HomeMicrosoft Patch Tuesday › June 2025

Microsoft Patch Tuesday, June 2025

·

Microsoft's June 2025 security release, published June 10, 2025: 47 updates fixing 64 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 1 CVE from this release is on the Senserva hot list today (as of 2026-09-18), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
47
Updates (KBs)
64
CVEs fixed
7
On the CISA KEV list
0
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2025-33053Internet Shortcut Files Remote Code Execution VulnerabilityCVSS 8.8Exploited
CVE-2025-33073Windows SMB Client Elevation of Privilege VulnerabilityCVSS 8.8Exploited Hot now
CVE-2025-30400Microsoft DWM Core Library Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-32701Windows Common Log File System Driver Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-32706Windows Common Log File System Driver Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-32709Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-30397Scripting Engine Memory Corruption VulnerabilityCVSS 7.5Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2025-33064Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-33066Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-29964Windows Media Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-29966Remote Desktop Client Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-29967Remote Desktop Client Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-29962Windows Media Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-29963Windows Media Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-47163Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-47166Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-47172Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8

Products fixed this month

Windows Server 2019 (14)Windows Server 2022 (10)Microsoft Office 2019 for 32-bit editions (9)Windows 10 Version 1809 for 32-bit Systems (7)Windows 10 Version 1809 for x64-based Systems (7)Windows Server 2019 (Server Core installation) (7)Microsoft SharePoint Enterprise Server 2016 (6)Microsoft SharePoint Server 2019 (6)Microsoft Office 2019 for 64-bit editions (6)Microsoft 365 Apps for Enterprise for 32-bit Systems (4)

Every update in this release

All 31 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5060525 ExploitedHigh8.839Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 11 Version 22H2 for ARM64-based SystemsSupport · Catalog
KB5060999 ExploitedHigh8.835Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 11 Version 22H2 for ARM64-based SystemsSupport · Catalog
KB5060841 ExploitedHigh8.839Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 11 Version 22H2 for ARM64-based SystemsSupport · Catalog
KB5060533 ExploitedHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5060998 ExploitedHigh8.830Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5061026 ExploitedHigh8.812Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5061078 ExploitedHigh8.814Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5060996 ExploitedHigh8.81Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5061072 ExploitedHigh8.811Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5061036 ExploitedHigh8.813Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5058497 ExploitedHigh8.842Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5058451 ExploitedHigh8.834Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5058403 ExploitedHigh8.834Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5058429 ExploitedHigh8.825Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5058430 ExploitedHigh8.829Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5058454 ExploitedHigh8.829Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5061198 ExploitedHigh8.13Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5002732High8.85Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002729High8.85Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002736High8.83Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002730High8.44Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002616High8.41Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002689High7.81Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002728High7.81Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5002735High7.81Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5002731High7.82Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft Office 2019 for 32-bit editionsSupport · Catalog
KB5002727High7.82Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft Office 2019 for 32-bit editionsSupport · Catalog
KB5002710High7.82Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft Office 2019 for 32-bit editionsSupport · Catalog
KB5061935High7.51PowerShell 7.4, PowerShell 7.5, .NET 8.0 installed on WindowsSupport · Catalog
KB5061936High7.51PowerShell 7.4, PowerShell 7.5, .NET 8.0 installed on WindowsSupport · Catalog
KB5002683Medium6.71Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
Take this release to your AI

Composed from the June 2025 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.