Transcript
and we're here to talk about the September patch Tuesday. The first thing I want to talk about today is CVE-2025-55234. It's an SMB relay attack. And the executive summary for this one definitely caught my attention. Microsoft states that they released the CVE to provide customers with audit capabilities. Now the goal of a CVE should be to define a vulnerability, not to announce new configuration features. I'm really hoping that Microsoft clarifies the statement, otherwise I wonder if this CVE should even exist. After all, SMB relay attacks are nothing new. A bit of a warning for anyone running the Microsoft High Performance Compute Pack or the HPC Pack. There was a single critical CVSS score vulnerability this month, and it was for CVE-2025-55232, which is a vulnerability in the HPC Pack. The vulnerability allows for unauthenticated remote code execution. Hopefully that risk will be offset by the fact that not everyone runs this software, and that's likely one of the reasons why Microsoft has indicated that exploitation is less likely for this vulnerability. Finally, just for awareness this month, I think it's worth mentioning CVE-2025-55241. It was an elevation of privilege in Azure Entra. Now this is a no privileges required privilege escalation, which is somewhat interesting, but there's no action to take on your part. The only reason I'm mentioning it is because Azure Entra is such a critical component in environments, and it's something that you might want to talk to Microsoft about just to find out a bit more about how this vulnerability was discovered, or to find out if it had ever been exploited in the past in your environment. I doubt that's the case, given they didn't say anything, but it's always worth double checking. Once again, I'm Tyler Reguli, and this has been your September Patch Tuesday Update. Thank you, and have a great day.