Microsoft’s July 2025 Patch Tuesday delivers critical security fixes, enterprise-focused Windows 11 enhancements, and marks a major shift in OS adoption trends.
Key Takeaways:
Microsoft has released today the July 2025 Patch Tuesday updates for Windows 11 and Windows 10. This month, Microsoft fixed 130 vulnerabilities in Windows, Office, Azure, Teams, Hyper-V, Windows BitLocker, and other components, and you can also expect the usual bug fixes and quality improvements.
Windows 11 has finally become the most popular version of the operating system, surpassing Windows 10. According to StatCounter, Windows 11 held a 52% market share, while Windows 10 dropped to 44.59% in July 2025. This shift is influenced by the upcoming end of support on October 14, 2025.
According to the Zero Day Initiative, Microsoft released a total of 130 patches yesterday, with fixes for 10 critical vulnerabilities. However, none of them are already being exploited by attackers.
Here are the most important vulnerabilities you should know about this month:
Here’s the full list of CVEs Microsoft released this month:
| Product | Impact | Max Severity | Article | Download | Details |
| Windows 10 Version 22H2 for x64-based Systems | Elevation of Privilege | Important | 5062554 | Security Update | CVE-2025-49659 |
| Windows 11 Version 22H2 for x64-based Systems | Elevation of Privilege | Important | 5062552 | Security Update | CVE-2025-49659 |
| Windows 11 Version 22H2 for ARM64-based Systems | Elevation of Privilege | Important | 5062552 | Security Update | CVE-2025-49659 |
| Windows 10 Version 21H2 for x64-based Systems | Elevation of Privilege | Important | 5062554 | Security Update | CVE-2025-49659 |
| Windows 10 Version 21H2 for ARM64-based Systems | Elevation of Privilege | Important | 5062554 | Security Update | CVE-2025-49659 |
| Windows 10 Version 21H2 for 32-bit Systems | Elevation of Privilege | Important | 5062554 | Security Update | CVE-2025-49659 |
| Windows Server 2022 (Server Core installation) | Elevation of Privilege | Important | 5062572 | Security Update | CVE-2025-49659 |
| Windows Server 2022 | Elevation of Privilege | Important | 5062572 | Security Update | CVE-2025-49659 |
| Windows Server 2019 (Server Core installation) | Elevation of Privilege | Important | 5062557 | Security Update | CVE-2025-49659 |
| Windows Server 2019 | Elevation of Privilege | Important | 5062557 | Security Update | CVE-2025-49659 |
| Windows 10 Version 1809 for x64-based Systems | Elevation of Privilege | Important | 5062557 | Security Update | CVE-2025-49659 |
| Windows 10 for 32-bit Systems | Security Feature Bypass | Important | 5062561 | Security Update | CVE-2025-48818 |
| Windows 10 for x64-based Systems | Elevation of Privilege | Important | 5062561 | Security Update | CVE-2025-49732 |
| Windows Server 2025 | Elevation of Privilege | Important | 5062553 | Security Update | CVE-2025-49732 |
| Windows 11 Version 24H2 for x64-based Systems | Elevation of Privilege | Important | 5062553 | Security Update | CVE-2025-49732 |
| Windows 11 Version 24H2 for ARM64-based Systems | Elevation of Privilege | Important | 5062553 | Security Update | CVE-2025-49732 |
| Windows Server 2022, 23H2 Edition (Server Core installation) | Elevation of Privilege | Important | 5062570 | Security Update | CVE-2025-49732 |
| Windows 11 Version 23H2 for x64-based Systems | Elevation of Privilege | Important | 5062552 | Security Update | CVE-2025-49732 |
| Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Elevation of Privilege | Important | 5062624 | Monthly Rollup | CVE-2025-49727 |
| Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Elevation of Privilege | Important | 5062618 | Security Only | CVE-2025-49727 |
| Windows Server 2008 for x64-based Systems Service Pack 2 | Elevation of Privilege | Important | 5062624 | Monthly Rollup | CVE-2025-49727 |
| Windows Server 2008 for x64-based Systems Service Pack 2 | Elevation of Privilege | Important | 5062618 | Security Only | CVE-2025-49727 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Elevation of Privilege | Important | 5062624 | Monthly Rollup | CVE-2025-49727 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Elevation of Privilege | Important | 5062618 | Security Only | CVE-2025-49727 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 | Elevation of Privilege | Important | 5062624 | Monthly Rollup | CVE-2025-49727 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 | Elevation of Privilege | Important | 5062618 | Security Only | CVE-2025-49727 |
