ΑρχικήUpdatesMicrosoft Patch Tuesday Σεπτεμβρίου 2025: Διορθώθηκαν 81 Ευπάθειες

Microsoft Patch Tuesday Σεπτεμβρίου 2025: Διορθώθηκαν 81 Ευπάθειες

Η Microsoft κυκλοφόρησε τις ενημερώσεις Patch Tuesday για τον Σεπτέμβριο του 2025, αντιμετωπίζοντας συνολικά 81 ευπάθειες ασφαλείας στο σύνολο των προϊόντων της. Οι ενημερώσεις ασφαλείας καλύπτουν διάφορα λογισμικά, συμπεριλαμβανομένων των Windows, Microsoft Office, Azure και SQL Server.

Microsoft Patch Tuesday Σεπτεμβρίου 2025

Μεταξύ των διορθώσεων περιλαμβάνονται 22 ευπάθειες που επιτρέπουν απομακρυσμένη εκτέλεση κώδικα (RCE), καθιστώντας αυτή την ενημέρωση σημαντική για τους διαχειριστές συστημάτων. Από τις 81 ευπάθειες, 8 αξιολογούνται ως Κρίσιμες, ενώ οι υπόλοιπες 73 κατατάσσονται ως Σημαντικές.

Οι ευπάθειες καλύπτουν διάφορες κατηγορίες, με την Απομακρυσμένη Εκτέλεση Κώδικα (RCE), την Ανύψωση Προνομίων (EoP) και την Αποκάλυψη Πληροφοριών να είναι οι πιο συχνοί τύποι στην έκδοση αυτού του μήνα.

Δείτε επίσης: Σφάλμα στο Adobe Commerce επιτρέπει κατάληψη λογαριασμών

Patch Tuesday: RCE ευπάθειες

Οι κρίσιμες ευπάθειες RCE θα μπορούσαν να επιτρέψουν σε επιτιθέμενους να εκτελέσουν αυθαίρετο κώδικα σε επηρεαζόμενα συστήματα. Μεταξύ των πιο σοβαρών είναι αυτές που βρέθηκαν στο Graphics Kernel (CVE-2025-55226, CVE-2025-55236) και το Windows Graphics Component (CVE-2025-55228).

Το Microsoft Office έλαβε, επίσης, μια κρίσιμη διόρθωση για μια ευπάθεια heap-based buffer overflow (CVE-2025-54910) που επιτρέπει την τοπική εκτέλεση κώδικα. Επιπλέον, διορθώθηκε μια κρίσιμη ευπάθεια RCE στο Windows Hyper-V (CVE-2025-55224). Αυτό το σφάλμα, που προκύπτει από ένα race condition, θα μπορούσε να επιτρέψει σε έναν τοπικό επιτιθέμενο να εκτελέσει αυθαίρετο κώδικα. Αυτοί οι τύποι ευπαθειών είναι ιδιαίτερα επικίνδυνοι καθώς συχνά μπορούν να χρησιμοποιηθούν για αρχική πρόσβαση ή lateral movement μέσα σε ένα δίκτυο.

Ανύψωση Προνομίων

Ένα σημαντικό μέρος της ενημέρωσης του Σεπτεμβρίου είναι αφιερωμένο στη διόρθωση ευπαθειών Ανύψωσης Προνομίων στο οικοσύστημα των Windows. Μια κρίσιμη ευπάθεια EoP στο Windows NTLM (CVE-2025-54918) θα μπορούσε να επιτρέψει σε έναν εξουσιοδοτημένο επιτιθέμενο να ανυψώσει τα προνόμιά του μέσω του δικτύου. Άλλες σημαντικές ευπάθειες EoP διορθώθηκαν στο PowerShell Direct (CVE-2025-49734), στο Windows Ancillary Function Driver for WinSock (CVE-2025-54099) και στο Windows Kernel (CVE-2025-54110).

Microsoft Patch Tuesday Σεπτεμβρίου 2025: Διορθώθηκαν 81 Ευπάθειες

Αποκάλυψη πληροφοριών

Η ενημέρωση αντιμετωπίζει επίσης πολυάριθμες ευπάθειες αποκάλυψης πληροφοριών, ιδιαίτερα στο Windows Routing and Remote Access Service (RRAS), με έξι διαφορετικά CVEs (CVE-2025-53797, CVE-2025-53798, CVE-2025-54095, CVE-2025-54096, CVE-2025-54097, CVE-2025-55225) που σχετίζονται με buffer over-read και out-of-bounds read issues. Αν και δεν είναι τόσο σοβαρές όσο οι RCE, αυτές οι ευπάθειες μπορούν να διαρρεύσουν ευαίσθητες πληροφορίες μνήμης που βοηθούν τους επιτιθέμενους να δημιουργήσουν πιο σύνθετες εκμεταλλεύσεις.

Δείτε επίσης: Κρίσιμες ευπάθειες στο Ivanti Endpoint Manager επιτρέπουν RCE

Microsoft Patch Tuesday: Άλλες διορθώσεις

Πέρα από το βασικό λειτουργικό σύστημα, η Microsoft έχει διορθώσει κρίσιμες και σημαντικές ευπάθειες στο λογισμικό της για επιχειρήσεις και παραγωγικότητα. Αντιμετωπίστηκε μια σημαντική ευπάθεια RCE στο Microsoft SharePoint (CVE-2025-54897), η οποία θα μπορούσε να χρησιμοποιηθεί από έναν εξουσιοδοτημένο επιτιθέμενο μέσω του δικτύου μέσω deserialization of untrusted data.

