While there was only one zero-day in this Patch Tuesday, Microsoft fixed numerous, critical remote code execution flaws in Microsoft Office that can be exploited simply by opening a specially crafted document or when viewed through the preview pane. Today is Microsoft's July 2025 Patch Tuesday, which includes security updates for 137 flaws, including one publicly disclosed zero-day vulnerability in Microsoft SQL Server. This month's Patch Tuesday fixes one publicly disclosed zero-day in Microsoft SQL Server. Microsoft fixes a flaw in Microsoft SQL Server that could allow a remote, unauthenticated attacker to access data from uninitialized memory. This Patch Tuesday also fixes fourteen "Critical" vulnerabilities, ten of which are remote code execution vulnerabilities, one is an information disclosure, and two are AMD side channel attack flaws. Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available. Microsoft states that the security updates for these flaws are not yet available for Microsoft Office LTSC for Mac 2021 and 2024 and will be released shortly. The company also fixed another critical RCE in Microsoft SharePoint tracked as CVE-2025-49704 that can be exploited remotely over the Internet as long as they have an account on the platform. "Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network," explains Microsoft. Admins can fix the flaw by installing the latest version of Microsoft SQL Server and by installing the Microsoft OLE DB Driver 18 or 19. Microsoft attributes the discovery of this flaw to Vladimir Aleksic with Microsoft and does not provide details regarding how it was publicly disclosed.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Tue, 08 Jul 2025 17:35:13 +0000