| Windows Server 2016 (Server Core installation) | Elevation of Privilege | Important | 5062560 | Security Update | CVE-2025-49727 |
| Windows Server 2016 | Elevation of Privilege | Important | 5062560 | Security Update | CVE-2025-49727 |
| Windows 11 Version 23H2 for ARM64-based Systems | Elevation of Privilege | Important | 5062552 | Security Update | CVE-2025-49725 |
| Windows Server 2025 (Server Core installation) | Elevation of Privilege | Important | 5062553 | Security Update | CVE-2025-49725 |
| Windows 10 Version 22H2 for 32-bit Systems | Elevation of Privilege | Important | 5062554 | Security Update | CVE-2025-49725 |
| Windows 10 Version 22H2 for ARM64-based Systems | Elevation of Privilege | Important | 5062554 | Security Update | CVE-2025-49725 |
| Microsoft SharePoint Server 2019 | Spoofing | Important | 5002741 | Security Update | CVE-2025-49706 |
| Microsoft SharePoint Enterprise Server 2016 | Spoofing | Important | 5002744 | Security Update | CVE-2025-49706 |
| Microsoft PowerPoint 2016 (64-bit edition) | Remote Code Execution | Important | 5002746 | Security Update | CVE-2025-49705 |
| Microsoft PowerPoint 2016 (32-bit edition) | Remote Code Execution | Important | 5002746 | Security Update | CVE-2025-49705 |
| Microsoft Office LTSC for Mac 2024 | Remote Code Execution | Important | CVE-2025-49705 | ||
| Microsoft Office LTSC 2024 for 64-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2025-49705 |
| Microsoft Office LTSC 2024 for 32-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2025-49705 |
| Microsoft Office LTSC 2021 for 32-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2025-49705 |
| Microsoft Office LTSC 2021 for 64-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2025-49705 |
| Microsoft Office LTSC for Mac 2021 | Remote Code Execution | Important | CVE-2025-49705 | ||
| Microsoft 365 Apps for Enterprise for 64-bit Systems | Remote Code Execution | Important | Click to Run | Security Update | CVE-2025-49705 |
| Microsoft Word 2016 (64-bit edition) | Remote Code Execution | Critical | 5002745 | Security Update | CVE-2025-49703 |
| Microsoft Word 2016 (32-bit edition) | Remote Code Execution | Critical | 5002745 | Security Update | CVE-2025-49703 |
| Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5062597 | Monthly Rollup | CVE-2025-49667 |
| Windows 10 Version 1809 for 32-bit Systems | Elevation of Privilege | Important | 5062557 | Security Update | CVE-2025-49659 |
| Windows Server 2012 R2 | Elevation of Privilege | Important | 5062597 | Monthly Rollup | CVE-2025-49667 |
| Windows Server 2012 (Server Core installation) | Elevation of Privilege | Important | 5062592 | Monthly Rollup | CVE-2025-49665 |
| Windows Server 2012 | Elevation of Privilege | Important | 5062592 | Monthly Rollup | CVE-2025-49665 |
| Windows 10 Version 1607 for x64-based Systems | Elevation of Privilege | Important | 5062560 | Security Update | CVE-2025-49665 |
| Windows 10 Version 1607 for 32-bit Systems | Elevation of Privilege | Important | 5062560 | Security Update | CVE-2025-49665 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Denial of Service | Low | 5062632 | Monthly Rollup | CVE-2025-49683 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Denial of Service | Low | 5062619 | Security Only | CVE-2025-49683 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Denial of Service | Low | 5062632 | Monthly Rollup | CVE-2025-49683 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Denial of Service | Low | 5062619 | Security Only | CVE-2025-49683 |
| Azure Monitor Agent | Remote Code Execution | Important | Release Notes | Security Update | CVE-2025-47988 |
| Microsoft 365 Apps for Enterprise for 32-bit Systems | Remote Code Execution | Important | Click to Run | Security Update | CVE-2025-49705 |
| Microsoft Office 2019 for 64-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2025-49705 |
| Microsoft Office 2019 for 32-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2025-49705 |
| Microsoft SQL Server 2019 for x64-based Systems (CU 32) | Information Disclosure | Important | 5058722 | {“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108270″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108270\””} | CVE-2025-49718 |
