July 2025 Patch Tuesday Updates are Now Available on Windows 11 and Windows 10

Microsoft’s July 2025 Patch Tuesday delivers critical security fixes, enterprise-focused Windows 11 enhancements, and marks a major shift in OS adoption trends.

Windows 11 hero approved - 2

Key Takeaways:

  • Microsoft fixed 130 vulnerabilities in July 2025 Patch Tuesday, including several critical ones in Windows, SQL Server, SharePoint, and Office.
  • Windows 11 has overtaken Windows 10 in global usage as the end-of-support date for Windows 10 nears.
  • New Windows 11 enhancements include the KB5062553 update, which adds a Settings homepage tailored for enterprise devices.

Microsoft has released today the July 2025 Patch Tuesday updates for Windows 11 and Windows 10. This month, Microsoft fixed 130 vulnerabilities in Windows, Office, Azure, Teams, Hyper-V, Windows BitLocker, and other components, and you can also expect the usual bug fixes and quality improvements.

Windows 11 has finally become the most popular version of the operating system, surpassing Windows 10. According to StatCounter, Windows 11 held a 52% market share, while Windows 10 dropped to 44.59% in July 2025. This shift is influenced by the upcoming end of support on October 14, 2025.

July 2025 Patch Tuesday updates fix 130 vulnerabilities

According to the Zero Day Initiative, Microsoft released a total of 130 patches yesterday, with fixes for 10 critical vulnerabilities. However, none of them are already being exploited by attackers.

Here are the most important vulnerabilities you should know about this month:

  • CVE-2025-47981: This is a heap-based buffer overflow in the Windows SPNEGO Extended Negotiation mechanism. A remote hacker could exploit it by crafting a specially crafted message and running arbitrary code on a vulnerable machine.
  • CVE-2025-49701 and CVE-2025-49704: These vulnerabilities could be exploited by an attacker authenticated with site owner privileges on a vulnerable SharePoint server. Microsoft advises SharePoint admins to patch these security flaws as soon as possible.
  • CVE-2025-48799: This is an elevation of privilege vulnerability that affects the Windows Update Service. Microsoft believes that attackers are more likely to exploit this security flaw and recommends immediate patching.
  • CVE-2025-49717: This is an SQL Server vulnerability that could allow remote code execution within the database engine as well as on the host OS. An attacker could abuse stolen credentials or app flaws to escalate privileges, deploy ransomware, or move laterally in a compromised network.
  • CVE-2025-49696: This vulnerability could be exploited locally by an attacker via the Preview Pane in Microsoft Office. Cybercriminals could carry out an attack by combining an out-of-bounds read and heap-based buffer overflow, and doesn’t require authentication.
  • CVE-2025-49698, 2025-49700, and 2025-49703: The important-rated vulnerabilities in Microsoft Word are use-after-free flaws that are technically difficult to exploit due to modern protections like ASLR. However, their risk is elevated because they can be triggered through the Preview Pane.

Here’s the full list of CVEs Microsoft released this month:

