Microsoft has released the August 2025 security update, which fixes 111 Microsoft CVEs related to various products like Windows Hyper-V, Azure Virtual Machines, Microsoft Office SharePoint, Microsoft Edge for Android, Microsoft Graphics Component, Microsoft Dynamics 365 (on-premises), Windows Routing and Remote Access Service (RRAS), Windows NTFS, Remote Access Point-to-Point Protocol (PPP) EAP-TLS, Windows Win32K - GRFX, Windows Distributed Transaction Coordinator, and Windows Cloud Files Mini Filter Driver.
The update addresses vulnerabilities in the following components: Remote Desktop Server, Windows DirectX, Windows Installer, Graphics Kernel, Windows Message Queuing, Windows Media, Windows PrintWorkflow UserSvc, Windows NT OS Kernel, Windows Kernel, Windows Streaming WOW Thunk Service Driver, Desktop Windows Manager, Windows Local Security Authority Subsystem Service (LSASS), Windows Remote Desktop Services, Windows Push Notifications, SQL Server, Microsoft Dynamics 365 (on-premises), and Azure File Sync.
August 2025 Security Updates
This release consists of the following 111 Microsoft CVEs:
Tag CVE Base Score FAQs? Workarounds? Mitigations? SQL Server CVE-2025-24999 8.8 Yes No No Microsoft Exchange Server CVE-2025-25005 6.5 No No No Microsoft Exchange Server CVE-2025-25006 5.3 Yes No No Microsoft Exchange Server CVE-2025-25007 5.3 Yes No No Microsoft Exchange Server CVE-2025-33051 7.5 Yes No No SQL Server CVE-2025-47954 8.8 Yes No No Role: Windows Hyper-V CVE-2025-48807 7.5 Yes No No Azure Virtual Machines CVE-2025-49707 7.9 Yes No No Microsoft Office SharePoint CVE-2025-49712 8.8 Yes No No Microsoft Edge for Android CVE-2025-49736 4.3 Yes No No Microsoft Graphics Component CVE-2025-49743 6.7 Yes No No Microsoft Dynamics 365 (on-premises) CVE-2025-49745 5.4 Yes No No Role: Windows Hyper-V CVE-2025-49751 6.8 Yes No No Microsoft Edge for Android CVE-2025-49755 4.3 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49757 8.8 Yes No No SQL Server CVE-2025-49758 8.8 Yes No No SQL Server CVE-2025-49759 8.8 Yes No No Windows Kernel CVE-2025-49761 7.8 Yes No No Windows Ancillary Function Driver for WinSock CVE-2025-49762 7.0 Yes No No Desktop Windows Manager CVE-2025-50153 7.8 Yes No No Windows File Explorer CVE-2025-50154 7.5 Yes No No Windows Push Notifications CVE-2025-50155 7.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-50156 5.7 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-50157 5.7 Yes No No Windows NTFS CVE-2025-50158 7.0 Yes No No Remote Access Point-to-Point Protocol (PPP) EAP-TLS CVE-2025-50159 7.3 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-50160 8.0 Yes No No Windows Win32K - GRFX CVE-2025-50161 7.3 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-50162 8.0 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-50163 8.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-50164 8.0 Yes No No Microsoft Graphics Component CVE-2025-50165 9.8 Yes No No Windows Distributed Transaction Coordinator CVE-2025-50166 6.5 Yes No No Role: Windows Hyper-V CVE-2025-50167 7.0 Yes No No Windows Win32K - ICOMP CVE-2025-50168 7.8 Yes No No Windows SMB CVE-2025-50169 7.5 Yes No No Windows Cloud Files Mini Filter Driver CVE-2025-50170 7.8 Yes No No Remote Desktop Server CVE-2025-50171 9.1 No No No Windows DirectX CVE-2025-50172 6.5 No No No Windows Installer CVE-2025-50173 7.8 Yes No No Graphics Kernel CVE-2025-50176 7.8 Yes No No Windows Message Queuing CVE-2025-50177 8.1 Yes No No Windows Media CVE-2025-53131 8.8 Yes No No Windows Win32K - GRFX CVE-2025-53132 8.0 Yes No No Windows PrintWorkflowUserSvc CVE-2025-53133 7.8 Yes No No Windows Ancillary Function Driver for WinSock CVE-2025-53134 7.0 Yes No No Windows DirectX CVE-2025-53135 7.0 Yes No No Windows NT OS Kernel CVE-2025-53136 5.5 Yes No No Windows Ancillary Function Driver for WinSock CVE-2025-53137 7.0 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-53138 5.7 Yes No No Kernel Transaction Manager CVE-2025-53140 7.0 Yes No No Windows Ancillary Function Driver for WinSock CVE-2025-53141 7.8 Yes No No Microsoft Brokering File System CVE-2025-53142 7.0 Yes No No Windows Message Queuing CVE-2025-53143 8.8 Yes No No Windows Message Queuing CVE-2025-53144 8.8 Yes No No Windows Message Queuing CVE-2025-53145 8.8 Yes No No Windows Ancillary Function Driver for WinSock CVE-2025-53147 7.0 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-53148 5.7 Yes No No Kernel Streaming WOW Thunk Service Driver CVE-2025-53149 7.8 Yes No No Windows Kernel CVE-2025-53151 7.8 Yes No No Desktop Windows Manager CVE-2025-53152 7.