• News/
  • https://www.theregister.com/2025/07/08/microsoft_patch_tuesday/

Microsoft enjoys first Patch Tuesday of 2025 with no active exploits

The Register
·
Iain Thomson
·
Published Jul 8, 2025
·
Updated

September’s Patch Tuesday won’t require Microsoft users to rapidly repair rancid software, but SAP users need to move fast to address extremely dangerous bugs. Microsoft did find two bugs worthy of urgent attention. CVE-2025-55234 allows relay attacks and escalation of privileges against SMB Server. Admins can ameliorate these by using Server signing and the Extended Protection for Authentication (EPA) but it's better to patch and be safe than sorry. The second, CVE-2024-21907, isn't too much of an issue unless you're running a version of Newtonsoft.Json prior to the 13.0.1 build. This flaw emerged last year, so if you're vulnerable you may already face a problem with denial-of-service attacks exploiting the errors in its use of libraries. Microsoft’s fixed-flaw manifesto includes the 9.8-rated CVE-2025-55232 which can cause serious problems for users of Microsoft's High Performance Compute package, allowing code execution over the network. Redmond warns admins to watch for dodgy traffic on TCP port 5999 as that’s a sign this issue is under attack. That’s one of eight critical flaws. Office's Preview pane is still causing problems - this time with CVE-2025-54910. Maybe turn it off for the moment if possible. Redmond issued eight important patches for Excel. Six fixes for Defender Firewall address elevation of privilege attacks. Five fixes patch up Hyper-V. Users of Redmond’s Routing and Remote Access Service (RRAS) have ten fixes to consider. SAP NetWeaver customers need to g...

Read full article

Affected Software

3 affected components
Microsoft SMB Server
Newtonsoft Json=13.0.1
Microsoft High Performance Compute
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Microsoft Patch Tuesday for July 2025, highlighting the lack of urgent patches for Microsoft software and emphasizing the need for SAP users to address critical vulnerabilities.

2

What security implications are discussed in the article?

The article mentions urgent vulnerabilities in SAP software and highlights a specific Microsoft bug, CVE-2025-55234, which allows relay attacks and privilege escalation.

3

What products or software are affected by the vulnerabilities mentioned?

The affected products include Microsoft SMB Server, Newtonsoft Json, and Microsoft High Performance Compute.

4

What specific vulnerabilities are highlighted in the Patch Tuesday report?

CVE-2025-55234 is noted for allowing relay attacks and privilege escalation against the SMB Server.

5

What actions should users take regarding SAP software based on the article?

SAP users are urged to quickly address extremely dangerous bugs that were identified in the July 2025 Patch Tuesday report.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203