Severity
High
Analysis Summary
CVE-2025-53772 CVSS:8.8
Microsoft Web Deploy could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data.
CVE-2025-53729 CVSS:7.8
Microsoft Azure File Sync could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper access control.
CVE-2025-53793 CVSS:7.5
Microsoft Azure Stack Hub could allow a local attacker to obtain sensitive information, caused by improper authentication that allows the exposure of private personal information to an unauthorized actor.
CVE-2025-53140 CVSS:7
Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a use-after-free error in the Kernel Transaction Manager component.
CVE-2025-53149 CVSS:7.8
Microsoft Windows is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by the Kernel Streaming WOW Thunk Service Driver component. A local authenticated attacker could exploit this vulnerability to gain elevated privileges on the system.
CVE-2025-50154 CVSS:7.5
Microsoft Windows could allow a remote attacker to conduct spoofing attacks, caused by exposure of sensitive information to an unauthorized actor in the File Explorer.
CVE-2025-25005 CVSS:6.5
Microsoft Exchange Server could allow a remote attacker to obtain sensitive information, caused by an improper input validation error.
CVE-2025-53779 CVSS:7.2
Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a relative path traversal in the Kerberos component.
Impact
- Gain Access
- Code Execution
- Privilege Escalation
- Information Disclosure
Indicators of Compromise
CVE
- CVE-2025-53772
- CVE-2025-53729
- CVE-2025-53793
- CVE-2025-53140
- CVE-2025-53149
- CVE-2025-50154
- CVE-2025-25005
- CVE-2025-53779
Affected Vendors
- Microsoft
Affected Products
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
- Microsoft Windows Server 2012
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2022
- Microsoft Windows Server 2019 (Server Core installation)
- Microsoft Windows Server 2012 (Server Core installation)
- Microsoft Windows Server 2012 R2 (Server Core installation)
- Microsoft Windows Server 2016 (Server Core installation)
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Windows Server 2025 (Server Core installation)
- Microsoft Windows 10 Version 1507
- Microsoft Windows 11 version 22H2
- Microsoft Windows 10 Version 1809
- Microsoft Windows 11 version 22H3
- Microsoft Windows 11 Version 23H2
- Microsoft Windows Server 2025 (Server Core installation) 10.0.26100.0
- Microsoft Windows Server 2025 10.0.26100.0
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Web Deploy 4.0
- Microsoft Azure File Sync
- Microsoft Azure Stack Hub 2408
- Microsoft Azure Stack Hub 2406
- Microsoft Azure Stack Hub 2501
- Microsoft Windows Server 2022 - 23H2 Edition (Server Core installation)
Remediation
Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

