
Microsoft has launched fixes for the 137 safety flaws, together with one Zero-Day vulnerability and 14 essential flaws for Home windows, as a part of its July 2025 Patch Tuesday launch. Out of the 14 essential flaws, the corporate recognized and stuck 10 distant code execution flaws, one info disclosure challenge, and two AMD aspect channel assault flaws. In its June 2025 Patch Tuesday Launch, the US-based tech large had mounted 67 safety flaws, together with two Zero-Day vulnerabilities.
Microsoft Fixes Zero-Day Flaw within the SQL Server
Microsoft, within the release notes, revealed that the corporate July 2025 safety replace fixes 137 Home windows safety vulnerabilities. This included one publicly disclosed Zero-Day flaw that impacts the SQL Server. The corporate acknowledged, “Improper enter validation in SQL Server permits an unauthorised attacker to reveal info over a community.”
In line with Microsoft’s website, zero-day vulnerabilites are software program flaws that do not have any official patch or replace but. Most instances, even the software program writer has no concept that the vulnerability exists. Such flaws are often exploited by dangerous actors and are extremely extreme.
The tech large mentioned that the vulnerabilities have been found by Vladimir Aleksic with Microsoft. Nonetheless, the corporate didn’t disclose particulars concerning how the Zero-Day vulnerability turned publicly recognized.
Microsoft additionally mounted 14 essential vulnerabilities, together with 10 distant code execution flaws, one info disclosure flaw, and two AMD aspect channel assault vulnerabilities. In its July 2025 Patch Tuesday replace Microsoft additionally patched 53 elevation of privilege vulnerabilities, eight safety function bypass vulnerabilities, 41 distant code execution vulnerabilities, 18 info disclosure vulnerabilities, six denial of service vulnerabilities, and 4 spoofing flaws.
For context, in its June 2025 Patch Tuesday replace, Microsoft rolled out fixes for 67 safety flaws that affected varied services and products. The US-based firm mounted 14 vulnerabilities that would have led to an escalation of privilege, 26 distant code execution vulnerabilities, and 17 different points that would have led to info disclosure.