Transcript
and I'm here to talk to you about this month's Patch Tuesday. There's not a lot I'm going to talk about, there's just two things I want to touch on, so we'll just jump right into those. The first thing I want to talk to you about is CVE-2025-33053. This is the one CVE that Microsoft listed as exploit detected. There's a great blog post out there from Checkpoint if you want to check it out, with all the details on this vulnerability, but essentially what it is, is a .URL shortcut file that links to a WebDAV server and allows for code execution. So take a look at the blog post, make sure you're updated for this one, because it is seeing active exploitation. The other thing I want to touch on is the four Office updates, specifically Microsoft Office 365, that are all preview pane affected. I'm not going to list the CVEs, because there are a bunch of them, but they're all the Office ones. Whenever you see preview pane affected, that means that when you receive an email, if your preview is turned on, the exploit has a chance to run immediately without any interaction from you. One of the big things here is that the Microsoft 365 Office client specifically does not have updates available yet. So we'll have to wait for Microsoft to release those. Thankfully, there are no exploits at the moment for these, so the risk is relatively low, but something to keep in mind and keep an eye out for those updates when they do get released in the future. Once again, I'm Tyler Reguli, and this has been your June Patch Tuesday update. Thank you. Microsoft Mechanics www.microsoft.com