MSRC Reports
61 subscribers
2.94K links
Microsoft Security Response Center Reports
(Unofficial).

Reports usually come in bursts, because that's just how Microsoft releases them.
Download Telegram
CVE-2025-0033 AMD CVE-2025-0033: RMP Corruption During SNP Initialization

Corrected security updates table. This is an informational change only.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-0033
CVE-2025-59227 Microsoft Office Remote Code Execution Vulnerability

Updated acknowledgment.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59227
CVE-2025-59233 Microsoft Excel Remote Code Execution Vulnerability

Updated acknowledgment. This is an informational change only.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59233
CVE-2025-50154 Microsoft Windows File Explorer Spoofing Vulnerability

Updated an acknowledgement. This is an informational change only.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-50154
CVE-2025-53784 Microsoft Word Remote Code Execution Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53784
CVE-2025-53740 Microsoft Office Remote Code Execution Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53740
CVE-2025-53739 Microsoft Excel Remote Code Execution Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53739
CVE-2025-53738 Microsoft Word Remote Code Execution Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53738
CVE-2025-53737 Microsoft Excel Remote Code Execution Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53737
CVE-2025-53736 Microsoft Word Information Disclosure Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53736
CVE-2025-53735 Microsoft Excel Remote Code Execution Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53735
CVE-2025-53733 Microsoft Word Remote Code Execution Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53733
CVE-2025-53731 Microsoft Office Remote Code Execution Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53731
CVE-2025-53761 Microsoft PowerPoint Remote Code Execution Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53761
CVE-2025-53760 Microsoft SharePoint Elevation of Privilege Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53760
CVE-2025-53759 Microsoft Excel Remote Code Execution Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53759
CVE-2025-53741 Microsoft Excel Remote Code Execution Vulnerability

Revised the packages to include Download Center ID for this vulnerability.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53741
Chromium: CVE-2025-11756 Use after free in Safe Browsing

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-11756
CVE-2025-55315 ASP.NET Security Feature Bypass Vulnerability

Added an FAQ to explain the disparity between the Important severity, the exploitability assessment of "less likely to be exploited", and the high CVSS3.1 score of 9.9 out of 10.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-55315
CVE-2025-40010 afs: Fix potential null pointer dereference in afs_put_server

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-40010
CVE-2025-40005 spi: cadence-quadspi: Implement refcount to handle unbind during busy

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-40005