CVE-2025-33053
published 2025-06-10CVE-2025-33053: External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
PriorityP191high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-07-01
Exploited in the wild
EPSS
81.56%
99.6th percentile
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.21034 | 10.0.10240.21034 |
| microsoft | windows_10_1607 | < 10.0.14393.8148 | 10.0.14393.8148 |
| microsoft | windows_10_1809 | < 10.0.17763.7434 | 10.0.17763.7434 |
| microsoft | windows_10_21h2 | < 10.0.19044.5965 | 10.0.19044.5965 |
| microsoft | windows_10_22h2 | < 10.0.19045.5965 | 10.0.19045.5965 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.21034 | 10.0.10240.21034 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.8148 | 10.0.14393.8148 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.7434 | 10.0.17763.7434 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.5965 | 10.0.19044.5965 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.5965 | 10.0.19045.5965 |
| microsoft | windows_11_22h2 | < 10.0.22621.5472 | 10.0.22621.5472 |
| microsoft | windows_11_23h2 | < 10.0.22631.5472 | 10.0.22631.5472 |
| microsoft | windows_11_24h2 | < 10.0.26100.4270 | 10.0.26100.4270 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.5472 | 10.0.22621.5472 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.5472 | 10.0.22631.5472 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.5472 | 10.0.22631.5472 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.4349 | 10.0.26100.4349 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27769 | 6.1.7601.27769 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.23351 | 6.0.6003.23351 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25522 | 6.2.9200.25522 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22620 | 6.3.9600.22620 |
| microsoft | windows_server_2016 | < 10.0.14393.8148 | 10.0.14393.8148 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.8148 | 10.0.14393.8148 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-33053 exploits WebDAV via malicious .url (Internet Shortcut) files; monitor for LNK/URL files referencing remote WebDAV paths (UNC paths to WebDAV servers) combined with rundll32.exe execution. ↗
- →Monitor for rundll32.exe spawned with a WebDAV UNC working directory (\\<host>\DavWWWRoot) and shell32.dll Control_RunDLL arguments loading a remote DLL — a living-off-the-land technique used in CVE-2025-33053 exploitation. ↗
- →Stealth Falcon group targets government and defense entities in the Middle East and Africa using spear-phishing with malicious .url files exploiting CVE-2025-33053; tools include keyloggers, credential dumpers, and the custom 'Horus Agent' implant. ↗
- →Check Point IPS signature available: 'Microsoft Web Distributed Authoring and Versioning Remote Code Execution (CVE-2025-33053)' ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-26qv-p8cr-jxp5: External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network
ghsa_unreviewed·2025-06-10
CVE-2025-33053 [HIGH] CWE-73 GHSA-26qv-p8cr-jxp5: External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network
External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network.
VulnCheck
Microsoft Windows External Control of File Name or Path Vulnerability
vulncheck·2025·CVSS 8.8
CVE-2025-33053 [HIGH] CWE-73 Microsoft Windows External Control of File Name or Path Vulnerability
Microsoft Windows External Control of File Name or Path Vulnerability
Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2025-Jun; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33053; https://research.checkpoint.com/2025/stealth-
CISA
Microsoft Windows External Control of File Name or Path Vulnerability
cisa·2025-06-10·CVSS 8.8
CVE-2025-33053 [HIGH] CWE-73 Microsoft Windows External Control of File Name or Path Vulnerability
Vulnerability: Microsoft Windows External Control of File Name or Path Vulnerability
Affected: Microsoft Windows
Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053 ; https://nvd.nist.gov/vuln/detail/CVE-2025-33053
Remediation Due Date: 2025-07-01
Microsoft
Internet Shortcut Files Remote Code Execution Vulnerability
vendor_msrc·2025-06-10·CVSS 8.8
CVE-2025-33053 [HIGH] CWE-73 Internet Shortcut Files Remote Code Execution Vulnerability
Internet Shortcut Files Remote Code Execution Vulnerability
Description: External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
FAQ: The Security Updates table indicates that this vulnerability affects all supported versions of Microsoft Windows. Why are IE Cumulative updates listed for Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, and Windows Server 2012 R2?
