HomeMicrosoft Patch Tuesday › June 2025

Microsoft Patch Tuesday, June 2025

·

Microsoft's June 2025 security release, published June 10, 2025: 47 updates fixing 59 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 1 CVE from this release is on the Senserva hot list today (as of 2026-08-30), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
47
Updates (KBs)
59
CVEs fixed
7
On the CISA KEV list
0
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2025-33053Internet Shortcut Files Remote Code Execution VulnerabilityCVSS 8.8Exploited
CVE-2025-33073Windows SMB Client Elevation of Privilege VulnerabilityCVSS 8.8Exploited Hot now
CVE-2025-30400Microsoft DWM Core Library Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-32701Windows Common Log File System Driver Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-32706Windows Common Log File System Driver Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-32709Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-30397Scripting Engine Memory Corruption VulnerabilityCVSS 7.5Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2025-33064Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-33066Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-29964Windows Media Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-29966Remote Desktop Client Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-29967Remote Desktop Client Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-29962Windows Media Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-29963Windows Media Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-47163Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-47166Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-47172Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8

Products fixed this month

Windows Server 2019 (14)Windows Server 2022 (10)Microsoft Office 2019 for 32-bit editions (9)Windows 10 Version 1809 for 32-bit Systems (7)Windows 10 Version 1809 for x64-based Systems (7)Windows Server 2019 (Server Core installation) (7)Microsoft SharePoint Enterprise Server 2016 (6)Microsoft SharePoint Server 2019 (6)Microsoft Office 2019 for 64-bit editions (6)Microsoft 365 Apps for Enterprise for 32-bit Systems (4)

Every update in this release

All 31 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5060525 ExploitedHigh8.839Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 11 Version 22H2 for ARM64-based SystemsSupport · Catalog
KB5060999 ExploitedHigh8.835Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 11 Version 22H2 for ARM64-based SystemsSupport · Catalog
KB5060841 ExploitedHigh8.839Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 11 Version 22H2 for ARM64-based SystemsSupport · Catalog
KB5060533 ExploitedHigh8.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5060998 ExploitedHigh8.830Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5061026 ExploitedHigh8.812Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5061078 ExploitedHigh8.814Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5060996 ExploitedHigh8.81Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5061072 ExploitedHigh8.811Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5061036 ExploitedHigh8.813Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5058497 ExploitedHigh8.842Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5058451 ExploitedHigh8.834Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5058403 ExploitedHigh8.834Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5058429 ExploitedHigh8.825Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5058430 ExploitedHigh8.829Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5058454 ExploitedHigh8.829Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5061198 ExploitedHigh8.13Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5002732High8.85Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002729High8.85Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002736High8.83Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002730High8.44Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002616High8.41Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002689High7.81Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002728High7.81Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5002735High7.81Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5002731High7.82Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft Office 2019 for 32-bit editionsSupport · Catalog
KB5002727High7.82Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft Office 2019 for 32-bit editionsSupport · Catalog
KB5002710High7.82Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft Office 2019 for 32-bit editionsSupport · Catalog
KB5061935High7.51PowerShell 7.4, PowerShell 7.5, .NET 8.0 installed on WindowsSupport · Catalog
KB5061936High7.51PowerShell 7.4, PowerShell 7.5, .NET 8.0 installed on WindowsSupport · Catalog
KB5002683Medium6.71Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
Take this release to your AI

Composed from the June 2025 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see the same thing in your own tenant.

Siemserva by Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and returns every missing update ranked by what is actually being exploited, alongside all 650+ configuration checks.

1Find it2Fix it3Prove it
Start my free auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.