| Microsoft SQL Server 2022 for x64-based Systems (CU 19) | Information Disclosure | Important | 5058712 | {“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108269″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108269\””} | CVE-2025-49718 |
| Microsoft SQL Server 2022 for x64-based Systems (GDR) | Information Disclosure | Important | 5058721 | {“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108268″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108268\””} | CVE-2025-49718 |
| Microsoft SQL Server 2019 for x64-based Systems (GDR) | Information Disclosure | Important | 5058713 | {“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108274″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108274\””} | CVE-2025-49718 |
| Python extension for Visual Studio Code | Remote Code Execution | Important | Release Notes | {“type”:5,”hyperlink”:”https://marketplace.visualstudio.com/items?itemName=ms-python.python”,”tooltip”:”Open \”https://marketplace.visualstudio.com/items?itemName=ms-python.python\””} | CVE-2025-49714 |
| Microsoft SharePoint Server Subscription Edition | Spoofing | Important | 5002751 | Security Update | CVE-2025-49706 |
| Microsoft Visual Studio 2022 version 17.14 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-49739 |
| Microsoft Visual Studio 2015 Update 3 | Elevation of Privilege | Important | 5063035 | Security Update | CVE-2025-49739 |
| Microsoft Visual Studio 2022 version 17.10 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-49739 |
| Microsoft Visual Studio 2022 version 17.8 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-49739 |
| Microsoft Visual Studio 2022 version 17.12 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-49739 |
| Microsoft Visual Studio 2019 version 16.11 (includes 16.0 – 16.10) | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-49739 |
| Microsoft Visual Studio 2017 version 15.9 (includes 15.0 – 15.8) | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-49739 |
| Microsoft PC Manager | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-49738 |
| Microsoft Teams for Mac | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-49737 |
| Microsoft SharePoint Server 2019 | Remote Code Execution | Critical | 5002739 | Security Update | CVE-2025-49703 |
| Microsoft SharePoint Enterprise Server 2016 | Remote Code Execution | Critical | 5002743 | Security Update | CVE-2025-49703 |
| Microsoft Office 2016 (64-bit edition) | Remote Code Execution | Critical | 5002742 | Security Update | CVE-2025-49702 |
| Microsoft Office 2016 (32-bit edition) | Remote Code Execution | Critical | 5002742 | Security Update | CVE-2025-49702 |
| Microsoft Office for Android | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2025-49697 |
| Microsoft Word 2016 (64-bit edition) | Remote Code Execution | Critical | 5002742 | Security Update | CVE-2025-49698 |
| Microsoft Word 2016 (32-bit edition) | Remote Code Execution | Critical | 5002742 | Security Update | CVE-2025-49698 |
| Office Online Server | Remote Code Execution | Critical | 5002740 | Security Update | CVE-2025-49697 |
| Microsoft Office 2016 (64-bit edition) | Remote Code Execution | Critical | 5002749 | Security Update | CVE-2025-49697 |
| Microsoft Office 2016 (32-bit edition) | Remote Code Execution | Critical | 5002749 | Security Update | CVE-2025-49697 |
| Microsoft Word 2016 (64-bit edition) | Remote Code Execution | Important | 5002655 | Security Update | CVE-2025-49700 |
| Microsoft Outlook 2016 (64-bit edition) | Remote Code Execution | Important | 5002747 | Security Update | CVE-2025-49699 |
| Microsoft Outlook 2016 (32-bit edition) | Remote Code Execution | Important | 5002747 | Security Update | CVE-2025-49699 |
| Microsoft Word 2016 (64-bit edition) | Remote Code Execution | Important | 5001941 | Security Update | CVE-2025-49699 |
| Microsoft Word 2016 (64-bit edition) | Remote Code Execution | Important | 4464583 | Security Update | CVE-2025-49699 |
| Microsoft Word 2016 (32-bit edition) | Remote Code Execution | Important | 5001941 | Security Update | CVE-2025-49699 |
| Microsoft Word 2016 (32-bit edition) | Remote Code Execution | Important | 4464583 | Security Update | CVE-2025-49699 |
| Remote Desktop client for Windows Desktop | Remote Code Execution | Important | Release Notes | {“type”:5,”hyperlink”:”https://learn.microsoft.com/en-us/azure/virtual-desktop/whats-new-client-windows#updates-for-version-1263530″,”tooltip”:”Open \”https://learn.microsoft.com/en-us/azure/virtual-desktop/whats-new-client-windows#updates-for-version-1263530\””} | CVE-2025-48817 |