While Microsoft has announced retirement of the Internet Explorer 11 application on certain platforms and the Microsoft Edge Legacy application is deprecated, the underlying MSHTML, EdgeHTML, and scripting platforms are still supported. The MSHTML platform is used by Internet Explorer mode in Microsoft Edge as well as other applications thr
Exploit-DB
WebDAV Windows 10 - Remote Code Execution (RCE)
exploitdb·2025-06-15·CVSS 8.8
CVE-2025-33053 [HIGH] WebDAV Windows 10 - Remote Code Execution (RCE)
WebDAV Windows 10 - Remote Code Execution (RCE)
---
Exploit Title: WebDAV Windows 10 - Remote Code Execution (RCE)
Date: June 2025
Author: Dev Bui Hieu
Tested on: Windows 10, Windows 11
Platform: Windows
Type: Remote
CVE: CVE-2025-33053
Description:
This exploit leverages the behavior of Windows .URL files to execute a
remote binary over a UNC path. When a victim opens or previews the .URL
file (e.g. from email), the system may automatically reach out to the
specified path (e.g. WebDAV or SMB share), leading to arbitrary code
execution without prompt.
```bash
python3 gen_url.py --ip 192.168.1.100 --out doc.url
```
import argparse
def generate_url_file(output_file, url_target, working_directory, icon_file, icon_index, modified):
content = f"""[InternetShortcut]
URL={url_target}
Workin
Metasploit
CVE-2025-33053 Exploit via Malicious .URL File and WebDAV
metasploit·CVSS 8.8
CVE-2025-33053 [HIGH] CVE-2025-33053 Exploit via Malicious .URL File and WebDAV
CVE-2025-33053 Exploit via Malicious .URL File and WebDAV
This module exploits CVE-2025-33053 by generating a malicious .URL file pointing to a trusted LOLBAS binary with parameters designed to trigger unintended behavior. Optionally, a payload is generated and hosted on a specified WebDAV directory. When the victim opens the shortcut, it will attempt to access the WebDAV path, potentially resulting in remote code execution via a trusted binary.
Checkpoint
2025: The Untold Stories of Check Point Research
blogs_checkpoint·2026-02-23
CVE-2025-33053 2025: The Untold Stories of Check Point Research
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## 2025: The Untold Stories of Check Point Research
## Introduction
Check Point Research (CPR) continuously tracks threats, following the clues that lead to major players and incidents in t
Tenable
Patch Tuesday 2025 Year In Review
blogs_tenable·2025-12-10
Patch Tuesday 2025 Year In Review
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
Exploits and vulnerabilities in Q2 2025
blogs_securelist·2025-08-27·CVSS 8.2
CVE-2025-32433 [HIGH] Exploits and vulnerabilities in Q2 2025
Table of Contents
Statistics on registered vulnerabilities
Exploitation statistics
Windows and Linux vulnerability exploitation
Most common published exploits
Vulnerability exploitation in APT attacks
C2 frameworks
Interesting vulnerabilities
CVE-2025-32433: vulnerability in the SSH server, part of the Erlang/OTP framework
CVE-2025-6218: directory traversal vulnerability in WinRAR
CVE-2025-3052: insecure data access vulnerability in NVRAM, allowing bypass of UEFI signature checks
CVE-2025-49113: insecure deserialization vulnerability in Roundcube Webmail
CVE-2025-1533: stack overflow vulnerability in the AsIO3.sys driver
Conclusion and advice
Authors
Alexander Kolesnikov
Vulnerability registrations in Q2 2025 proved to be quite dynamic. Vulnerabilities that were published i
Securelist
Vulnerability landscape analysis for Q2 2025
blogs_securelist·2025-08-27
Vulnerability landscape analysis for Q2 2025
Table of Contents
- Statistics on registered vulnerabilities
- Exploitation statistics
- Vulnerability exploitation in APT attacks
- C2 frameworks
- Interesting vulnerabilities
- Conclusion and advice
Authors
- Alexander Kolesnikov
Vulnerability registrations in Q2 2025 proved to be quite dynamic. Vulnerabilities that were published impact the security of nearly every computer subsystem: UEFI, drivers, operating systems, browsers, as well as user and web applications. Based on our analysis, threat actors continue to leverage vulnerabilities in real-world attacks as a means of gaining access to user systems, just like in previous periods.
