• News/
  • https://www.theregister.com/2025/05/14/patch_tuesday_may/

Microsoft, Apple fix exploited flaws on Patch Tuesday

The Register
·
Iain Thomson
·
Published May 14, 2025
·
Updated

Patch Tuesday It's that time of the month again, and Microsoft has made it extra spicy by revealing five flaws it says are under active exploitation – but rates as important rather than critical fixes. Microsoft's 78-fix bundle for this Patch Tuesday wasn't unusually large, but the five problems under attack right now all have CVSS severity scores of 7.5 or 7.8 out of 10, and hit Windows 10 and 11 devices, and Windows Server releases since 2019. They look like strong candidates to be top of your patching list in your next change window. The five exploited flaws are: After you deal with the above, the next three Microsoft patches of interest are Azure problems – especially the 10/10 rated CVE-2025-29813, an authentication bypass attack on the cloud platform's DevOps platform. CVE-2025-29827 allows elevation of privilege attacks against Azure Automation, and CVE-2025-29972 is a spoofing attack against Azure Storage. Crucially, Microsoft has already fixed all three in production, and says it added the CVE information to the patch bundle to "provide further transparency." You can see the rest of the critical fixes and patches-of-interest in May's batch below, a summary courtesy of Trend Micro's Zero Day Initiative. "There are seven lucky Denial-of-Service (DoS) bugs getting patches this month," commented Dustin Childs, head of threat awareness at Trend's ZDI. However, Microsoft provides no actionable information about these bugs. Instead, they simply state that an attacker could ...

Read full article

Affected Software

35 affected components
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Server=2019
Microsoft Azure DevOps
Microsoft Azure Automation
Microsoft Azure Storage
Adobe Photoshop
Adobe Illustrator
Adobe Animate
Adobe ColdFusion
Adobe Substance 3D Stager
Adobe Connect
Adobe Bridge
Adobe InDesign
Adobe Dimension
Adobe Substance 3D Painter
Adobe Lightroom
Apple iOS=18.4.1
Apple iOS=18.5
Apple iOS=17.77
Apple Safari=18.5
Apple macOS Sequoia=15.5
Apple macOS Sonoma=14.7.6
Apple Ventura=13.7.6
Apple tvOS
Apple visionOS=2.5
Apple WatchOS=11.5
SAP NetWeaver
Ivanti Neurons for ITSM
Ivanti Cloud Services Application
Ivanti Neurons for MDM
Microsoft Windows=10
Microsoft Windows=11
Microsoft Windows Server
Microsoft Azure
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main focus of this article?

The article discusses the May Patch Tuesday updates from Microsoft and Apple, highlighting five flaws currently being exploited.

2

What security vulnerabilities are highlighted in the updates?

The article mentions five important flaws reported by Microsoft that are under active exploitation.

3

Which Microsoft products are affected by the vulnerabilities?

Affected Microsoft products include Windows 10, Windows 11, Windows Server 2019, Azure DevOps, Azure Automation, and Azure Storage.

4

What Apple products received security updates?

Apple's updates address security vulnerabilities in iOS 18.4.1, 18.5, Safari 18.5, and various macOS versions including Sequoia and Sonoma.

5

How does Microsoft categorize the exploited flaws?

Microsoft rates the five exploited flaws as important rather than critical in their severity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203