ProductImpactMax SeverityArticleDownloadDetails
Windows 10 Version 22H2 for x64-based SystemsElevation of PrivilegeImportant5062554Security UpdateCVE-2025-49659
Windows 11 Version 22H2 for x64-based SystemsElevation of PrivilegeImportant5062552Security UpdateCVE-2025-49659
Windows 11 Version 22H2 for ARM64-based SystemsElevation of PrivilegeImportant5062552Security UpdateCVE-2025-49659
Windows 10 Version 21H2 for x64-based SystemsElevation of PrivilegeImportant5062554Security UpdateCVE-2025-49659
Windows 10 Version 21H2 for ARM64-based SystemsElevation of PrivilegeImportant5062554Security UpdateCVE-2025-49659
Windows 10 Version 21H2 for 32-bit SystemsElevation of PrivilegeImportant5062554Security UpdateCVE-2025-49659
Windows Server 2022 (Server Core installation)Elevation of PrivilegeImportant5062572Security UpdateCVE-2025-49659
Windows Server 2022Elevation of PrivilegeImportant5062572Security UpdateCVE-2025-49659
Windows Server 2019 (Server Core installation)Elevation of PrivilegeImportant5062557Security UpdateCVE-2025-49659
Windows Server 2019Elevation of PrivilegeImportant5062557Security UpdateCVE-2025-49659
Windows 10 Version 1809 for x64-based SystemsElevation of PrivilegeImportant5062557Security UpdateCVE-2025-49659
Windows 10 for 32-bit SystemsSecurity Feature BypassImportant5062561Security UpdateCVE-2025-48818
Windows 10 for x64-based SystemsElevation of PrivilegeImportant5062561Security UpdateCVE-2025-49732
Windows Server 2025Elevation of PrivilegeImportant5062553Security UpdateCVE-2025-49732
Windows 11 Version 24H2 for x64-based SystemsElevation of PrivilegeImportant5062553Security UpdateCVE-2025-49732
Windows 11 Version 24H2 for ARM64-based SystemsElevation of PrivilegeImportant5062553Security UpdateCVE-2025-49732
Windows Server 2022, 23H2 Edition (Server Core installation)Elevation of PrivilegeImportant5062570Security UpdateCVE-2025-49732
Windows 11 Version 23H2 for x64-based SystemsElevation of PrivilegeImportant5062552Security UpdateCVE-2025-49732
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)Elevation of PrivilegeImportant5062624Monthly RollupCVE-2025-49727
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)Elevation of PrivilegeImportant5062618Security OnlyCVE-2025-49727
Windows Server 2008 for x64-based Systems Service Pack 2Elevation of PrivilegeImportant5062624Monthly RollupCVE-2025-49727
Windows Server 2008 for x64-based Systems Service Pack 2Elevation of PrivilegeImportant5062618Security OnlyCVE-2025-49727
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)Elevation of PrivilegeImportant5062624Monthly RollupCVE-2025-49727
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)Elevation of PrivilegeImportant5062618Security OnlyCVE-2025-49727
Windows Server 2008 for 32-bit Systems Service Pack 2Elevation of PrivilegeImportant5062624Monthly RollupCVE-2025-49727
Windows Server 2008 for 32-bit Systems Service Pack 2Elevation of PrivilegeImportant5062618Security OnlyCVE-2025-49727
Windows Server 2016 (Server Core installation)Elevation of PrivilegeImportant5062560Security UpdateCVE-2025-49727
Windows Server 2016Elevation of PrivilegeImportant5062560Security UpdateCVE-2025-49727
Windows 11 Version 23H2 for ARM64-based SystemsElevation of PrivilegeImportant5062552Security UpdateCVE-2025-49725
Windows Server 2025 (Server Core installation)Elevation of PrivilegeImportant5062553Security UpdateCVE-2025-49725
Windows 10 Version 22H2 for 32-bit SystemsElevation of PrivilegeImportant5062554Security UpdateCVE-2025-49725
Windows 10 Version 22H2 for ARM64-based SystemsElevation of PrivilegeImportant5062554Security UpdateCVE-2025-49725
Microsoft SharePoint Server 2019SpoofingImportant5002741Security UpdateCVE-2025-49706
Microsoft SharePoint Enterprise Server 2016SpoofingImportant5002744Security UpdateCVE-2025-49706
Microsoft PowerPoint 2016 (64-bit edition)Remote Code ExecutionImportant5002746Security UpdateCVE-2025-49705
Microsoft PowerPoint 2016 (32-bit edition)Remote Code ExecutionImportant5002746Security UpdateCVE-2025-49705
Microsoft Office LTSC for Mac 2024Remote Code ExecutionImportantCVE-2025-49705
Microsoft Office LTSC 2024 for 64-bit editionsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2025-49705
Microsoft Office LTSC 2024 for 32-bit editionsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2025-49705
Microsoft Office LTSC 2021 for 32-bit editionsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2025-49705