This report also describes known vulnerabilities used with popular C2 frameworks during the first half of 2025.
## Statistics on registered vulnera
Bleepingcomputer
Microsoft fixes Surface Hub boot issues with emergency update
blogs_bleepingcomputer·2025-06-17
Microsoft fixes Surface Hub boot issues with emergency update
## Microsoft fixes Surface Hub boot issues with emergency update
## Sergiu Gatlan
Microsoft has released an emergency update to fix a known issue causing startup failures for some Surface Hub v1 devices running Windows 10.
As the company explained when it acknowledged this issue last week, users see Secure Boot Violation errors on affected devices, prompting them to check the Secure Boot Policy in setup.
These boot problems only impact Surface Hub v1 systems running Windows 10, version 22H2, after installing the June 2025 Windows security update ( KB5060533 ). Microsoft also noted that these boot problems do not affect Surface Hub 2S and Surface Hub 3 devices.
While the company released a mitigation one day after discovering it to ensure that other systems would not be impacted after
Checkpoint
16th June – Threat Intelligence Report
blogs_checkpoint·2025-06-16
CVE-2025-33053 16th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 16th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 16th June, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
One of South Korea’s largest ticketing platforms Yes24 has been a victim of a ransomware attack that resulted in a four-day service outage, disrupting online bookings for concerts, e-book access, and community forums. The incident has caused significant turmoil in the entertainment industry, forcing event cancellations and dela
Bleepingcomputer
Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices
blogs_bleepingcomputer·2025-06-13·CVSS 8.8
[HIGH] Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices
## Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices
## Sergiu Gatlan
Microsoft is investigating a known issue that triggers Secure Boot errors and prevents Surface Hub v1 devices from starting up.
These boot problems only impact Surface Hub v1 systems running Windows 10, version 22H2, after installing the KB5060533 June 2025 Windows security update.
Microsoft says that "Surface Hub v1 devices might fail to start with the following error: 'Secure Boot Violation. Invalid signature detected. Check Secure Boot Policy in Setup."
It's also important to note that this known issue did not impact Surface Hub 2S and Surface Hub 3 devices, according to Redmond.
The company says it released a mitigation one day after discovering the issue, to ensure that other systems w
Bleepingcomputer
Windows 11 24H2 emergency update fixes Easy Anti-Cheat BSOD issue
blogs_bleepingcomputer·2025-06-12
Windows 11 24H2 emergency update fixes Easy Anti-Cheat BSOD issue
## Windows 11 24H2 emergency update fixes Easy Anti-Cheat BSOD issue
## Sergiu Gatlan
Microsoft has released an emergency Windows 11 24H2 update to address an incompatibility issue triggering restarts with blue screen of death (BSOD) errors on systems with Easy Anti-Cheat.
The out-of-band update ( KB5063060 ) is a revised version of the Windows 11 KB5060842 cumulative update released during this month's Patch Tuesday after many customers reported experiencing system reboots and IRQL_NOT_LESS_OR_EQUAL BSODs tied to ntoskrnl.exe or EasyAntiCheat_EOS.exe crashing on computers running various games, including Fortnite .
Microsoft said on Tuesday that the emergency update addressed a compatibility issue and rolled out to "a limited set of these devices" running Windows 11, version 24H2.
