Overview
- The August 12, 2025 update addresses 119 vulnerabilities across Windows, Azure and Microsoft applications, with 13 rated critical and 91 important.
- A publicly disclosed zero-day, CVE-2025-53779 in Windows Kerberos, could let authenticated attackers elevate to domain administrator privileges.
- Critical remote code execution and elevation-of-privilege patches target DirectX Graphics Kernel, Microsoft Message Queuing, Office components and GDI+.
- Affected products range from Hyper-V, NTLM authentication and Microsoft Edge to cloud services including Azure Virtual Machines, Azure OpenAI and Microsoft 365 Copilot.
- Qualys urges urgent remediation using its VMDR platform paired with a detailed webinar to speed deployment of these high-impact patches.