Microsoft has released the July 2025 security update release, which includes 130 Microsoft CVEs, including Service Fabric, Windows Kernel, Remote Desktop Client, Windows Visual Basic Scripting, Microsoft Intune, Virtual Hard Disk (VHDX), Microsoft Input Method Editor (IME), Windows Storage VSP Driver, Windows GDI, Windows Event Tracing, Universal Print Management Service, Windows Cred SSProvider Protocol, Azure Monitor Agent, Microsoft Input Method Editor (IME), Microsoft PC Manager, Microsoft Office, Windows MBT Transport driver, Windows Routing and Remote Access Service (RRAS), Windows Hyper-V, Windows Connected Devices Platform Service, Windows BitLocker, Windows Update Service, Windows SMB, Windows Virtualization-Based Security (VBS) Enclave, Microsoft MPEG-2 Video Extension, Windows Kernel, Windows Secure Kernel Mode, Windows Office Excel, Windows Remote Desktop Licensing Service, Windows SSDP Service, HID class driver, Remote Desktop Client, Windows Universal Plug and Play (UPnP) Device Host, Windows AppX Deployment Service, Windows Cryptographic Services, Windows Routing and Remote Access Service (RRAS), Windows TDX.sys, Windows Event Tracing, Windows Ancillary Function Driver for WinSock, Windows Routing and Remote Access Service (RRAS), Windows User-Mode Driver Framework Host, Workspace Broker, Windows Kernel, Windows Win32K - ICOMP, and Windows Routing and Remote Access Service (RRAS).
July 2025 Security Updates
This release consists of the following 130 Microsoft CVEs:
Tag CVE Base Score FAQs? Workarounds? Mitigations? Service Fabric CVE-2025-21195 6.0 Yes No No Windows Kernel CVE-2025-26636 5.5 Yes No No Remote Desktop Client CVE-2025-33054 8.1 Yes No No Windows Visual Basic Scripting CVE-2025-47159 7.8 Yes No No Microsoft Intune CVE-2025-47178 8.0 Yes No No Virtual Hard Disk (VHDX) CVE-2025-47971 7.8 Yes No No Microsoft Input Method Editor (IME) CVE-2025-47972 8.0 Yes No No Virtual Hard Disk (VHDX) CVE-2025-47973 7.8 Yes No No Windows SSDP Service CVE-2025-47975 7.0 Yes No No Windows SSDP Service CVE-2025-47976 7.8 Yes No No Windows Kerberos CVE-2025-47978 6.5 No No No Windows Imaging Component CVE-2025-47980 6.2 Yes No No Windows SPNEGO Extended Negotiation CVE-2025-47981 9.8 Yes No Yes Windows Storage VSP Driver CVE-2025-47982 7.8 Yes No No Windows GDI CVE-2025-47984 7.5 Yes No No Windows Event Tracing CVE-2025-47985 7.8 Yes No No Universal Print Management Service CVE-2025-47986 8.8 Yes No No Windows Cred SSProvider Protocol CVE-2025-47987 7.8 Yes No No Azure Monitor Agent CVE-2025-47988 7.5 Yes No No Microsoft Input Method Editor (IME) CVE-2025-47991 7.8 Yes No No Microsoft PC Manager CVE-2025-47993 7.8 Yes No No Microsoft Office CVE-2025-47994 7.8 Yes No No Windows MBT Transport driver CVE-2025-47996 7.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-47998 8.8 Yes No No Role: Windows Hyper-V CVE-2025-47999 6.8 Yes No No Windows Connected Devices Platform Service CVE-2025-48000 7.8 Yes No No Windows BitLocker CVE-2025-48001 6.8 Yes No No Role: Windows Hyper-V CVE-2025-48002 5.7 Yes No No Windows BitLocker CVE-2025-48003 6.8 Yes No No Windows Update Service CVE-2025-48799 7.8 Yes No No Windows BitLocker CVE-2025-48800 6.8 Yes No No Windows SMB CVE-2025-48802 6.5 No No No Windows Virtualization-Based Security (VBS) Enclave CVE-2025-48803 6.7 Yes No No Windows BitLocker CVE-2025-48804 6.8 Yes No No Microsoft MPEG-2 Video Extension CVE-2025-48805 7.8 Yes No No Microsoft MPEG-2 Video Extension CVE-2025-48806 