Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

June 2025 Patch Tuesday: Exploited WebDAV Flaw & Office Risks

Fortra
05/12/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


and I'm here to talk to you about this month's Patch Tuesday. There's not a lot I'm going to talk about, there's just two things I want to touch on, so we'll just jump right into those. The first thing I want to talk to you about is CVE-2025-33053. This is the one CVE that Microsoft listed as exploit detected. There's a great blog post out there from Checkpoint if you want to check it out, with all the details on this vulnerability, but essentially what it is, is a .URL shortcut file that links to a WebDAV server and allows for code execution. So take a look at the blog post, make sure you're updated for this one, because it is seeing active exploitation. The other thing I want to touch on is the four Office updates, specifically Microsoft Office 365, that are all preview pane affected. I'm not going to list the CVEs, because there are a bunch of them, but they're all the Office ones. Whenever you see preview pane affected, that means that when you receive an email, if your preview is turned on, the exploit has a chance to run immediately without any interaction from you. One of the big things here is that the Microsoft 365 Office client specifically does not have updates available yet. So we'll have to wait for Microsoft to release those. Thankfully, there are no exploits at the moment for these, so the risk is relatively low, but something to keep in mind and keep an eye out for those updates when they do get released in the future. Once again, I'm Tyler Reguli, and this has been your June Patch Tuesday update. Thank you. Microsoft Mechanics www.microsoft.com

TL;DR

  • CVE-2025-33053 is actively exploited in the wild, involving malicious .URL shortcut files that link to WebDAV servers to achieve code execution—immediate patching is critical.
  • Four Microsoft Office 365 vulnerabilities are preview pane-affected, meaning exploits could trigger automatically when emails are opened without any user interaction required.
  • Microsoft 365 Office client patches are not yet available for the preview pane vulnerabilities, though no active exploits currently exist, creating a window of exposure to monitor.

Summary

Tyler Reguly, Associate Director of Security R&D at Fortra, provides a focused analysis of June 2025's Microsoft Patch Tuesday, highlighting two critical areas requiring immediate attention from security teams. The briefing covers an actively exploited vulnerability involving .URL shortcut files and WebDAV servers (CVE-2025-33053), which has been documented by Checkpoint researchers and requires urgent patching. Additionally, Reguly addresses four Microsoft Office 365 vulnerabilities that are preview pane-affected, meaning they could execute without user interaction when emails are opened. Notably, patches for the Microsoft 365 Office client are not yet available, creating a temporary exposure window that defenders should monitor. This concise update helps security practitioners prioritize their patching efforts for the month and understand the specific risks associated with each vulnerability class.

Chapters

0:00 - Introduction
0:13 - CVE-2025-33053 Actively Exploited
0:45 - Office 365 Preview Pane Vulnerabilities
1:34 - Closing

Key Quotes

0:18 "This is the one CVE that Microsoft listed as exploit detected."
0:30 "... a .URL shortcut file that links to a WebDAV server and allows for code execution."
1:06 "... if your preview is turned on, the exploit has a chance to run immediately without any interaction from you."

Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Threat Intelligence
  • Email Security
  • Technical Deep Dive
  • Patch Tuesday
  • Microsoft Security Updates
  • CVE-2025-33053
  • WebDAV Exploitation
  • Office 365 Vulnerabilities
  • Preview Pane Attacks
  • Zero-Day Threats
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: June 2025 Patch Tuesday: Exploited WebDAV Flaw & Office Risks

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    13

                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                    08/13/202612:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Becoming Agent Ready with Cyera: Essential Strategies and Insights
                      https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/03/2026
                      01:00 PM
                      09/03/2026
                      Verge.io: Can You Afford Your Next Storage Refresh?
                      https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version