July 2025 Patch Tuesday forecast: Take a break from the grind
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-51978 | An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request. NVD description · AI analysis pending | 9.8 | 19% | — | — | ||
| CVE-2025-47981 | Unauthenticated Heap Buffer Overflow RCE in Windows SPNEGO (CVE-2025-47981) CVE-2025-47981 is a critical (CVSS 9.8) heap-based buffer overflow (CWE-122) in the Windows SPNEGO Extended Negotiation component, part of Windows' Negotiate authentication stack. An unauthenticated remote attacker can trigger the overflow by sending specially crafted authentication negotiation traffic to a service that processes SPNEGO/Negotiate authentication over the network. Successful exploitation yields remote code execution with no privileges or user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), and press coverage of the July 2025 release describes the bug as potentially wormable. All listed supported Windows 10 and Windows 11 client builds and Windows Server 2008, 2012, 2016 and 2019 are affected, since SPNEGO is a default Windows component. The flaw was fixed in the July 2025 Patch Tuesday; it is not yet in CISA KEV and Microsoft reported no active exploitation, but public proof-of-concept code and detection/mitigation scripts exist, and EPSS estimates a 32.6% probability of exploitation within 30 days (98th percentile). Do: Apply the July 2025 Microsoft Patch Tuesday security updates (the cumulative updates for the affected Windows 10/11 client branches and Windows Server 2008/2012/2016/2019) on all systems, prioritizing internet-facing servers and hosts that accept Negotiate/SPNEGO authentication such as web and application servers. Until patched, limit untrusted network access to services using Negotiate authentication and use the published third-party detection and mitigation scripts (e.g., the Vicarius scripts referenced in public coverage) to identify and contain vulnerable hosts. No active exploitation has been reported as of the July 2025 release, but public PoCs exist, so patch before widespread scanning or weaponization begins. | 9.8 | 33% | PoC ×3 |
| mass≈1 billion+ Windows client and server installations (SPNEGO/Negotiate is a default Windows component present on every in-scope Windows 10/11 and Server build) | |
| CVE-2025-6554 | Type Confusion in Google Chrome V8 Allows Arbitrary Read/Write (Actively Exploited) CVE-2025-6554 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine of Google Chrome, affecting versions prior to 138.0.7204.96. A remote attacker can trigger it by inducing a user to open a crafted HTML page, and the flaw permits arbitrary read and write within the browser renderer process. Successful exploitation yields high confidentiality and integrity impact, and V8 type confusion bugs are commonly used as the first stage toward a full browser compromise. Any user of an unpatched Chrome or Chromium-based browser is exposed, and the flaw is being actively exploited in the wild as a zero-day; CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-02. Ransomware usage is not confirmed (reported as unknown), and no public proof-of-concept is known. Do: Update Chrome to 138.0.7204.96 or later (check chrome://settings/help) and restart the browser to load the patched V8; users of Chromium-derived browsers (Edge, Brave, Opera, etc.) should install their vendor's corresponding V8 patch. Organizations must apply vendor mitigations or follow BOD 22-01 guidance given the KEV listing, and should inventory managed browsers and force-update policies to confirm rollout. | 8.1 | 13% | KEV |
| mass≈3+ billion Chrome users; effectively every desktop Chrome installation running a build older than 138.0.7204.96 |
Full article721 words · extracted from helpnetsecurity.com · click to collapse
July 2025 Patch Tuesday is now live:
Microsoft fixes critical wormable Windows flaw (CVE-2025-47981)

There was a barrage of updates released the week of June 2025 Patch Tuesday. This included security updates from Adobe, Google, Microsoft, Mozilla, and others. But it has been ‘calm’ the past couple of weeks. The news and message boards were covering the continuing update issues from the past couple of months but there wasn’t a lot of new or exciting information. If this lull in activity continues, maybe we’ll be able to get a break from the grind next week and have an ‘easy’ Patch Tuesday. Already halfway through the year, it would be nice to take a little time and enjoy the summer.

Game crashes, delayed updates, and DHCP disruptions
My article last month covered some of the issues encountered with recent OS updates and the out-of-band (OOB) patch releases. The trend continued this month for some users. The day after Patch Tuesday, Microsoft immediately released another update KB5063060 for Windows 11 24H2. This was done to address a BSOD issue due to incompatibility with the Easy Anti-Cheat service used by many games. Microsoft soon followed that up with an update to the June 10 release of KB5060842.
Per Microsoft in that KB – “Some devices in environments where IT admis use quality update (QU) deferral policies might experience delays in receiving the June 2025 Windows security update. Although the update was released on June 10, 2025, its update metadata timestamp reflects a date of June 20, 2025. This discrepancy might cause devices with configured deferral periods to receive the update later than expected.” The workaround is to create an expedite policy to deliver the update immediately, or to adjust the dates in your deployment rings to expedite the patch.
Microsoft also reported soon after Patch Tuesday that DHCP server service might stop responding or refuse to connect after the June 2025 update is applied to Windows Server 2016 through version 2025. The workaround is to roll back the latest updates. I’ve not seen any newer announcements regarding this, so be on the lookout for a fix in the upcoming July release.
Chrome zero-day patched, printer flaws revealed
Google reported a fix for their fourth zero-day vulnerability of the year. They just announced on June 30th, the Stable channel had been updated to 138.0.7204.96/.97 for Windows, 138.0.7204.92/.93 for Mac and 138.0.7204.92 for Linux. This was in response to CVE-2025-6554 which was listed as ‘type confusion in V8’, the JavaScript engine. No details were given about the known exploitation.
In a different type of print nightmare, Rapid7 reported 8 vulnerabilities it found in 5 different printer manufacturers. As reported, the most serious is CVE-2024-51978 with a CVSS 9.8, where an unauthenticated attacker who knows the target device’s serial number, can generate the default administrator password for the device. This vulnerability cannot be fixed in firmware but can only be addressed in a new manufacturing process.
The good news is that this CVE is only an issue if you haven’t reset the default password. This project has been several months in the making, so please read the article and take steps to protect your printing devices from exploitation.
July 2025 Patch Tuesday forecast
- Microsoft has been working hard on Office the last several months, so look for continued security fixes in all the Office products. We haven’t seen a security fix in the .NET framework or any of the dedicated server software in several months.
- Adobe Acrobat and Reader received an update last month, but look for updates in the popular programs of Creative Cloud this month like Photoshop and Illustrator.
- Security updates could be on the way for Sequoia, Sonoma, and Ventura since they were last updated on May 12th. They will include the standalone and embedded updates for Safari as well.
- If you haven’t picked up the zero-day release yet, be sure to include Chrome update in your deployment. Google releases almost every Patch Tuesday.
- Mozilla released security updates for Firefox back on June 24 and followed up with related Thunderbird updates. I’m not sure how to call this one, but be on the lookout for a Firefox release soon.
June 2025 has been a quiet month with regards to big announcements and patch updates. Let’s hope that continues into this Patch Tuesday.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/07/07/july-2025-patch-tuesday-forecast/