Microsoft Office LTSC 2021 for 64-bit editionsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2025-49705
Microsoft Office LTSC for Mac 2021Remote Code ExecutionImportantCVE-2025-49705
Microsoft 365 Apps for Enterprise for 64-bit SystemsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2025-49705
Microsoft Word 2016 (64-bit edition)Remote Code ExecutionCritical5002745Security UpdateCVE-2025-49703
Microsoft Word 2016 (32-bit edition)Remote Code ExecutionCritical5002745Security UpdateCVE-2025-49703
Windows Server 2012 R2 (Server Core installation)Elevation of PrivilegeImportant5062597Monthly RollupCVE-2025-49667
Windows 10 Version 1809 for 32-bit SystemsElevation of PrivilegeImportant5062557Security UpdateCVE-2025-49659
Windows Server 2012 R2Elevation of PrivilegeImportant5062597Monthly RollupCVE-2025-49667
Windows Server 2012 (Server Core installation)Elevation of PrivilegeImportant5062592Monthly RollupCVE-2025-49665
Windows Server 2012Elevation of PrivilegeImportant5062592Monthly RollupCVE-2025-49665
Windows 10 Version 1607 for x64-based SystemsElevation of PrivilegeImportant5062560Security UpdateCVE-2025-49665
Windows 10 Version 1607 for 32-bit SystemsElevation of PrivilegeImportant5062560Security UpdateCVE-2025-49665
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Denial of ServiceLow5062632Monthly RollupCVE-2025-49683
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Denial of ServiceLow5062619Security OnlyCVE-2025-49683
Windows Server 2008 R2 for x64-based Systems Service Pack 1Denial of ServiceLow5062632Monthly RollupCVE-2025-49683
Windows Server 2008 R2 for x64-based Systems Service Pack 1Denial of ServiceLow5062619Security OnlyCVE-2025-49683
Azure Monitor AgentRemote Code ExecutionImportantRelease NotesSecurity UpdateCVE-2025-47988
Microsoft 365 Apps for Enterprise for 32-bit SystemsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2025-49705
Microsoft Office 2019 for 64-bit editionsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2025-49705
Microsoft Office 2019 for 32-bit editionsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2025-49705
Microsoft SQL Server 2019 for x64-based Systems (CU 32)Information DisclosureImportant5058722{“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108270″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108270\””}CVE-2025-49718
Microsoft SQL Server 2022 for x64-based Systems (CU 19)Information DisclosureImportant5058712{“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108269″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108269\””}CVE-2025-49718
Microsoft SQL Server 2022 for x64-based Systems (GDR)Information DisclosureImportant5058721{“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108268″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108268\””}CVE-2025-49718
Microsoft SQL Server 2019 for x64-based Systems (GDR)Information DisclosureImportant5058713{“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108274″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108274\””}CVE-2025-49718
Python extension for Visual Studio CodeRemote Code ExecutionImportantRelease Notes{“type”:5,”hyperlink”:”https://marketplace.visualstudio.com/items?itemName=ms-python.python”,”tooltip”:”Open \”https://marketplace.visualstudio.com/items?itemName=ms-python.python\””}CVE-2025-49714
Microsoft SharePoint Server Subscription EditionSpoofingImportant5002751Security UpdateCVE-2025-49706
Microsoft Visual Studio 2022 version 17.14Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-49739
Microsoft Visual Studio 2015 Update 3Elevation of PrivilegeImportant5063035Security UpdateCVE-2025-49739
Microsoft Visual Studio 2022 version 17.10Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-49739
Microsoft Visual Studio 2022 version 17.8Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-49739
Microsoft Visual Studio 2022 version 17.12Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-49739
Microsoft Visual Studio 2019 version 16.11 (includes 16.0 – 16.10)Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-49739
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 – 15.8)Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-49739
Microsoft PC ManagerElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-49738
Microsoft Teams for MacElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-49737