| Windows App Client for Windows Desktop | Remote Code Execution | Important | Release Notes | {“type”:5,”hyperlink”:”https://learn.microsoft.com/en-us/windows-app/whats-new?toc=admins%2Ftoc.json&tabs=windows”,”tooltip”:”Open \”https://learn.microsoft.com/en-us/windows-app/whats-new?toc=admins%2Ftoc.json&tabs=windows\””} | CVE-2025-48817 |
| Microsoft Configuration Manager 2503 | Remote Code Execution | Important | KB31909343 | {“type”:5,”hyperlink”:”https://learn.microsoft.com/en-us/mem/configmgr/core/servers/manage/install-in-console-updates”,”tooltip”:”Open \”https://learn.microsoft.com/en-us/mem/configmgr/core/servers/manage/install-in-console-updates\””} | CVE-2025-47178 |
| Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Critical | 5061018 | Monthly Rollup | CVE-2025-49735 |
| Windows Server 2012 R2 | Remote Code Execution | Critical | 5061018 | Monthly Rollup | CVE-2025-49735 |
| Windows Server 2012 (Server Core installation) | Remote Code Execution | Critical | 5061059 | Monthly Rollup | CVE-2025-49735 |
| Windows Server 2012 | Remote Code Execution | Critical | 5061059 | Monthly Rollup | CVE-2025-49735 |
| Windows Server 2016 (Server Core installation) | Remote Code Execution | Critical | 5061010 | Security Update | CVE-2025-49735 |
| Windows Server 2016 | Remote Code Execution | Critical | 5061010 | Security Update | CVE-2025-49735 |
| Windows Server 2025 | Remote Code Execution | Critical | 5060842 | Security Update | CVE-2025-49735 |
| Windows Server 2022, 23H2 Edition (Server Core installation) | Remote Code Execution | Critical | 5060999 | Security Update | CVE-2025-49735 |
| Windows Server 2025 (Server Core installation) | Remote Code Execution | Critical | 5060842 | Security Update | CVE-2025-49735 |
| Windows Server 2022 (Server Core installation) | Remote Code Execution | Critical | 5060526 | Security Update | CVE-2025-49735 |
| Windows Server 2022 | Remote Code Execution | Critical | 5060526 | Security Update | CVE-2025-49735 |
| Windows Server 2019 (Server Core installation) | Remote Code Execution | Critical | 5060998 | Security Update | CVE-2025-49735 |
| Windows Server 2019 | Remote Code Execution | Critical | 5060998 | Security Update | CVE-2025-49735 |
| Microsoft Teams for Desktop | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-49731 |
| Microsoft Teams for iOS | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-49731 |
| Microsoft Teams for Android | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-49731 |
| Microsoft SQL Server 2017 for x64-based Systems (CU 31) | Information Disclosure | Important | 5058714 | {“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108272″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108272\””} | CVE-2025-49719 |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | Information Disclosure | Important | 5058717 | {“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108273″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108273\””} | CVE-2025-49719 |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR) | Information Disclosure | Important | 5058718 | {“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108275″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108275\””} | CVE-2025-49719 |
| Microsoft SQL Server 2017 for x64-based Systems (GDR) | Information Disclosure | Important | 5058716 | {“type”:5,”hyperlink”:”https://www.microsoft.com/download/details.aspx?id=108271″,”tooltip”:”Open \”https://www.microsoft.com/download/details.aspx?id=108271\””} | CVE-2025-49719 |
| Microsoft Excel 2016 (64-bit edition) | Remote Code Execution | Important | 5002749 | Security Update | CVE-2025-49711 |
| Microsoft Excel 2016 (32-bit edition) | Remote Code Execution | Important | 5002749 | Security Update | CVE-2025-49711 |
| Microsoft Excel 2016 (64-bit edition) | Information Disclosure | Important | 5002734 | Security Update | CVE-2025-48812 |
| Microsoft Excel 2016 (32-bit edition) | Information Disclosure | Important | 5002734 | Security Update | CVE-2025-48812 |
| Azure Service Fabric | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-21195 |
| Microsoft Edge (Chromium-based) | Remote Code Execution | Important | Release Notes | Security Update | CVE-2025-49713 |
| Dynamics 365 FastTrack Implementation | Information Disclosure | Critical | CVE-2025-49715 | ||
| Windows Server 2025 | Security Feature Bypass | Important | 5060841 | SecurityHotpatchUpdate | CVE-2025-33069 |