7.8 Yes No No Windows Kernel CVE-2025-48808 5.5 Yes No No Windows Kernel CVE-2025-48809 5.5 Yes No No Windows Secure Kernel Mode CVE-2025-48810 5.5 Yes No No Windows Virtualization-Based Security (VBS) Enclave CVE-2025-48811 6.7 Yes No No Microsoft Office Excel CVE-2025-48812 5.5 Yes No No Windows Remote Desktop Licensing Service CVE-2025-48814 7.5 Yes No No Windows SSDP Service CVE-2025-48815 7.8 Yes No No HID class driver CVE-2025-48816 7.8 Yes No No Remote Desktop Client CVE-2025-48817 8.8 Yes No No Windows BitLocker CVE-2025-48818 6.8 Yes No No Windows Universal Plug and Play (UPnP) Device Host CVE-2025-48819 7.1 Yes No No Windows AppX Deployment Service CVE-2025-48820 7.8 Yes No No Windows Universal Plug and Play (UPnP) Device Host CVE-2025-48821 7.1 Yes No No Role: Windows Hyper-V CVE-2025-48822 8.6 Yes No No Windows Cryptographic Services CVE-2025-48823 5.9 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-48824 8.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49657 8.8 Yes No No Windows TDX.sys CVE-2025-49658 5.5 Yes No No Windows TDX.sys CVE-2025-49659 7.8 Yes No No Windows Event Tracing CVE-2025-49660 7.8 Yes No No Windows Ancillary Function Driver for WinSock CVE-2025-49661 7.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49663 8.8 Yes No No Windows User-Mode Driver Framework Host CVE-2025-49664 5.5 Yes No No Workspace Broker CVE-2025-49665 7.8 Yes No No Windows Kernel CVE-2025-49666 7.2 Yes No No Windows Win32K - ICOMP CVE-2025-49667 7.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49668 8.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49669 8.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49670 8.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49671 6.5 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49672 8.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49673 8.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49674 8.8 Yes No No Kernel Streaming WOW Thunk Service Driver CVE-2025-49675 7.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49676 8.8 Yes No No Microsoft Brokering File System CVE-2025-49677 7.0 Yes No No Windows NTFS CVE-2025-49678 7.0 Yes No No Windows Shell CVE-2025-49679 7.8 Yes No No Windows Performance Recorder CVE-2025-49680 7.3 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49681 6.5 Yes No No Windows Media CVE-2025-49682 7.3 Yes No No Virtual Hard Disk (VHDX) CVE-2025-49683 7.8 Yes No No Storage Port Driver CVE-2025-49684 5.5 Yes No No Microsoft Windows Search Component CVE-2025-49685 7.0 Yes No No Windows TCP/IP CVE-2025-49686 7.8 Yes No No Microsoft Input Method Editor (IME) CVE-2025-49687 8.8 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49688 8.8 Yes No No Virtual Hard Disk (VHDX) CVE-2025-49689 7.8 Yes No No Capability Access Management Service (camsvc) CVE-2025-49690 7.4 Yes No No Windows Media CVE-2025-49691 8.8 Yes No No Microsoft Brokering File System CVE-2025-49693 7.8 Yes No No Microsoft Brokering File System CVE-2025-49694 7.8 Yes No No Microsoft Office CVE-2025-49695 8.4 Yes No No Microsoft Office CVE-2025-49696 8.4 Yes No No Microsoft Office CVE-2025-49697 8.4 Yes No No Microsoft Office Word CVE-2025-49698 7.8 Yes No No Microsoft Office CVE-2025-49699 7.0 Yes No No Microsoft Office Word CVE-2025-49700 7.8 Yes No No Microsoft Office SharePoint CVE-2025-49701 8.8 Yes No No Microsoft Office CVE-2025-49702 7.8 Yes No No Microsoft Office Word CVE-2025-49703 7.8 Yes No No Microsoft Office SharePoint CVE-2025-49704 8.8 