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-53153 5.7 Yes No No Windows Ancillary Function Driver for WinSock CVE-2025-53154 7.8 Yes No No Role: Windows Hyper-V CVE-2025-53155 7.8 Yes No No Storage Port Driver CVE-2025-53156 5.5 Yes No No Windows Local Security Authority Subsystem Service (LSASS) CVE-2025-53716 6.5 No No No Windows Ancillary Function Driver for WinSock CVE-2025-53718 7.0 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-53719 5.7 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-53720 8.0 Yes No No Windows Connected Devices Platform Service CVE-2025-53721 7.0 Yes No No Windows Remote Desktop Services CVE-2025-53722 7.5 No No No Role: Windows Hyper-V CVE-2025-53723 7.8 Yes No No Windows Push Notifications CVE-2025-53724 7.8 Yes No No Windows Push Notifications CVE-2025-53725 7.8 Yes No No Windows Push Notifications CVE-2025-53726 7.8 Yes No No SQL Server CVE-2025-53727 8.8 Yes No No Microsoft Dynamics 365 (on-premises) CVE-2025-53728 6.5 Yes No No Azure File Sync CVE-2025-53729 7.8 Yes No No Microsoft Office Visio CVE-2025-53730 7.8 Yes No No Microsoft Office CVE-2025-53731 8.4 Yes No No Microsoft Office CVE-2025-53732 7.8 Yes No No Microsoft Office Word CVE-2025-53733 8.4 Yes No No Microsoft Office Visio CVE-2025-53734 7.8 Yes No No Microsoft Office Excel CVE-2025-53735 7.8 Yes No No Microsoft Office Word CVE-2025-53736 6.8 Yes No No Microsoft Office Excel CVE-2025-53737 7.8 Yes No No Microsoft Office Word CVE-2025-53738 7.8 Yes No No Microsoft Office Excel CVE-2025-53739 7.8 Yes No No Microsoft Office CVE-2025-53740 8.4 Yes No No Microsoft Office Excel CVE-2025-53741 7.8 Yes No No Microsoft Office Excel CVE-2025-53759 7.8 Yes No No Microsoft Office SharePoint CVE-2025-53760 7.1 Yes No No Microsoft Office PowerPoint CVE-2025-53761 7.8 Yes No No Azure Stack CVE-2025-53765 4.4 Yes No No Windows GDI+ CVE-2025-53766 9.8 Yes No No Azure OpenAI CVE-2025-53767 10.0 Yes No No Windows Security App CVE-2025-53769 5.5 No No No Web Deploy CVE-2025-53772 8.8 Yes No No GitHub Copilot and Visual Studio CVE-2025-53773 7.8 Yes No No Microsoft 365 Copilot's Business Chat CVE-2025-53774 6.5 Yes No No Windows NTLM CVE-2025-53778 8.8 Yes No No Windows Kerberos CVE-2025-53779 7.2 Yes No No Azure Virtual Machines CVE-2025-53781 7.7 Yes No No Microsoft Teams CVE-2025-53783 7.5 Yes No No Microsoft Office Word CVE-2025-53784 8.4 Yes No No Microsoft Exchange Server CVE-2025-53786 8.0 Yes No No Microsoft 365 Copilot's Business Chat CVE-2025-53787 8.2 Yes No No Windows Subsystem for Linux CVE-2025-53788 7.0 Yes No No Windows StateRepository API CVE-2025-53789 7.8 Yes No No Azure Portal CVE-2025-53792 9.1 Yes No No Azure Stack CVE-2025-53793 7.5 Yes No No We are republishing 8 non-Microsoft CVEs:
CNA Tag CVE FAQs? Workarounds? Mitigations? Chrome Microsoft Edge (Chromium-based) CVE-2025-8576 Yes No No Chrome Microsoft Edge (Chromium-based) CVE-2025-8577 Yes No No Chrome Microsoft Edge (Chromium-based) CVE-2025-8578 Yes No No Chrome Microsoft Edge (Chromium-based) CVE-2025-8579 Yes No No Chrome Microsoft Edge (Chromium-based) CVE-2025-8580 Yes No No Chrome Microsoft Edge (Chromium-based) CVE-2025-8581 Yes No No Chrome Microsoft Edge (Chromium-based) CVE-2025-8582 Yes No No Chrome Microsoft Edge (Chromium-based) CVE-2025-8583 Yes No No Security Update Guide Blog Posts
Date Blog Post November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API January 11, 2022 Coming Soon: New Security Update Guide Notification System February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners December 8, 2020 Security Update Guide: Let’s keep the conversation going November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide Relevant Resources
- The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
- Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
- Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
- A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
- In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
- Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
Known Issues
You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.
For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).
KB Article Applies To 5063888 Windows Server 2008 (Monthly Rollup) 5063948 Windows Server 2008 (Security-only update) 5002769 SharePoint Server 2019 5050672 Exchange Server 2019 CU15 5050673 Exchange Server 2019 CU14 5050674 Exchange Server 2016 CU23