Microsoft SharePoint Server 2019Remote Code ExecutionCritical5002739Security UpdateCVE-2025-49703
Microsoft SharePoint Enterprise Server 2016Remote Code ExecutionCritical5002743Security UpdateCVE-2025-49703
Microsoft Office 2016 (64-bit edition)Remote Code ExecutionCritical5002742Security UpdateCVE-2025-49702
Microsoft Office 2016 (32-bit edition)Remote Code ExecutionCritical5002742Security UpdateCVE-2025-49702
Microsoft Office for AndroidRemote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2025-49697
Microsoft Word 2016 (64-bit edition)Remote Code ExecutionCritical5002742Security UpdateCVE-2025-49698
Microsoft Word 2016 (32-bit edition)Remote Code ExecutionCritical5002742Security UpdateCVE-2025-49698
Office Online ServerRemote Code ExecutionCritical5002740Security UpdateCVE-2025-49697
Microsoft Office 2016 (64-bit edition)Remote Code ExecutionCritical5002749Security UpdateCVE-2025-49697
Microsoft Office 2016 (32-bit edition)Remote Code ExecutionCritical5002749Security UpdateCVE-2025-49697
Microsoft Word 2016 (64-bit edition)Remote Code ExecutionImportant5002655Security UpdateCVE-2025-49700
Microsoft Outlook 2016 (64-bit edition)Remote Code ExecutionImportant5002747Security UpdateCVE-2025-49699
Microsoft Outlook 2016 (32-bit edition)Remote Code ExecutionImportant5002747Security UpdateCVE-2025-49699
Microsoft Word 2016 (64-bit edition)Remote Code ExecutionImportant5001941Security UpdateCVE-2025-49699
Microsoft Word 2016 (64-bit edition)Remote Code ExecutionImportant4464583Security UpdateCVE-2025-49699
Microsoft Word 2016 (32-bit edition)Remote Code ExecutionImportant5001941Security UpdateCVE-2025-49699
Microsoft Word 2016 (32-bit edition)Remote Code ExecutionImportant4464583Security UpdateCVE-2025-49699
Remote Desktop client for Windows DesktopRemote Code ExecutionImportantRelease Notes{“type”:5,”hyperlink”:”https://learn.microsoft.com/en-us/azure/virtual-desktop/whats-new-client-windows#updates-for-version-1263530″,”tooltip”:”Open \”https://learn.microsoft.com/en-us/azure/virtual-desktop/whats-new-client-windows#updates-for-version-1263530\””}CVE-2025-48817
Windows App Client for Windows DesktopRemote Code ExecutionImportantRelease Notes{“type”:5,”hyperlink”:”https://learn.microsoft.com/en-us/windows-app/whats-new?toc=admins%2Ftoc.json&tabs=windows”,”tooltip”:”Open \”https://learn.microsoft.com/en-us/windows-app/whats-new?toc=admins%2Ftoc.json&tabs=windows\””}CVE-2025-48817
Microsoft Configuration Manager 2503Remote Code ExecutionImportantKB31909343{“type”:5,”hyperlink”:”https://learn.microsoft.com/en-us/mem/configmgr/core/servers/manage/install-in-console-updates”,”tooltip”:”Open \”https://learn.microsoft.com/en-us/mem/configmgr/core/servers/manage/install-in-console-updates\””}CVE-2025-47178
Windows Server 2012 R2 (Server Core installation)Remote Code ExecutionCritical5061018Monthly RollupCVE-2025-49735
Windows Server 2012 R2Remote Code ExecutionCritical5061018Monthly RollupCVE-2025-49735
Windows Server 2012 (Server Core installation)Remote Code ExecutionCritical5061059Monthly RollupCVE-2025-49735
Windows Server 2012Remote Code ExecutionCritical5061059Monthly RollupCVE-2025-49735
Windows Server 2016 (Server Core installation)Remote Code ExecutionCritical5061010Security UpdateCVE-2025-49735
Windows Server 2016Remote Code ExecutionCritical5061010Security UpdateCVE-2025-49735
Windows Server 2025Remote Code ExecutionCritical5060842Security UpdateCVE-2025-49735
Windows Server 2022, 23H2 Edition (Server Core installation)Remote Code ExecutionCritical5060999Security UpdateCVE-2025-49735
Windows Server 2025 (Server Core installation)Remote Code ExecutionCritical5060842Security UpdateCVE-2025-49735
Windows Server 2022 (Server Core installation)Remote Code ExecutionCritical5060526Security UpdateCVE-2025-49735
Windows Server 2022Remote Code ExecutionCritical5060526Security UpdateCVE-2025-49735
Windows Server 2019 (Server Core installation)Remote Code ExecutionCritical5060998Security UpdateCVE-2025-49735
Windows Server 2019Remote Code ExecutionCritical5060998Security UpdateCVE-2025-49735
Microsoft Teams for DesktopElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-49731
Microsoft Teams for iOSElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-49731
Microsoft Teams for AndroidElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-49731
