MSRC Reports
58 subscribers
2.57K links
Microsoft Security Response Center Reports
(Unofficial).

Reports usually come in bursts, because that's just how Microsoft releases them.
Download Telegram
CVE-2025-61661 Grub2: grub2: out-of-bounds write via malicious usb device

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-61661
CVE-2025-61663 Grub2: missing unregister call for normal commands may lead to use-after-free

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-61663
CVE-2025-61662 Grub2: missing unregister call for gettext command may lead to use-after-free

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-61662
CVE-2025-38387 RDMA/mlx5: Initialize obj_event->obj_sub_list before xa_insert

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-38387
CVE-2025-38389 drm/i915/gt: Fix timeline left held on VMA alloc error

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-38389
CVE-2025-38386 ACPICA: Refuse to evaluate a method if arguments are missing

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-38386
CVE-2025-38384 mtd: spinand: fix memory leak of ECC engine conf

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-38384
CVE-2025-62560 Microsoft Excel Remote Code Execution Vulnerability

Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62560
CVE-2025-62559 Microsoft Word Remote Code Execution Vulnerability

Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62559
CVE-2025-62558 Microsoft Word Remote Code Execution Vulnerability

Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62558
CVE-2025-62557 Microsoft Office Remote Code Execution Vulnerability

Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62557
CVE-2025-62556 Microsoft Excel Remote Code Execution Vulnerability

Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62556
CVE-2025-62555 Microsoft Word Remote Code Execution Vulnerability

Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62555
CVE-2025-62554 Microsoft Office Remote Code Execution Vulnerability

Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62554
CVE-2025-62564 Microsoft Excel Remote Code Execution Vulnerability

Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62564
CVE-2025-62562 Microsoft Outlook Remote Code Execution Vulnerability

Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62562
CVE-2025-62561 Microsoft Excel Remote Code Execution Vulnerability

Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62561
CVE-2025-2296 Un-verified kernel bypass Secure Boot mechanism in direct boot mode

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-2296
CVE-2025-68258 comedi: multiq3: sanitize config options in multiq3_attach()

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-68258
CVE-2025-68188 tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check()

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-68188
CVE-2025-68217 Input: pegasus-notetaker - fix potential out-of-bounds access

Information published.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-68217