Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

September 2025 Patch Tuesday: SMB Relay & Azure Entra

Fortra
03/30/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


and we're here to talk about the September patch Tuesday. The first thing I want to talk about today is CVE-2025-55234. It's an SMB relay attack. And the executive summary for this one definitely caught my attention. Microsoft states that they released the CVE to provide customers with audit capabilities. Now the goal of a CVE should be to define a vulnerability, not to announce new configuration features. I'm really hoping that Microsoft clarifies the statement, otherwise I wonder if this CVE should even exist. After all, SMB relay attacks are nothing new. A bit of a warning for anyone running the Microsoft High Performance Compute Pack or the HPC Pack. There was a single critical CVSS score vulnerability this month, and it was for CVE-2025-55232, which is a vulnerability in the HPC Pack. The vulnerability allows for unauthenticated remote code execution. Hopefully that risk will be offset by the fact that not everyone runs this software, and that's likely one of the reasons why Microsoft has indicated that exploitation is less likely for this vulnerability. Finally, just for awareness this month, I think it's worth mentioning CVE-2025-55241. It was an elevation of privilege in Azure Entra. Now this is a no privileges required privilege escalation, which is somewhat interesting, but there's no action to take on your part. The only reason I'm mentioning it is because Azure Entra is such a critical component in environments, and it's something that you might want to talk to Microsoft about just to find out a bit more about how this vulnerability was discovered, or to find out if it had ever been exploited in the past in your environment. I doubt that's the case, given they didn't say anything, but it's always worth double checking. Once again, I'm Tyler Reguli, and this has been your September Patch Tuesday Update. Thank you, and have a great day.

TL;DR

  • CVE-2025-55234 is an SMB relay attack that Microsoft released to provide audit capabilities, raising questions about whether it should be classified as a CVE since SMB relay attacks are not new.
  • CVE-2025-55232 is a critical unauthenticated remote code execution vulnerability in Microsoft HPC Pack, though exploitation is considered less likely due to limited deployment of the software.
  • CVE-2025-55241 is a no-privileges-required privilege escalation in Azure Entra that has been automatically patched, but organizations should verify if their environments were affected given Entra's critical role.

Summary

Tyler Reguly, Associate Director of Security R&D at Fortra, provides a focused analysis of September 2025's Microsoft Patch Tuesday release, highlighting three vulnerabilities that warrant attention from IT and security teams. The briefing examines CVE-2025-55234, an SMB relay attack that Microsoft released primarily for audit capabilities rather than as a traditional vulnerability disclosure—a decision that raises questions about CVE assignment practices. Reguly also covers CVE-2025-55232, a critical unauthenticated remote code execution vulnerability in Microsoft's High Performance Compute Pack, and CVE-2025-55241, a privilege escalation issue in Azure Entra that requires no user privileges. While the Azure Entra vulnerability has been patched automatically by Microsoft, Reguly recommends organizations verify whether their environments were affected. This concise update helps administrators prioritize patching efforts and understand the strategic implications of Microsoft's security communications.

Chapters

0:00 - Introduction
0:09 - CVE-2025-55234: SMB Relay
0:40 - CVE-2025-55232: HPC Pack RCE
1:15 - CVE-2025-55241: Azure Entra Escalation

Key Quotes

0:18 "Microsoft states that they released the CVE to provide customers with audit capabilities. Now the goal of a CVE should be to define a vulnerability, not to announce new configuration features."
0:54 "The vulnerability allows for unauthenticated remote code execution. Hopefully that risk will be offset by the fact that not everyone runs this software, and that's likely one of the reasons why Microsoft has indicated that exploitation is less likely for this vulnerability."
1:35 "Azure Entra is such a critical component in environments, and it's something that you might want to talk to Microsoft about just to find out a bit more about how this vulnerability was discovered, or to find out if it had ever been exploited in the past in your environment."

Categories:
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Cloud Security
  • Identity & Access
  • Technical Deep Dive
  • Best Practices
  • Patch Tuesday
  • Microsoft Security Updates
  • SMB Relay Attacks
  • Remote Code Execution
  • Azure Entra Security
  • Privilege Escalation
  • CVE Assignment Practices
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: September 2025 Patch Tuesday: SMB Relay & Azure Entra

              Industry Events (Sponsor Hosted)

              • Sep
                29

                Embracing AI Adoption While Ensuring Robust Security Measures

                09/29/202612:00 PM ET
                • Oct
                  01

                  Meta Muse 101: Embracing the Agentic Internet and Its Next Steps.

                  10/01/202601:00 PM ET
                  • Oct
                    13

                    Your Questions Answered: Insights on DatasecAI 2026

                    10/13/202602:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Enhanced Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-enhanced-visibility-and-control-in-your-operations/
                    • 10/01/2026
                      01:00 PM
                      10/01/2026
                      Meta Muse 101: Embracing the Agentic Internet and Its Next Steps.
                      https://www.truthinit.com/index.php/channel/2144/meta-muse-101-embracing-the-agentic-internet-and-its-next-steps/
                    • 10/13/2026
                      02:00 PM
                      10/13/2026
                      Your Questions Answered: Insights on DatasecAI 2026
                      https://www.truthinit.com/index.php/channel/2141/your-questions-answered-insights-on-datasecai-2026/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version