| Windows 11 Version 24H2 for x64-based Systems | Security Feature Bypass | Important | 5060842 | Security Update | CVE-2025-33069 |
| Windows 11 Version 24H2 for x64-based Systems | Security Feature Bypass | Important | 5060841 | SecurityHotpatchUpdate | CVE-2025-33069 |
| Windows 11 Version 24H2 for ARM64-based Systems | Security Feature Bypass | Important | 5060842 | Security Update | CVE-2025-33069 |
| Windows 11 Version 24H2 for ARM64-based Systems | Security Feature Bypass | Important | 5060841 | SecurityHotpatchUpdate | CVE-2025-33069 |
| Windows Server 2025 (Server Core installation) | Security Feature Bypass | Important | 5060841 | SecurityHotpatchUpdate | CVE-2025-33069 |
| PowerShell 7.5 | Remote Code Execution | Important | Release Notes | {“type”:5,”hyperlink”:”https://github.com/PowerShell/Announcements/issues/77″,”tooltip”:”Open \”https://github.com/PowerShell/Announcements/issues/77\””} | CVE-2025-30399 |
| PowerShell 7.4 | Remote Code Execution | Important | Release Notes | {“type”:5,”hyperlink”:”https://github.com/PowerShell/Announcements/issues/77″,”tooltip”:”Open \”https://github.com/PowerShell/Announcements/issues/77\””} | CVE-2025-30399 |
| .NET 9.0 installed on Windows | Remote Code Execution | Important | 5061936 | Security Update | CVE-2025-30399 |
| .NET 9.0 installed on Mac OS | Remote Code Execution | Important | 5061936 | Security Update | CVE-2025-30399 |
| .NET 9.0 installed on Linux | Remote Code Execution | Important | 5061936 | Security Update | CVE-2025-30399 |
| .NET 8.0 installed on Mac OS | Remote Code Execution | Important | 5061935 | Security Update | CVE-2025-30399 |
| .NET 8.0 installed on Linux | Remote Code Execution | Important | 5061935 | Security Update | CVE-2025-30399 |
| .NET 8.0 installed on Windows | Remote Code Execution | Important | 5061935 | Security Update | CVE-2025-30399 |
| Microsoft Edge (Chromium-based) Updater | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-47181 |
| Microsoft Defender for Endpoint for Linux | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-47161 |
| Microsoft Visual Studio CoPilot Chat Extension | Security Feature Bypass | Important | Release Notes | Security Update | CVE-2025-21264 |
| Microsoft Office LTSC for Mac 2024 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2025-30393 |
| Microsoft Office LTSC for Mac 2021 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2025-30393 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Elevation of Privilege | Important | 5061196 | Monthly Rollup | CVE-2025-32709 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Elevation of Privilege | Important | 5061195 | Security Update | CVE-2025-32709 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Elevation of Privilege | Important | 5061196 | Monthly Rollup | CVE-2025-32709 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Elevation of Privilege | Important | 5061195 | Security Update | CVE-2025-32709 |
| Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Elevation of Privilege | Important | 5061198 | Monthly Rollup | CVE-2025-32709 |
| Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Elevation of Privilege | Important | 5061197 | Security Only | CVE-2025-32709 |
| Windows Server 2008 for x64-based Systems Service Pack 2 | Elevation of Privilege | Important | 5061198 | Monthly Rollup | CVE-2025-32709 |
| Windows Server 2008 for x64-based Systems Service Pack 2 | Elevation of Privilege | Important | 5061197 | Security Only | CVE-2025-32709 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Elevation of Privilege | Important | 5061198 | Monthly Rollup | CVE-2025-32709 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Elevation of Privilege | Important | 5061197 | Security Only | CVE-2025-32709 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 | Elevation of Privilege | Important | 5061198 | Monthly Rollup | CVE-2025-32709 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 | Elevation of Privilege | Important | 5061197 | Security Only | CVE-2025-32709 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 | Elevation of Privilege | Important | 5058449 | Monthly Rollup | CVE-2025-24063 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 | Elevation of Privilege | Important | 5058429 | Security Only | CVE-2025-24063 |
| Windows Server 2016 (Server Core installation) | Elevation of Privilege | Important | 5058383 | Security Update | CVE-2025-24063 |