Ho
Bleepingcomputer
Microsoft creates separate Windows 11 24H2 update for incompatible PCs
blogs_bleepingcomputer·2025-06-11·CVSS 8.8
[HIGH] Microsoft creates separate Windows 11 24H2 update for incompatible PCs
## Microsoft creates separate Windows 11 24H2 update for incompatible PCs
## Sergiu Gatlan
Microsoft confirmed on Tuesday that it's pushing a revised security update targeting some Windows 11 24H2 systems incompatible with the initial update released during this month's Patch Tuesday.
"This update is being gradually rolled out to devices running Windows 11, version 24H2. We've identified a compatibility issue affecting a limited set of these devices," the company said in a Twitter thread.
"If your device is affected, you'll receive a revised update with all the June 2025 security improvements in the near term."
In a message center update on Tuesday, Redmond added that "the June 2025 security update is fully available for all other supported versions of Windows."
Microsoft has yet to
Krebs
Patch Tuesday, June 2025 Edition
blogs_krebs·2025-06-11·CVSS 8.8
CVE-2025-33053 [HIGH] Patch Tuesday, June 2025 Edition
Microsoft today released security updates to fix at least 67 vulnerabilities in its Windows operating systems and software. Redmond warns that one of the flaws is already under active attack, and that software blueprints showing how to exploit a pervasive Windows bug patched this month are now public.
The sole zero-day flaw this month is CVE-2025-33053 , a remote code execution flaw in the Windows implementation of WebDAV — an HTTP extension that lets users remotely manage files and directories on a server. While WebDAV isn’t enabled by default in Windows, its presence in legacy or specialized systems still makes it a relevant target, said Seth Hoyt , senior security engineer at Automox .
Adam Barnett , lead software engineer at Rapid7 , said Microsoft’s advisory for CVE-2025-33053 does
Bleepingcomputer
Hackers exploited Windows WebDav zero-day to drop malware
blogs_bleepingcomputer·2025-06-11·CVSS 8.8
CVE-2025-33053 [HIGH] Hackers exploited Windows WebDav zero-day to drop malware
## Hackers exploited Windows WebDav zero-day to drop malware
## Bill Toulas
An APT hacking group known as 'Stealth Falcon' exploited a Windows WebDav RCE vulnerability in zero-day attacks since March 2025 against defense and government organizations in Turkey, Qatar, Egypt, and Yemen.
Stealth Falcon (aka 'FruityArmor') is an advanced persistent threat (APT) group known for conducting cyberespionage attacks against Middle East organizations.
The flaw, tracked under CVE-2025-33053, is a remote code execution (RCE) vulnerability that arises from the improper handling of the working directory by certain legitimate system executables.
Specifically, when a .url file sets its WorkingDirectory to a remote WebDAV path, a built-in Windows tool can be tricked into executing a malicious executabl
Tenable
Microsoft’s June 2025 Patch Tuesday Addresses 65 CVEs (CVE-2025-33053)
blogs_tenable·2025-06-10·CVSS 8.8
[HIGH] Microsoft’s June 2025 Patch Tuesday Addresses 65 CVEs (CVE-2025-33053)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Microsoft and Adobe Patch Tuesday, June 2025 Security Update Review
blogs_qualys·2025-06-10
Microsoft and Adobe Patch Tuesday, June 2025 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for June 2025
Adobe Patches for June 2025
Zero-day Vulnerabilities Patched in June Patch Tuesday Edition
Critical Severity Vulnerabilities Patched in June Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response withPatch Management (PM)
Microsoft June 2025 Patch Tuesday Mitigations
Qualys Monthly Webinar Series
Microsoft’s June 2025 Patch Tuesday has landed, addressing a new batch of critical and important vulnerabilities across Windows and enterprise products. Here’s a quick breakdown of what you need to know.
