Full Report
Microsoft has released its monthly security update for June 2025, which includes 66 vulnerabilities affecting a range of products, including 10 that Microsoft marked as “critical.”
Analysis Summary
# Vulnerability: Microsoft June 2025 Patch Summary (RCEs, EoPs in Windows, Office, SharePoint)
## CVE Details
- CVE ID: Multiple (Including CVE-2025-32710, CVE-2025-29828, CVE-2025-33071, CVE-2025-47172, CVE-2025-47162, CVE-2025-47164, CVE-2025-47167, CVE-2025-47953, CVE-2025-33070, CVE-2025-47966, CVE-2025-32713, CVE-2025-32714, CVE-2025-47962)
- CVSS Score: Varies (Critical, Important). Critical Examples: CVE-2025-47966 (9.8), CVE-2025-47172 (8.8), CVE-2025-32710 (8.1), CVE-2025-33071 (8.1).
- CWE: Various; includes Use-After-Free, Heap-based Buffer Overflow, Type Confusion, Cryptographic Protocol Vulnerabilities.
## Affected Systems
- Products: Microsoft Windows (Services including Remote Desktop Services (RDS), Schannel, KDC Proxy Service, NetLogon), Microsoft Office, SharePoint Server, Windows Power Automate, Windows Common Log File System Driver, Windows Installer, Windows SDK.
- Versions: Not specified in detail, but applies to systems receiving the June 2025 security updates.
- Configurations: Specific configuration noted for CVE-2025-33071 (Windows servers configured as Kerberos KDC Proxy Protocol server; Domain controllers noted as *not* affected). CVE-2025-32710 affects systems with the Remote Desktop Gateway role. CVE-2025-47172 requires an authenticated attacker with at least Site Member permission on a SharePoint server.
## Vulnerability Description
Microsoft patched 66 vulnerabilities in June 2025, including 11 classified as "Critical."
**Key RCE Vulnerabilities include:**
* **CVE-2025-32710 (RDS):** A Use-After-Free vulnerability triggered by winning a race condition when connecting to an RDS Gateway server.
* **CVE-2025-29828 (Schannel):** RCE possible via malicious use of fragmented ClientHello messages due to a missing memory release in Windows Cryptographic Services.
* **CVE-2025-33071 (KDC Proxy Service):** RCE via a cryptographic protocol flaw in the Kerberos KDC Proxy Service using a specially crafted application.
* **CVE-2025-47172 (SharePoint):** SQL Command Injection flaw allowing an authenticated attacker (Site Member level minimum) to execute code remotely.
* **CVE-2025-47162, -47164, -47167, -47953 (Office):** Memory corruption flaws including heap-based buffer overflow, use-after-free, and type confusion.
**Key Elevation of Privilege (EoP) Vulnerabilities:**
* **CVE-2025-47966 (Power Automate):** Critical EoP exposing sensitive information over the network (though Microsoft states this is fully mitigated).
* **CVE-2025-33070 (Netlogon):** Authentication bypass using uninitialized resources leading potentially to Domain Administrator privileges.
## Exploitation
- Status: Microsoft reports that none of the disclosed vulnerabilities have been actively exploited in the wild as of the release date. PoCs or exploit code are not publicly detailed, but information on complexity suggests varied likelihood.
- Complexity: Varies significantly:
* Low complexity (More likely to be exploited): CVE-2025-47172 (SharePoint), CVE-2025-47162, -47164, -47167 (Office).
* High complexity (Less likely/More likely depending on CVE): CVE-2025-32710, CVE-2025-29828, CVE-2025-33071, CVE-2025-33070.
- Attack Vector: Mostly Network (RCEs) or Local (some EoPs).
## Impact
- Confidentiality: High potential, especially via RCEs and information disclosure (CVE-2025-47966).
- Integrity: High potential, especially via RCEs and EoPs leading to arbitrary code execution or privilege escalation.
- Availability: Potential impact due to code execution disrupting services, though specific availability impact is not detailed for all.
## Remediation
### Patches
- Apply the consolidated Microsoft June 2025 Security Updates for all affected products immediately. (Specific patch versions are not listed in the summary but are available via Microsoft Update Guide links).
### Workarounds
- **CVE-2025-47966 (Power Automate):** Microsoft states this vulnerability is **fully mitigated** and no further action is required by users.
- **CVE-2025-33071 (KDC Proxy):** Mitigation applies only to systems *not* configured as KDC Proxy servers. Disabling this role on non-domain controller servers mitigates this specific flaw.
## Detection
- Detection rules are available from Talos/Cisco:
* Snort Rules (Legacy): 55802, 56290, 65030-65043.
* Snort 3 Rules: 301220, 301250-301255.
- General detection relies on monitoring network connections attempting to exploit specific service handling (e.g., unusual ClientHello fragmentation for Schannel, or targeted connection attempts against RDS or SharePoint endpoints).
## References
- Vendor Advisory: Microsoft Security Update Guide for June 2025
- Talos/Cisco Security Advisory for rule updates.
- Specific CVE Links (Defanged):
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32710
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29828
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33071
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47172
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47162
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47164
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47167
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47953
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33070
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47966
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32713
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32714
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47962