| Windows Server 2016 | Elevation of Privilege | Important | 5058383 | Security Update | CVE-2025-24063 |
| Windows 10 Version 22H2 for x64-based Systems | Remote Code Execution | Important | 5058379 | Security Update | CVE-2025-30397 |
| Windows 11 Version 22H2 for x64-based Systems | Remote Code Execution | Important | 5058405 | Security Update | CVE-2025-30397 |
| Windows 11 Version 22H2 for ARM64-based Systems | Remote Code Execution | Important | 5058405 | Security Update | CVE-2025-30397 |
| Windows 10 Version 21H2 for x64-based Systems | Remote Code Execution | Important | 5058379 | Security Update | CVE-2025-30397 |
| Windows 10 Version 21H2 for ARM64-based Systems | Remote Code Execution | Important | 5058379 | Security Update | CVE-2025-30397 |
| Windows 10 Version 21H2 for 32-bit Systems | Remote Code Execution | Important | 5058379 | Security Update | CVE-2025-30397 |
| Windows Server 2022 (Server Core installation) | Remote Code Execution | Important | 5058385 | Security Update | CVE-2025-30397 |
| Windows Server 2022 | Remote Code Execution | Important | 5058385 | Security Update | CVE-2025-30397 |
| Windows Server 2022 | Remote Code Execution | Important | 5058500 | SecurityHotpatchUpdate | CVE-2025-30397 |
| Windows Server 2019 (Server Core installation) | Remote Code Execution | Important | 5058392 | Security Update | CVE-2025-30397 |
| Windows Server 2019 | Remote Code Execution | Important | 5058392 | Security Update | CVE-2025-30397 |
| Windows 10 Version 1607 for x64-based Systems | Information Disclosure | Important | 5058383 | Security Update | CVE-2025-29974 |
| Windows 10 Version 1607 for 32-bit Systems | Information Disclosure | Important | 5058383 | Security Update | CVE-2025-29974 |
| Windows 10 for x64-based Systems | Information Disclosure | Important | 5058387 | Security Update | CVE-2025-29974 |
| Windows 10 for 32-bit Systems | Information Disclosure | Important | 5058387 | Security Update | CVE-2025-29974 |
| Windows Server 2025 | Information Disclosure | Important | 5058411 | Security Update | CVE-2025-29974 |
| Windows Server 2025 | Information Disclosure | Important | 5058497 | SecurityHotpatchUpdate | CVE-2025-29974 |
| Windows 11 Version 24H2 for x64-based Systems | Information Disclosure | Important | 5058411 | Security Update | CVE-2025-29974 |
| Windows 11 Version 24H2 for x64-based Systems | Information Disclosure | Important | 5058497 | SecurityHotpatchUpdate | CVE-2025-29974 |
| Windows 11 Version 24H2 for ARM64-based Systems | Information Disclosure | Important | 5058411 | Security Update | CVE-2025-29974 |
| Windows 11 Version 24H2 for ARM64-based Systems | Information Disclosure | Important | 5058497 | SecurityHotpatchUpdate | CVE-2025-29974 |
| Windows Server 2022, 23H2 Edition (Server Core installation) | Information Disclosure | Important | 5058384 | Security Update | CVE-2025-29974 |
| Windows 11 Version 23H2 for x64-based Systems | Information Disclosure | Important | 5058405 | Security Update | CVE-2025-29961 |
| Windows 11 Version 23H2 for ARM64-based Systems | Information Disclosure | Important | 5058405 | Security Update | CVE-2025-29961 |
| Windows Server 2025 (Server Core installation) | Information Disclosure | Important | 5058411 | Security Update | CVE-2025-29961 |
| Windows Server 2025 (Server Core installation) | Information Disclosure | Important | 5058497 | SecurityHotpatchUpdate | CVE-2025-29961 |
| Windows 10 Version 22H2 for 32-bit Systems | Information Disclosure | Important | 5058379 | Security Update | CVE-2025-29961 |
| Windows 10 Version 22H2 for ARM64-based Systems | Information Disclosure | Important | 5058379 | Security Update | CVE-2025-29961 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Information Disclosure | Important | 5058430 | Monthly Rollup | CVE-2025-29956 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Information Disclosure | Important | 5058454 | Security Only | CVE-2025-29956 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Information Disclosure | Important | 5058430 | Monthly Rollup | CVE-2025-29956 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Information Disclosure | Important | 5058454 | Security Only | CVE-2025-29956 |
| Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Information Disclosure | Important | 5058449 | Monthly Rollup | CVE-2025-29956 |
| Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Information Disclosure | Important | 5058429 | Security Only | CVE-2025-29956 |
