Microsoft Patch Tuesday – August 2025

Today marks Microsoft Patch Tuesday for August 2025. There are 111 vulnerabilities that have been addressed this time around. This is quite a few, although only a few are higher severity. As always, make sure to patch your systems as soon as possible.

Notable Patch Tuesday vulnerabilities for August

  • CVE-2025-50165: A remote code execution vulnerability in Windows Graphics component could allow an attacker to remotely execute code if successfully exploited.
  • CVE-2025-53779: A path traversal vulnerability in Kerberos could allow an attacker to gain domain administrator privileges if successfully exploited. In order to carry out the attack the attacker needs an account that has access to some privileged dMSA attributes. Due to the higher privileges required, Microsoft deems the risk for exploitation less likely.

For all the CVEs and more detailed patch information, please check the release notes.

Need help addressing vulnerabilities similar to these in your own organization? Speak to an Outpost24 expert.

About the Author

Marcus White Cybersecurity Specialist, Outpost24

Marcus is an Outpost24 cybersecurity specialist based in the UK, with 8+ years experience in the tech and cyber sectors. He writes about attack surface management, application security, threat intelligence, and compliance.