Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

June 2025 Patch Tuesday: Exploited WebDAV Flaw & Office Risks

Fortra
05/12/2026
22
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • CVE-2025-33053 is actively exploited in the wild, involving malicious .URL shortcut files that link to WebDAV servers to achieve code execution—immediate patching is critical.
  • Four Microsoft Office 365 vulnerabilities are preview pane-affected, meaning exploits could trigger automatically when emails are opened without any user interaction required.
  • Microsoft 365 Office client patches are not yet available for the preview pane vulnerabilities, though no active exploits currently exist, creating a window of exposure to monitor.

Summary

Tyler Reguly, Associate Director of Security R&D at Fortra, provides a focused analysis of June 2025's Microsoft Patch Tuesday, highlighting two critical areas requiring immediate attention from security teams. The briefing covers an actively exploited vulnerability involving .URL shortcut files and WebDAV servers (CVE-2025-33053), which has been documented by Checkpoint researchers and requires urgent patching. Additionally, Reguly addresses four Microsoft Office 365 vulnerabilities that are preview pane-affected, meaning they could execute without user interaction when emails are opened. Notably, patches for the Microsoft 365 Office client are not yet available, creating a temporary exposure window that defenders should monitor. This concise update helps security practitioners prioritize their patching efforts for the month and understand the specific risks associated with each vulnerability class.

Chapters

0:00 - Introduction
0:13 - CVE-2025-33053 Actively Exploited
0:45 - Office 365 Preview Pane Vulnerabilities
1:34 - Closing

Key Quotes

0:18 "This is the one CVE that Microsoft listed as exploit detected."
0:30 "... a .URL shortcut file that links to a WebDAV server and allows for code execution."
1:06 "... if your preview is turned on, the exploit has a chance to run immediately without any interaction from you."

Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Threat Intelligence
  • Email Security
  • Technical Deep Dive
  • Patch Tuesday
  • Microsoft Security Updates
  • CVE-2025-33053
  • WebDAV Exploitation
  • Office 365 Vulnerabilities
  • Preview Pane Attacks
  • Zero-Day Threats
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: June 2025 Patch Tuesday: Exploited WebDAV Flaw & Office Risks

              Upcoming Webinar Calendar

              • 06/10/2026
                11:00 AM
                06/10/2026
                Action1: Vulnerability Digest--Patch Tuesday & Other Updates
                https://www.truthinit.com/index.php/channel/1997/action1-vulnerability-digest-patch-tuesday-other-updates/
              • 06/10/2026
                02:00 PM
                06/10/2026
                Understanding the True Costs of DIY Data Classification vs. Buying Solutions
                https://www.truthinit.com/index.php/channel/1985/understanding-the-true-costs-of-diy-data-classification-vs-buying-solutions/
              • 06/23/2026
                10:00 AM
                06/23/2026
                Stay Informed on the Latest Keepit Partner Developments – June 23
                https://www.truthinit.com/index.php/channel/1990/stay-informed-on-the-latest-keepit-partner-developments-–-june-23/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/

              Upcoming Events

              • Jun
                10

                Action1: Vulnerability Digest--Patch Tuesday & Other Updates

                06/10/202611:00 AM ET
                • Jun
                  10

                  Understanding the True Costs of DIY Data Classification vs. Buying Solutions

                  06/10/202602:00 PM ET
                  • Jun
                    23

                    Stay Informed on the Latest Keepit Partner Developments – June 23

                    06/23/202610:00 AM ET
                    • Jun
                      25

                      Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                      06/25/202601:00 PM ET
                      More events
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version