| Windows Server 2008 for x64-based Systems Service Pack 2 | Information Disclosure | Important | 5058449 | Monthly Rollup | CVE-2025-29956 |
| Windows Server 2008 for x64-based Systems Service Pack 2 | Information Disclosure | Important | 5058429 | Security Only | CVE-2025-29956 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Information Disclosure | Important | 5058449 | Monthly Rollup | CVE-2025-29956 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Information Disclosure | Important | 5058429 | Security Only | CVE-2025-29956 |
| Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5058403 | Monthly Rollup | CVE-2025-27468 |
| Windows Server 2012 R2 | Elevation of Privilege | Important | 5058403 | Monthly Rollup | CVE-2025-27468 |
| Windows Server 2012 (Server Core installation) | Elevation of Privilege | Important | 5058451 | Monthly Rollup | CVE-2025-27468 |
| Windows Server 2012 | Elevation of Privilege | Important | 5058451 | Monthly Rollup | CVE-2025-27468 |
| Microsoft Excel 2016 (64-bit edition) | Remote Code Execution | Important | 5002717 | Security Update | CVE-2025-30376 |
| Microsoft Excel 2016 (32-bit edition) | Remote Code Execution | Important | 5002717 | Security Update | CVE-2025-30376 |
| Windows 10 Version 1809 for x64-based Systems | Remote Code Execution | Important | 5058392 | Security Update | CVE-2025-29969 |
| Windows 10 Version 1809 for 32-bit Systems | Remote Code Execution | Important | 5058392 | Security Update | CVE-2025-29969 |
| Microsoft Excel 2016 (64-bit edition) | Remote Code Execution | Important | 5002695 | Security Update | CVE-2025-32704 |
| Microsoft Excel 2016 (32-bit edition) | Remote Code Execution | Important | 5002695 | Security Update | CVE-2025-32704 |
| Microsoft Visual Studio 2022 version 17.13 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2025-32702 |
| Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Important | 5058380 | IE Cumulative | CVE-2025-30397 |
| Windows Server 2012 R2 | Remote Code Execution | Important | 5058380 | IE Cumulative | CVE-2025-30397 |
| Windows Server 2012 (Server Core installation) | Remote Code Execution | Important | 5058380 | IE Cumulative | CVE-2025-30397 |
| Windows Server 2012 | Remote Code Execution | Important | 5058380 | IE Cumulative | CVE-2025-30397 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Remote Code Execution | Important | 5058380 | IE Cumulative | CVE-2025-30397 |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Remote Code Execution | Important | 5058380 | IE Cumulative | CVE-2025-30397 |
| Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Remote Code Execution | Important | 5058380 | IE Cumulative | CVE-2025-30397 |
| Windows Server 2008 for x64-based Systems Service Pack 2 | Remote Code Execution | Important | 5058380 | IE Cumulative | CVE-2025-30397 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Remote Code Execution | Important | 5058380 | IE Cumulative | CVE-2025-30397 |
| Windows Server 2008 for 32-bit Systems Service Pack 2 | Remote Code Execution | Important | 5058380 | IE Cumulative | CVE-2025-30397 |
| Microsoft Office for Universal | Remote Code Execution | Important | Release Notes | Security Update | CVE-2025-30388 |
| Windows Server 2022 (Server Core installation) | Remote Code Execution | Critical | 5058500 | SecurityHotpatchUpdate | CVE-2025-29833 |
| Microsoft Defender for Identity | Spoofing | Important | CVE-2025-26685 | ||
| Windows HLK for Windows Server 2019 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-27488 |
| Windows HLK for Windows 10 version 2004 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-27488 |
| Windows 10 HLK version 21H2 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-27488 |
| Windows 10 HLK Version 22H2 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-27488 |
| Windows 10 HLK version 20H2 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-27488 |
| Windows HLK for Windows Server 2022 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-27488 |
| Windows 11 HLK 22H2 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-27488 |
| Windows 10 HLK version 21H1 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-27488 |
| Windows HLK Version 1809 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-27488 |
| Windows 11 HLK 24H2 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-27488 |