## Microsoft Patch Tuesday for June 2025
In this month’s Patch Tuesday, June 2025
Qualys
Microsoft and Adobe Patch Tuesday, June 2025 Security Update Review | Qualys
blogs_qualys·2025-06-10
Microsoft and Adobe Patch Tuesday, June 2025 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for June 2025
- Adobe Patches for June 2025
- Zero-day Vulnerabilities Patched in June Patch Tuesday Edition
- Critical Severity Vulnerabilities Patched in June Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response withPatch Management (PM)
- Microsoft June 2025 Patch Tuesday Mitigations
- Qualys Monthly Webinar Series
Microsoft’s June 2025 Patch Tuesday has landed, addressing a new batch of critical and important vulnerabilities across Windows and enterprise products. Here’s a quick breakdown of what you need to know.
## Microsoft Patch Tuesday for June 2025
In this month’s Patch Tuesd
Checkpoint
CVE-2025-33053, Stealth Falcon and Horus: A Saga of Middle Eastern Cyber Espionage
blogs_checkpoint·2025-06-10·CVSS 8.8
CVE-2025-33053 [HIGH] CVE-2025-33053, Stealth Falcon and Horus: A Saga of Middle Eastern Cyber Espionage
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## CVE-2025-33053, Stealth Falcon and Horus: A Saga of Middle Eastern Cyber Espionage
## Key Findings
Check Point Research (CPR) discovered a new campaign conducted by the APT group Stealth
Bleepingcomputer
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws
blogs_bleepingcomputer·2025-06-10·CVSS 8.8
[HIGH] Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws
## Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws
## Lawrence Abrams
13 Elevation of Privilege Vulnerabilities
3 Security Feature Bypass Vulnerabilities
25 Remote Code Execution Vulnerabilities
17 Information Disclosure Vulnerabilities
6 Denial of Service Vulnerabilities
2 Spoofing Vulnerabilities
This count does not include Mariner, Microsoft Edge, and Power Automate flaws fixed earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5060842 and KB5060999 cumulative updates and the Windows 10 KB5060533 cumulative update .
## Two zero-days
This month's Patch Tuesday fixes one actively exploited zero-day and one publicly disclosed vulnerability. Microsoft classifies a zero-day
Krebs
Patch Tuesday, June 2025 Edition
blogs_krebs·2025-06-10·CVSS 8.8
CVE-2025-33053 [HIGH] Patch Tuesday, June 2025 Edition
Microsoft today released security updates to fix at least 67 vulnerabilities in its Windows operating systems and software. Redmond warns that one of the flaws is already under active attack, and that software blueprints showing how to exploit a pervasive Windows bug patched this month are now public.
The sole zero-day flaw this month is CVE-2025-33053, a remote code execution flaw in the Windows implementation of WebDAV — an HTTP extension that lets users remotely manage files and directories on a server. While WebDAV isn’t enabled by default in Windows, its presence in legacy or specialized systems still makes it a relevant target, said Seth Hoyt, senior security engineer at Automox.
Adam Barnett, lead software engineer at Rapid7, said Microsoft’s advisory for CVE-2025-33053 does not m
Crowdstrike
June 2025 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] June 2025 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33053https://research.checkpoint.com/2025/stealth-falcon-zero-day/https://therecord.media/microsoft-cisa-zero-day-turkish-defense-orghttps://www.bleepingcomputer.com/news/security/stealth-falcon-hackers-exploited-windows-webdav-zero-day-to-drop-malware/https://www.darkreading.com/vulnerabilities-threats/stealth-falcon-apt-exploits-microsoft-rce-zero-day-mideasthttps://www.theregister.com/2025/06/10/microsoft_patch_tuesday_june/https://www.vicarius.io/vsociety/posts/cve-2025-33053-detection-script-remote-code-execution-vulnerability-in-microsoft-webdavhttps://www.vicarius.io/vsociety/posts/cve-2025-33053-mitigation-script-remote-code-execution-vulnerability-in-microsoft-webdavhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-33053
2025-06-10
Published
2025-06-10
Added to CISA KEV
Exploited in the wild