September’s Patch Tuesday won’t require Microsoft users to rapidly repair rancid software, but SAP users need to move fast to address extremely dangerous bugs. Microsoft did find two bugs worthy of urgent attention. CVE-2025-55234 allows relay attacks and escalation of privileges against SMB Server. Admins can ameliorate these by using Server signing and the Extended Protection for Authentication (EPA) but it's better to patch and be safe than sorry. The second, CVE-2024-21907, isn't too much of an issue unless you're running a version of Newtonsoft.Json prior to the 13.0.1 build. This flaw emerged last year, so if you're vulnerable you may already face a problem with denial-of-service attacks exploiting the errors in its use of libraries. Microsoft’s fixed-flaw manifesto includes the 9.8-rated CVE-2025-55232 which can cause serious problems for users of Microsoft's High Performance Compute package, allowing code execution over the network. Redmond warns admins to watch for dodgy traffic on TCP port 5999 as that’s a sign this issue is under attack. That’s one of eight critical flaws. Office's Preview pane is still causing problems - this time with CVE-2025-54910. Maybe turn it off for the moment if possible. Redmond issued eight important patches for Excel. Six fixes for Defender Firewall address elevation of privilege attacks. Five fixes patch up Hyper-V. Users of Redmond’s Routing and Remote Access Service (RRAS) have ten fixes to consider. SAP NetWeaver customers need to g...
Microsoft enjoys first Patch Tuesday of 2025 with no active exploits
The Register
·Iain Thomson
·Published Jul 8, 2025
·Updated
Affected Software
3 affected components
Microsoft SMB Server
Newtonsoft Json=13.0.1
Microsoft High Performance Compute
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Microsoft Patch Tuesday for July 2025, highlighting the lack of urgent patches for Microsoft software and emphasizing the need for SAP users to address critical vulnerabilities.
2
What security implications are discussed in the article?
The article mentions urgent vulnerabilities in SAP software and highlights a specific Microsoft bug, CVE-2025-55234, which allows relay attacks and privilege escalation.
3
What products or software are affected by the vulnerabilities mentioned?
The affected products include Microsoft SMB Server, Newtonsoft Json, and Microsoft High Performance Compute.
4
What specific vulnerabilities are highlighted in the Patch Tuesday report?
CVE-2025-55234 is noted for allowing relay attacks and privilege escalation against the SMB Server.
5
What actions should users take regarding SAP software based on the article?
SAP users are urged to quickly address extremely dangerous bugs that were identified in the July 2025 Patch Tuesday report.