Yes No No Microsoft Office PowerPoint CVE-2025-49705 7.8 Yes No No Microsoft Office SharePoint CVE-2025-49706 6.3 Yes No No Microsoft Office Excel CVE-2025-49711 7.8 Yes No No Microsoft Edge (Chromium-based) CVE-2025-49713 8.8 Yes No No Visual Studio Code - Python extension CVE-2025-49714 7.8 No No No Windows Netlogon CVE-2025-49716 5.9 Yes No No SQL Server CVE-2025-49717 8.5 Yes No No SQL Server CVE-2025-49718 7.5 Yes No No SQL Server CVE-2025-49719 7.5 Yes No No Windows Fast FAT Driver CVE-2025-49721 7.8 Yes No No Windows Print Spooler Components CVE-2025-49722 5.7 Yes No No Windows StateRepository API CVE-2025-49723 8.8 Yes No No Windows Connected Devices Platform Service CVE-2025-49724 8.8 Yes No Yes Windows Notification CVE-2025-49725 7.8 Yes No No Windows Notification CVE-2025-49726 7.8 Yes No No Windows Win32K - GRFX CVE-2025-49727 7.0 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49729 8.8 Yes No No Microsoft Windows QoS scheduler CVE-2025-49730 7.8 Yes No No Microsoft Teams CVE-2025-49731 3.1 Yes No No Microsoft Graphics Component CVE-2025-49732 7.8 Yes No No Windows Win32K - ICOMP CVE-2025-49733 7.8 Yes No No Windows KDC Proxy Service (KPSSVC) CVE-2025-49735 8.1 Yes No No Microsoft Teams CVE-2025-49737 7.0 Yes No No Microsoft PC Manager CVE-2025-49738 7.8 Yes No No Visual Studio CVE-2025-49739 8.8 Yes No No Windows SmartScreen CVE-2025-49740 8.8 Yes No No Microsoft Edge (Chromium-based) CVE-2025-49741 7.4 Yes No No Microsoft Graphics Component CVE-2025-49742 7.8 Yes No No Microsoft Graphics Component CVE-2025-49744 7.0 Yes No No Windows Routing and Remote Access Service (RRAS) CVE-2025-49753 8.8 Yes No No Office Developer Platform CVE-2025-49756 3.3 Yes No No Windows Storage CVE-2025-49760 3.5 No No No We are republishing 10 non-Microsoft CVEs:
CNA Tag CVE FAQs? Workarounds? Mitigations? MITRE Visual Studio CVE-2025-27613 No No No MITRE Visual Studio CVE-2025-27614 No No No AMD AMD Store Queue CVE-2025-36350 Yes No No AMD AMD L1 Data Queue CVE-2025-36357 Yes No No MITRE Visual Studio CVE-2025-46334 No No No MITRE Visual Studio CVE-2025-46835 No No No MITRE Visual Studio CVE-2025-48384 No No No MITRE Visual Studio CVE-2025-48385 No No No MITRE Visual Studio CVE-2025-48386 No No No Chrome Microsoft Edge (Chromium-based) CVE-2025-6554 Yes No No Security Update Guide Blog Posts
Date Blog Post November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API January 11, 2022 Coming Soon: New Security Update Guide Notification System February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners December 8, 2020 Security Update Guide: Let’s keep the conversation going November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide Relevant Resources
- The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
- Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
- Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
- A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
- In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
- Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
Known Issues
You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.
For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).
KB Article Applies To 5062554 Windows 10, version 21H2, Windows 10, version 22H2 5062557 Windows 10, version 1809, Windows Server 2019 5062560 Windows 10, version 1607, Windows Server 2016 5062572 Windows Server 2022 5062618 Windows Server 2008 (Security-only update) 5062624 Windows Server 2008 (Monthly Rollup)