcut resolve to an attacker-controlled path, such as a WebDAV share. Exploitation requires user interaction (CVSS vector UI:R): a user opening a crafted .url file, typically delivered via phishing, causes Windows to fetch and run content from the attacker-specified location, yielding remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). All supported Windows 10 and Windows 11 client versions and Windows Server 2008, 2012, 2016, and 2019 are affected. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-10, Microsoft patched it in the June 2025 Patch Tuesday release, and Check Point research tied it to a cyber-espionage campaign by the Stealth Falcon actor against a major Turkish defense organization. EPSS estimates an 85.4% probability of exploitation within 30 days (100th percentile).

Do: Apply Microsoft's June 2025 security updates to all affected Windows 10/11 clients and Windows Server 2008/2012/2016/2019 hosts, consistent with the KEV required action and BOD 22-01 timelines for federal agencies. Until patched, consider disabling the Windows WebDAV client where it is not needed and treat unsolicited .url shortcut files as untrusted; given confirmed espionage use, hunt for signs of exploitation on high-value endpoints.

8.888% KEV PoC ×3
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008, 2012, 2016, 2019
mass≈1 billion+ Windows devices (all listed Windows 10/11 client and mainstream Windows Server releases are affected)
CVE-2025-47966
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.

Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.

NVD description · AI analysis pending
9.81%
  • microsoft power automate for desktop
Full article657 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

A researcher tells CyberScoop that up to 80% of enterprises could be vulnerable to the zero-day Microsoft patched in its June update.

Microsoft logo is seen in a Microsoft store on March 10, 2021, in New York.(Photo by John Smith/VIEWpress)

Microsoft addressed 66 vulnerabilities across its suite of products and systems, including a zero-day in WebDAV that allows unauthorized attackers to remotely execute code, the company said in its latest security update Tuesday. 

The espionage group Stealth Falcon exploited the zero-day — CVE-2025-33053 — to execute malware on a defense company in Turkey in March, Check Point Research said in a threat report Tuesday. “Stealth Falcon’s activities are largely focused on the Middle East and Africa, with high-profile targets in the government and defense sectors observed in Turkey, Qatar, Egypt and Yemen,” researchers said.

According to security researchers, Stealth Falcon has been carrying espionage operations and deploying spyware against journalists, activists and dissidents since at least 2012.

“We are aware of a few organizations [impacted by the zero-day exploit] at the moment, and the CVE was only used by Stealth Falcon,” Eli Smadga, research group manager at Check Point Research, said via email. “The activity appears to be highly targeted, affecting specific victims rather than being widespread.”

The Cybersecurity and Infrastructure Security Agency added CVE-2025-33053 to its known exploited vulnerabilities catalog on Tuesday.

The espionage group’s recent operations “showcase a creative approach to infection chains by leveraging WebDAV, LOLBins, multi-stage loaders, and a mix of native and .NET components,” Check Point Research said in the threat report.

WebDAV, a set of extensions to the HTTP protocol that allows users to share and edit files remotely, is used widely across enterprise systems and often poorly secured, according to Mike Walters, president and co-founder of Action1. 

“Many organizations enable WebDAV for legitimate business needs — often without fully understanding the security risks it introduces,” Walters said in an email. “The potential impact is extensive, with millions of organizations worldwide at risk.”

Walters estimates up to 80% of enterprises could be vulnerable to the zero-day Microsoft patched in its Patch Tuesday security update.

The batch of CVE disclosures and patches in Microsoft’s monthly security update includes one critical vulnerability, 43 high-severity defects and 22 flaws with an initial CVSS score in the medium-severity range. 

The lone critical vulnerability — CVE-2025-47966 — exposes sensitive information to an unauthorized user in Power Automate, allowing an unauthorized attacker to escalate privileges.

Seventeen of the vulnerabilities in this month’s security update affect Microsoft Office and standalone Office products, including three defects Microsoft described as more likely to be exploited.

The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-june-2025/