Microsoft's September Patch Tuesday: Key Security Updates Included

10 Sep 2025

In its latest security update, Microsoft has released patches addressing 84 vulnerabilities, part of the September 2025 Patch Tuesday. Among the fixes are two zero-day vulnerabilities and eight marked as critical, with the remaining classified at varying levels of severity. The updates are crucial for reinforcing the security of Windows, Extended Security Updates, and Microsoft Office, which collectively earned significant patches this cycle.

Zero-Day Vulnerabilities in the Spotlight

Two zero-day vulnerabilities have been publicly disclosed but not actively exploited. The first, CVE-2025-55234, involves an elevation-of-privilege issue in the Windows SMB Server with a high CVSS score of 8.8. Without safeguards like SMB Server Signing or Extended Protection for Authentication, this flaw allows for potential relay attacks. Meanwhile, CVE-2024-21907 threatens systems through Newtonsoft.Json, creating a denial-of-service risk that disrupts applications by leveraging specifically crafted data.

Highlighting Critical Vulnerabilities

Critical vulnerabilities predominantly feature in Windows components and Microsoft Office. Notably, CVE-2025-54918 highlights an elevation-of-privilege weakness in NTLM, capable of elevating a user's privileges to SYSTEM remotely and with minimal complexity. CVE-2025-54910, targeting Microsoft Office, exposes systems to remote code execution attacks via heap-based buffer overflow, even when viewed through the Preview Pane.

Additional critical vulnerabilities such as CVE-2025-55228 and CVE-2025-53800 pertain to the Windows Graphics Component, allowing potential hypervisor escapes through privilege escalation or code execution. The new remote code execution flaw CVE-2025-49717 poses risks within Hyper-V, signalling attention to virtualized environments. Meanwhile, CVE-2025-53799, related to the Windows Imaging Component, highlights information disclosure risks, necessitating caution with unverified files.

Strategic Protection and Mitigation

Organizations must stay vigilant to unpatchable issues, building solid response plans to mitigate the vulnerabilities when immediate fixes aren't possible. Regular review and adaptation of patching strategies are essential for maintaining robust security frameworks. Vital to these endeavors is awareness of Microsoft's support timelines to ensure ongoing protection and timely upgrades. Utilizing tools like CrowdStrike’s Patch Tuesday dashboard can enhance operational understanding of system vulnerabilities and strengthen defenses.

The Common Vulnerability Scoring System (CVSS) remains a pivotal element in categorizing vulnerabilities by severity, assisting enterprises in appropriately prioritizing remediation measures. As businesses navigate the evolving threat landscape, these updates should be integrated into broader security initiatives to effectively protect infrastructures from emerging threats.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
5724003
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1030203
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
441139
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
372988
downloads

News and reviews for Desktop Windows

Epic Games Store Offers Free Games Including Ghostrunner 2

Epic Games Store is offering Free Games for a limited time, including Ghostrunner 2. These titles are available until 4pm BST on 18 September 2025, allowing players to explore diverse gaming experiences from a cyberpunk future to strategic tribal battles.

Read more

Strategic Tips for Conquering Beastfly in Pharloom

Learn effective strategies to tackle Beastfly in Pharloom with the right preparation and combat tactics for both the Hunter's March and Far Fields encounters.

Read more

Ghostrunner 2 Now Free on Epic Games Store for Limited Time

Ghostrunner 2, a fast-paced cyberpunk action game, is currently free on the Epic Games Store. Experience the enhanced combat, upgraded katana, and expansive new settings in this highly-rated sequel, available until September 18 alongside Monument Valley 2 and The Battle of Polytopia.

Read more

Microsoft Faces Scrutiny Over Security and Ransomware Threats

Sen. Wyden urges FTC probe into Microsoft's role in ransomware, citing inadequate cybersecurity. Wyden calls for stronger security measures for legacy encryptions like RC4.

Read more

Microsoft Releases Windows 11 25H2 ISOs for Testers

Microsoft has released ISO files for Windows 11 25H2, allowing testers a clean installation process before the update's full release. The update maintains core system components intact while offering significant internal improvements and is expected to be generally available in October.

Read more

Hell Let Loose Vietnam Offers Asymmetric Warfare Experience

Hell Let Loose Vietnam surprises with its setting shift. This sequel introduces asymmetric mechanics, offering unique strategies for players. Set during the Vietnam War, it promises an intense, immersive combat experience, expanding on the series' existing foundations ahead of its 2026 release.

Read more

Nano11 Launches: Minimizing Windows 11 Installation Size

NTDEV introduces Nano11, a PowerShell tool trimming Windows 11 ISOs, achieving up to 3.5 times size reduction. Designed for experimental use, it streamlines installations by removing non-essential components.

Read more

Helmets Now Available in Latest Space Marine 2 Update

Saber Interactive releases fan-favorite helmets in Space Marine 2, including the plain Mark 8, with patch 10.1, available in the store. The update also resolves gameplay bugs, enhancing the gaming experience.

Read more

Assassin's Creed Update Brings Key Enhancements for Gamers

Ubisoft's Assassin's Creed Shadows unveils major improvements including a new gear system, map enhancements, and a free story mission, enticing players to re-engage with the game.

Read more

Dragonwilds Update Delay Due to Technical Issues

Dragonwilds 0.9 update faces delay due to detected bugs. Originally set for September 9, release postponed for fixes. Features include new skill trees and controller overhaul. Expected this week, with 0.9.1 due late September.

Read more