Microsoft SQL Server 2017 for x64-based Systems (CU 31)Information DisclosureImportant5058714{“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108272″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108272\””}CVE-2025-49719
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature PackInformation DisclosureImportant5058717{“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108273″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108273\””}CVE-2025-49719
Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)Information DisclosureImportant5058718{“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108275″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108275\””}CVE-2025-49719
Microsoft SQL Server 2017 for x64-based Systems (GDR)Information DisclosureImportant5058716{“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108271″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108271\””}CVE-2025-49719
Microsoft Excel 2016 (64-bit edition)Remote Code ExecutionImportant5002749Security UpdateCVE-2025-49711
Microsoft Excel 2016 (32-bit edition)Remote Code ExecutionImportant5002749Security UpdateCVE-2025-49711
Microsoft Excel 2016 (64-bit edition)Information DisclosureImportant5002734Security UpdateCVE-2025-48812
Microsoft Excel 2016 (32-bit edition)Information DisclosureImportant5002734Security UpdateCVE-2025-48812
Azure Service FabricElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-21195
Microsoft Edge (Chromium-based)Remote Code ExecutionImportantRelease NotesSecurity UpdateCVE-2025-49713
Dynamics 365 FastTrack ImplementationInformation DisclosureCriticalCVE-2025-49715
Windows Server 2025Security Feature BypassImportant5060841SecurityHotpatchUpdateCVE-2025-33069
Windows 11 Version 24H2 for x64-based SystemsSecurity Feature BypassImportant5060842Security UpdateCVE-2025-33069
Windows 11 Version 24H2 for x64-based SystemsSecurity Feature BypassImportant5060841SecurityHotpatchUpdateCVE-2025-33069
Windows 11 Version 24H2 for ARM64-based SystemsSecurity Feature BypassImportant5060842Security UpdateCVE-2025-33069
Windows 11 Version 24H2 for ARM64-based SystemsSecurity Feature BypassImportant5060841SecurityHotpatchUpdateCVE-2025-33069
Windows Server 2025 (Server Core installation)Security Feature BypassImportant5060841SecurityHotpatchUpdateCVE-2025-33069
PowerShell 7.5Remote Code ExecutionImportantRelease Notes{“type”:5,”hyperlink”:”https://github.com/PowerShell/Announcements/issues/77″,”tooltip”:”Open \”https://github.com/PowerShell/Announcements/issues/77\””}CVE-2025-30399
PowerShell 7.4Remote Code ExecutionImportantRelease Notes{“type”:5,”hyperlink”:”https://github.com/PowerShell/Announcements/issues/77″,”tooltip”:”Open \”https://github.com/PowerShell/Announcements/issues/77\””}CVE-2025-30399
.NET 9.0 installed on WindowsRemote Code ExecutionImportant5061936Security UpdateCVE-2025-30399
.NET 9.0 installed on Mac OSRemote Code ExecutionImportant5061936Security UpdateCVE-2025-30399
.NET 9.0 installed on LinuxRemote Code ExecutionImportant5061936Security UpdateCVE-2025-30399
.NET 8.0 installed on Mac OSRemote Code ExecutionImportant5061935Security UpdateCVE-2025-30399
.NET 8.0 installed on LinuxRemote Code ExecutionImportant5061935Security UpdateCVE-2025-30399
.NET 8.0 installed on WindowsRemote Code ExecutionImportant5061935Security UpdateCVE-2025-30399
Microsoft Edge (Chromium-based) UpdaterElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-47181
Microsoft Defender for Endpoint for LinuxElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-47161
Microsoft Visual Studio CoPilot Chat ExtensionSecurity Feature BypassImportantRelease NotesSecurity UpdateCVE-2025-21264
Microsoft Office LTSC for Mac 2024Remote Code ExecutionImportantRelease NotesSecurity UpdateCVE-2025-30393
Microsoft Office LTSC for Mac 2021Remote Code ExecutionImportantRelease NotesSecurity UpdateCVE-2025-30393
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Elevation of PrivilegeImportant5061196Monthly RollupCVE-2025-32709
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Elevation of PrivilegeImportant5061195Security UpdateCVE-2025-32709
Windows Server 2008 R2 for x64-based Systems Service Pack 1Elevation of PrivilegeImportant5061196Monthly RollupCVE-2025-32709
Windows Server 2008 R2 for x64-based Systems Service Pack 1Elevation of PrivilegeImportant5061195Security UpdateCVE-2025-32709
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)Elevation of PrivilegeImportant5061198Monthly RollupCVE-2025-32709
