Patch Tuesday - July 2025

https://www.redlegg.com/hubfs/Theme-2024/overlay-red.png featured image

By: RedLegg Blog

*Important note: These are not the only vulnerabilities that were recently released; however, these are the vulnerabilities RedLegg has identified as critical and require immediate attention.

CRITICAL VULNERABILITIES

 

Windows KDC Proxy Service (KPSSVC)

CVE-2025-49735

Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability

Critical

SQL Server

CVE-2025-49717

Microsoft SQL Server Remote Code Execution Vulnerability

Critical

Microsoft Office SharePoint

CVE-2025-49704

Microsoft SharePoint Remote Code Execution Vulnerability

Critical

Microsoft Office Word

CVE-2025-49703

Microsoft Word Remote Code Execution Vulnerability

Critical

Microsoft Office

CVE-2025-702

Microsoft Office Remote Code Execution Vulnerability

Critical

Microsoft Office Word

CVE-2025-49698

Microsoft Word Remote Code Execution Vulnerability

Critical

Microsoft Office

CVE-2025-49697

Microsoft Office Remote Code Execution Vulnerability

Critical

Microsoft Office

CVE-2025-49696

Microsoft Office Remote Code Execution Vulnerability

Critical

Microsoft Office

CVE-2025-49695

Microsoft Office Remote Code Execution Vulnerability

Critical

Role: Windows Hyper-V

CVE-2025-48822

Windows Hyper-V Discrete Device Assignment (DDA) Remote Code Execution Vulnerability

Critical

Windows SPNEGO Extended Negotiation

CVE-2025-47981

SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability

Critical

Windows Imaging Component

 Windows Imaging Component Information Disclosure Vulnerability

Critical

AMD L1 Data Queue

    
CVE-2025-36357

AMD: CVE-2025-36357 Transient Scheduler Attack in L1 Data Queue

Critical

AMD Store Queue

AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue

Critical