| Windows HLK for Windows Server 2025 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-27488 |
| Visual Studio Code | Security Feature Bypass | Important | Release Notes | Security Update | CVE-2025-21264 |
| Microsoft Dataverse | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-29826 |
| Azure AI Document Intelligence Studio | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2025-30387 |
| Microsoft Office 2016 (64-bit edition) | Remote Code Execution | Critical | 5002711 | Security Update | CVE-2025-30386 |
| Microsoft Office 2016 (32-bit edition) | Remote Code Execution | Critical | 5002711 | Security Update | CVE-2025-30386 |
| Microsoft SharePoint Server Subscription Edition | Remote Code Execution | Important | 5002709 | Security Update | CVE-2025-30384 |
| Microsoft SharePoint Server 2019 | Remote Code Execution | Important | 5002708 | Security Update | CVE-2025-30384 |
| Microsoft SharePoint Enterprise Server 2016 | Remote Code Execution | Important | 5002722 | Security Update | CVE-2025-30384 |
| Office Online Server | Remote Code Execution | Important | 5002707 | Security Update | CVE-2025-30383 |
| Microsoft Excel 2016 (64-bit edition) | Remote Code Execution | Important | 5002716 | Security Update | CVE-2025-30379 |
| Microsoft Excel 2016 (32-bit edition) | Remote Code Execution | Important | 5002716 | Security Update | CVE-2025-30379 |
| Microsoft Office 2016 (64-bit edition) | Remote Code Execution | Important | 5002717 | Security Update | CVE-2025-29979 |
| Microsoft Office 2016 (32-bit edition) | Remote Code Execution | Important | 5002717 | Security Update | CVE-2025-29979 |
| Microsoft SharePoint Server 2019 | Elevation of Privilege | Important | 5002706 | Security Update | CVE-2025-29976 |
| Microsoft SharePoint Enterprise Server 2016 | Elevation of Privilege | Important | 5002712 | Security Update | CVE-2025-29976 |
| Azure File Sync v20.0 | Elevation of Privilege | Important | Release Notes | N/A | CVE-2025-29973 |
| Azure File Sync v19.0 | Elevation of Privilege | Important | Release Notes | N/A | CVE-2025-29973 |
| Windows 11 Version 24H2 for x64-based Systems | Denial of Service | Important | 5061258 | Security HotPatch Update | CVE-2025-29971 |
| Windows 11 Version 24H2 for ARM64-based Systems | Denial of Service | Important | 5061258 | Security HotPatch Update | CVE-2025-29971 |
| Build Tools for Visual Studio 2022 | Spoofing | Important | Release Notes | Security Update | CVE-2025-26646 |
| .NET 9.0 installed on Windows | Spoofing | Important | 5059201 | Security Update | CVE-2025-26646 |
| .NET 9.0 installed on Mac OS | Spoofing | Important | 5059201 | Security Update | CVE-2025-26646 |
| .NET 9.0 installed on Linux | Spoofing | Important | 5059201 | Security Update | CVE-2025-26646 |
| .NET 8.0 installed on Mac OS | Spoofing | Important | 5059200 | Security Update | CVE-2025-26646 |
| .NET 8.0 installed on Linux | Spoofing | Important | 5059200 | Security Update | CVE-2025-26646 |
| .NET 8.0 installed on Windows | Spoofing | Important | 5059200 | Security Update | CVE-2025-26646 |
For users running Windows 11 version 24H2, the KB5062553 patch brings various quality improvements, including a new Settings homepage for commercial customers. This new homepage will show cards relevant to enterprise-managed Windows 11 devices, including “Recommended settings” and “Bluetooth devices.” There are also two new enterprise-specific device info and accessibility preferences cards.
For Windows 10, the KB5062554 update is now available for users running version 22H2 of the operating system. This release fixes an issue affecting USB-connected Multi-Function printers with dual protocol interfaces.
Organizations looking to deploy this month’s patches should conduct thorough testing before deploying them widely on production systems. That said, applying the patches widely shouldn’t be delayed longer than necessary, as hackers start to work out how to weaponize newly reported vulnerabilities.
A best practice is to make sure you have backed up systems before applying updates. Every month, users experience issues with Windows updates that lead to systems not booting, application and hardware compatibility issues, or even data loss in extreme cases.
There are backup tools built into Windows and Windows Server that you can use to restore systems in the event a patch causes a problem. The backup features in Windows can be used to restore an entire system or files and folders on a granular basis.