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)Elevation of PrivilegeImportant5061197Security OnlyCVE-2025-32709
Windows Server 2008 for x64-based Systems Service Pack 2Elevation of PrivilegeImportant5061198Monthly RollupCVE-2025-32709
Windows Server 2008 for x64-based Systems Service Pack 2Elevation of PrivilegeImportant5061197Security OnlyCVE-2025-32709
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)Elevation of PrivilegeImportant5061198Monthly RollupCVE-2025-32709
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)Elevation of PrivilegeImportant5061197Security OnlyCVE-2025-32709
Windows Server 2008 for 32-bit Systems Service Pack 2Elevation of PrivilegeImportant5061198Monthly RollupCVE-2025-32709
Windows Server 2008 for 32-bit Systems Service Pack 2Elevation of PrivilegeImportant5061197Security OnlyCVE-2025-32709
Windows Server 2008 for 32-bit Systems Service Pack 2Elevation of PrivilegeImportant5058449Monthly RollupCVE-2025-24063
Windows Server 2008 for 32-bit Systems Service Pack 2Elevation of PrivilegeImportant5058429Security OnlyCVE-2025-24063
Windows Server 2016 (Server Core installation)Elevation of PrivilegeImportant5058383Security UpdateCVE-2025-24063
Windows Server 2016Elevation of PrivilegeImportant5058383Security UpdateCVE-2025-24063
Windows 10 Version 22H2 for x64-based SystemsRemote Code ExecutionImportant5058379Security UpdateCVE-2025-30397
Windows 11 Version 22H2 for x64-based SystemsRemote Code ExecutionImportant5058405Security UpdateCVE-2025-30397
Windows 11 Version 22H2 for ARM64-based SystemsRemote Code ExecutionImportant5058405Security UpdateCVE-2025-30397
Windows 10 Version 21H2 for x64-based SystemsRemote Code ExecutionImportant5058379Security UpdateCVE-2025-30397
Windows 10 Version 21H2 for ARM64-based SystemsRemote Code ExecutionImportant5058379Security UpdateCVE-2025-30397
Windows 10 Version 21H2 for 32-bit SystemsRemote Code ExecutionImportant5058379Security UpdateCVE-2025-30397
Windows Server 2022 (Server Core installation)Remote Code ExecutionImportant5058385Security UpdateCVE-2025-30397
Windows Server 2022Remote Code ExecutionImportant5058385Security UpdateCVE-2025-30397
Windows Server 2022Remote Code ExecutionImportant5058500SecurityHotpatchUpdateCVE-2025-30397
Windows Server 2019 (Server Core installation)Remote Code ExecutionImportant5058392Security UpdateCVE-2025-30397
Windows Server 2019Remote Code ExecutionImportant5058392Security UpdateCVE-2025-30397
Windows 10 Version 1607 for x64-based SystemsInformation DisclosureImportant5058383Security UpdateCVE-2025-29974
Windows 10 Version 1607 for 32-bit SystemsInformation DisclosureImportant5058383Security UpdateCVE-2025-29974
Windows 10 for x64-based SystemsInformation DisclosureImportant5058387Security UpdateCVE-2025-29974
Windows 10 for 32-bit SystemsInformation DisclosureImportant5058387Security UpdateCVE-2025-29974
Windows Server 2025Information DisclosureImportant5058411Security UpdateCVE-2025-29974
Windows Server 2025Information DisclosureImportant5058497SecurityHotpatchUpdateCVE-2025-29974
Windows 11 Version 24H2 for x64-based SystemsInformation DisclosureImportant5058411Security UpdateCVE-2025-29974
Windows 11 Version 24H2 for x64-based SystemsInformation DisclosureImportant5058497SecurityHotpatchUpdateCVE-2025-29974
Windows 11 Version 24H2 for ARM64-based SystemsInformation DisclosureImportant5058411Security UpdateCVE-2025-29974
Windows 11 Version 24H2 for ARM64-based SystemsInformation DisclosureImportant5058497SecurityHotpatchUpdateCVE-2025-29974
Windows Server 2022, 23H2 Edition (Server Core installation)Information DisclosureImportant5058384Security UpdateCVE-2025-29974
Windows 11 Version 23H2 for x64-based SystemsInformation DisclosureImportant5058405Security UpdateCVE-2025-29961
Windows 11 Version 23H2 for ARM64-based SystemsInformation DisclosureImportant5058405Security UpdateCVE-2025-29961
Windows Server 2025 (Server Core installation)Information DisclosureImportant5058411Security UpdateCVE-2025-29961
Windows Server 2025 (Server Core installation)Information DisclosureImportant5058497SecurityHotpatchUpdateCVE-2025-29961
Windows 10 Version 22H2 for 32-bit SystemsInformation DisclosureImportant5058379Security UpdateCVE-2025-29961
Windows 10 Version 22H2 for ARM64-based SystemsInformation DisclosureImportant5058379Security UpdateCVE-2025-29961
