Microsoft delivered a batch of security patches addressing at least 67 vulnerabilities spanning its Windows platforms and related software. The company flagged that attackers are already exploiting one of these flaws in the wild, while technical details for another significant Windows vulnerability have surfaced publicly.

This month's sole zero-day vulnerability is CVE-2025-33053, a remote code execution issue affecting the Windows implementation of WebDAV, an HTTP-based protocol for remote file and directory management on servers. Although WebDAV remains disabled by default on Windows systems, its continued presence in older deployments and specialized configurations keeps it relevant as an attack vector, according to Seth Hoyt, senior security engineer at Automox.

Adam Barnett, lead software engineer at Rapid7, noted that Microsoft's advisory omits a critical detail: the Windows WebDAV implementation has carried deprecated status since November 2023, meaning the WebClient service no longer activates automatically. The advisory also has attack complexity as low, which means that exploitation does not require preparation of the target environment in any way that is beyond the attacker's control, Barnett explained. Exploitation relies on the user clicking a malicious link. It's not clear how an asset would be immediately vulnerable if the service isn't running, but all versions of Windows receive a patch, including those released since the deprecation of WebClient, like Server 2025 and Windows 11 24H2.

Microsoft has cautioned that CVE-2025-33073, an elevation of privilege flaw in the Windows Server Message Block (SMB) client, faces probable exploitation due to publicly available proof-of-concept code. The vulnerability carries a CVSS severity rating of 8.8 out of 10, and successful exploitation grants attackers SYSTEM-level access to affected machines.

What makes this especially dangerous is that no further user interaction is required after the initial connection—something attackers can often trigger without the user realizing it, said Alex Vovk, co-founder and CEO of Action1. Given the high privilege level and ease of exploitation, this flaw poses a significant risk to Windows environments. The scope of affected systems is extensive, as SMB is a core Windows protocol used for file and printer sharing and inter-process communication.

Ten additional flaws received critical ratings from Microsoft this month, with eight classified as remote code execution vulnerabilities.

Conspicuously missing from this month's patch release is a remedy for BadSuccessor, a newly identified weakness in Windows Server 2025 that permits attackers to assume the privileges of any Active Directory user. Akamai researchers made the vulnerability public on May 21, and multiple working proof-of-concepts have since emerged. Satnam Narang from Tenable recommends that organizations operating at least one Windows Server 2025 domain controller audit and restrict permissions for Active Directory principals to the minimum necessary level.

Adobe released patches for Acrobat Reader and six additional products, resolving at least 259 vulnerabilities, with the majority concentrated in an Experience Manager update. Mozilla Firefox and Google Chrome both deployed recent security updates requiring browser restarts. Chrome's latest patch addresses two zero-day flaws: CVE-2025-5419 and CVE-2025-4664.

The SANS Internet Storm Center offers comprehensive analysis of Microsoft's individual patches, while Action1 provides breakdowns covering Microsoft and numerous other vendors releasing updates this cycle. As always, create system and data backups before applying patches, and report any installation difficulties in the comments.

Source: Krebs on Security