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Information DisclosureImportant5058430Monthly RollupCVE-2025-29956
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Information DisclosureImportant5058454Security OnlyCVE-2025-29956
Windows Server 2008 R2 for x64-based Systems Service Pack 1Information DisclosureImportant5058430Monthly RollupCVE-2025-29956
Windows Server 2008 R2 for x64-based Systems Service Pack 1Information DisclosureImportant5058454Security OnlyCVE-2025-29956
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)Information DisclosureImportant5058449Monthly RollupCVE-2025-29956
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)Information DisclosureImportant5058429Security OnlyCVE-2025-29956
Windows Server 2008 for x64-based Systems Service Pack 2Information DisclosureImportant5058449Monthly RollupCVE-2025-29956
Windows Server 2008 for x64-based Systems Service Pack 2Information DisclosureImportant5058429Security OnlyCVE-2025-29956
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)Information DisclosureImportant5058449Monthly RollupCVE-2025-29956
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)Information DisclosureImportant5058429Security OnlyCVE-2025-29956
Windows Server 2012 R2 (Server Core installation)Elevation of PrivilegeImportant5058403Monthly RollupCVE-2025-27468
Windows Server 2012 R2Elevation of PrivilegeImportant5058403Monthly RollupCVE-2025-27468
Windows Server 2012 (Server Core installation)Elevation of PrivilegeImportant5058451Monthly RollupCVE-2025-27468
Windows Server 2012Elevation of PrivilegeImportant5058451Monthly RollupCVE-2025-27468
Microsoft Excel 2016 (64-bit edition)Remote Code ExecutionImportant5002717Security UpdateCVE-2025-30376
Microsoft Excel 2016 (32-bit edition)Remote Code ExecutionImportant5002717Security UpdateCVE-2025-30376
Windows 10 Version 1809 for x64-based SystemsRemote Code ExecutionImportant5058392Security UpdateCVE-2025-29969
Windows 10 Version 1809 for 32-bit SystemsRemote Code ExecutionImportant5058392Security UpdateCVE-2025-29969
Microsoft Excel 2016 (64-bit edition)Remote Code ExecutionImportant5002695Security UpdateCVE-2025-32704
Microsoft Excel 2016 (32-bit edition)Remote Code ExecutionImportant5002695Security UpdateCVE-2025-32704
Microsoft Visual Studio 2022 version 17.13Remote Code ExecutionImportantRelease NotesSecurity UpdateCVE-2025-32702
Windows Server 2012 R2 (Server Core installation)Remote Code ExecutionImportant5058380IE CumulativeCVE-2025-30397
Windows Server 2012 R2Remote Code ExecutionImportant5058380IE CumulativeCVE-2025-30397
Windows Server 2012 (Server Core installation)Remote Code ExecutionImportant5058380IE CumulativeCVE-2025-30397
Windows Server 2012Remote Code ExecutionImportant5058380IE CumulativeCVE-2025-30397
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Remote Code ExecutionImportant5058380IE CumulativeCVE-2025-30397
Windows Server 2008 R2 for x64-based Systems Service Pack 1Remote Code ExecutionImportant5058380IE CumulativeCVE-2025-30397
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)Remote Code ExecutionImportant5058380IE CumulativeCVE-2025-30397
Windows Server 2008 for x64-based Systems Service Pack 2Remote Code ExecutionImportant5058380IE CumulativeCVE-2025-30397
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)Remote Code ExecutionImportant5058380IE CumulativeCVE-2025-30397
Windows Server 2008 for 32-bit Systems Service Pack 2Remote Code ExecutionImportant5058380IE CumulativeCVE-2025-30397
Microsoft Office for UniversalRemote Code ExecutionImportantRelease NotesSecurity UpdateCVE-2025-30388
Windows Server 2022 (Server Core installation)Remote Code ExecutionCritical5058500SecurityHotpatchUpdateCVE-2025-29833
Microsoft Defender for IdentitySpoofingImportantCVE-2025-26685
Windows HLK for Windows Server 2019Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-27488
Windows HLK for Windows 10 version 2004Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-27488
Windows 10 HLK version 21H2Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-27488
Windows 10 HLK Version 22H2Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-27488
Windows 10 HLK version 20H2Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-27488
Windows HLK for Windows Server 2022Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-27488
Windows 11 HLK 22H2Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-27488
Windows 10 HLK version 21H1Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-27488
Windows HLK Version 1809Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-27488
Windows 11 HLK 24H2Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-27488
Windows HLK for Windows Server 2025Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-27488
Visual Studio CodeSecurity Feature BypassImportantRelease NotesSecurity UpdateCVE-2025-21264
Microsoft DataverseElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-29826
Azure AI Document Intelligence StudioElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2025-30387
Microsoft Office 2016 (64-bit edition)Remote Code ExecutionCritical5002711Security UpdateCVE-2025-30386
Microsoft Office 2016 (32-bit edition)Remote Code ExecutionCritical5002711Security UpdateCVE-2025-30386
Microsoft SharePoint Server Subscription EditionRemote Code ExecutionImportant5002709Security UpdateCVE-2025-30384
Microsoft SharePoint Server 2019Remote Code ExecutionImportant5002708Security UpdateCVE-2025-30384
Microsoft SharePoint Enterprise Server 2016Remote Code ExecutionImportant5002722Security UpdateCVE-2025-30384
Office Online ServerRemote Code ExecutionImportant5002707Security UpdateCVE-2025-30383
Microsoft Excel 2016 (64-bit edition)Remote Code ExecutionImportant5002716Security UpdateCVE-2025-30379
Microsoft Excel 2016 (32-bit edition)Remote Code ExecutionImportant5002716Security UpdateCVE-2025-30379
Microsoft Office 2016 (64-bit edition)Remote Code ExecutionImportant5002717Security UpdateCVE-2025-29979
Microsoft Office 2016 (32-bit edition)Remote Code ExecutionImportant5002717Security UpdateCVE-2025-29979
Microsoft SharePoint Server 2019Elevation of PrivilegeImportant5002706Security UpdateCVE-2025-29976
Microsoft SharePoint Enterprise Server 2016Elevation of PrivilegeImportant5002712Security UpdateCVE-2025-29976
Azure File Sync v20.0Elevation of PrivilegeImportantRelease NotesN/ACVE-2025-29973
Azure File Sync v19.0Elevation of PrivilegeImportantRelease NotesN/ACVE-2025-29973
Windows 11 Version 24H2 for x64-based SystemsDenial of ServiceImportant5061258Security HotPatch UpdateCVE-2025-29971
Windows 11 Version 24H2 for ARM64-based SystemsDenial of ServiceImportant5061258Security HotPatch UpdateCVE-2025-29971
Build Tools for Visual Studio 2022SpoofingImportantRelease NotesSecurity UpdateCVE-2025-26646
.NET 9.0 installed on WindowsSpoofingImportant5059201Security UpdateCVE-2025-26646
.NET 9.0 installed on Mac OSSpoofingImportant5059201Security UpdateCVE-2025-26646
.NET 9.0 installed on LinuxSpoofingImportant5059201Security UpdateCVE-2025-26646
.NET 8.0 installed on Mac OSSpoofingImportant5059200Security UpdateCVE-2025-26646
.NET 8.0 installed on LinuxSpoofingImportant5059200Security UpdateCVE-2025-26646
.NET 8.0 installed on WindowsSpoofingImportant5059200Security UpdateCVE-2025-26646

Quality and experience updates

For users running Windows 11 version 24H2, the KB5062553 patch brings various quality improvements, including a new Settings homepage for commercial customers. This new homepage will show cards relevant to enterprise-managed Windows 11 devices, including “Recommended settings” and “Bluetooth devices.” There are also two new enterprise-specific device info and accessibility preferences cards.

For Windows 10, the KB5062554 update is now available for users running version 22H2 of the operating system. This release fixes an issue affecting USB-connected Multi-Function printers with dual protocol interfaces.

Windows Update testing and best practices

Organizations looking to deploy this month’s patches should conduct thorough testing before deploying them widely on production systems. That said, applying the patches widely shouldn’t be delayed longer than necessary, as hackers start to work out how to weaponize newly reported vulnerabilities.

A best practice is to make sure you have backed up systems before applying updates. Every month, users experience issues with Windows updates that lead to systems not booting, application and hardware compatibility issues, or even data loss in extreme cases.

There are backup tools built into Windows and Windows Server that you can use to restore systems in the event a patch causes a problem. The backup features in Windows can be used to restore an entire system or files and folders on a granular basis.