Το Microsoft Excel έλαβε μια σειρά διορθώσεων για επτά διαφορετικές ευπάθειες RCE (CVE-2025-54896, CVE-2025-54898, CVE-2025-54899, CVE-2025-54900, CVE-2025-54902, CVE-2025-54903, CVE-2025-54904). Αυτές οι ευπάθειες (κυρίως use-after-free and out-of-bounds read issues) επιτρέπουν σε έναν επιτιθέμενο να εκτελέσει κώδικα τοπικά αν ένας χρήστης ανοίξει ένα ειδικά διαμορφωμένο αρχείο.

Microsoft Patch Tuesday Σεπτεμβρίου 2025: Διορθώθηκαν 81 Ευπάθειες

Αρκετές ευπάθειες Ανύψωσης Προνομίων διορθώθηκαν επίσης στις υπηρεσίες Azure, συμπεριλαμβανομένων των Azure Arc (CVE-2025-55316) και του Azure Connected Machine Agent (CVE-2025-49692).

Η Microsoft καλεί όλους τους πελάτες να εφαρμόσουν άμεσα το Patch Tuesday Σεπτεμβρίου 2025 για να προστατεύσουν τα συστήματά τους από πιθανή εκμετάλλευση. Οι διαχειριστές θα πρέπει να δώσουν προτεραιότητα στη διόρθωση των κρίσιμων ευπαθειών RCE και Ανύψωσης Προνομίων για να μετριάσουν τους πιο σοβαρούς κινδύνους.

Δείτε επίσης: Η ευπάθεια SessionReaper απειλεί χιλιάδες ηλεκτρονικά καταστήματα

Από τις 81 ευπάθειες που αντιμετωπίστηκαν στην ενημέρωση της Microsoft, καμία δεν αναφέρθηκε ως zero-day.

TagCVE IDCVE TitleSeverity
Azure – NetworkingCVE-2025-54914Azure Networking Elevation of Privilege VulnerabilityCritical
Azure ArcCVE-2025-55316Azure Arc Elevation of Privilege VulnerabilityImportant
Azure Bot ServiceCVE-2025-55244Azure Bot Service Elevation of Privilege VulnerabilityCritical
Azure EntraCVE-2025-55241Azure Entra Elevation of Privilege VulnerabilityCritical
Azure Windows Virtual Machine AgentCVE-2025-49692Azure Connected Machine Agent Elevation of Privilege VulnerabilityImportant
Capability Access Management Service (camsvc)CVE-2025-54108Capability Access Management Service (camsvc) Elevation of Privilege VulnerabilityImportant
Dynamics 365 FastTrack Implementation AssetsCVE-2025-55238Dynamics 365 FastTrack Implementation Assets Information Disclosure VulnerabilityCritical
Graphics KernelCVE-2025-55236Graphics Kernel Remote Code Execution VulnerabilityCritical
Graphics KernelCVE-2025-55223DirectX Graphics Kernel Elevation of Privilege VulnerabilityImportant
Graphics KernelCVE-2025-55226Graphics Kernel Remote Code Execution VulnerabilityCritical
Microsoft AutoUpdate (MAU)CVE-2025-55317Microsoft AutoUpdate (MAU) Elevation of Privilege VulnerabilityImportant
Microsoft Brokering File SystemCVE-2025-54105Microsoft Brokering File System Elevation of Privilege VulnerabilityImportant
Microsoft Edge (Chromium-based)CVE-2025-9866Chromium: CVE-2025-9866 Inappropriate implementation in ExtensionsUnknown
Microsoft Edge (Chromium-based)CVE-2025-9867Chromium: CVE-2025-9867 Inappropriate implementation in DownloadsUnknown
Microsoft Edge (Chromium-based)CVE-2025-53791Microsoft Edge (Chromium-based) Security Feature Bypass VulnerabilityModerate
Microsoft Edge (Chromium-based)CVE-2025-9864Chromium: CVE-2025-9864 Use after free in V8Unknown
Microsoft Edge (Chromium-based)CVE-2025-9865Chromium: CVE-2025-9865 Inappropriate implementation in ToolbarUnknown
Microsoft Graphics ComponentCVE-2025-53807Windows Graphics Component Elevation of Privilege VulnerabilityImportant
Microsoft Graphics ComponentCVE-2025-53800Windows Graphics Component Elevation of Privilege VulnerabilityCritical
Microsoft High Performance Compute Pack (HPC)CVE-2025-55232Microsoft High Performance Compute (HPC) Pack Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2025-54910Microsoft Office Remote Code Execution VulnerabilityCritical
Microsoft OfficeCVE-2025-55243Microsoft OfficePlus Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2025-54906Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-54902Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-54899Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-54904Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-54903Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-54898Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-54896Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-54900Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-54901Microsoft Excel Information Disclosure VulnerabilityImportant
Microsoft Office PowerPointCVE-2025-54908Microsoft PowerPoint Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2025-54897Microsoft SharePoint Remote Code Execution VulnerabilityImportant
Microsoft Office VisioCVE-2025-54907Microsoft Office Visio Remote Code Execution VulnerabilityImportant
Microsoft Office WordCVE-2025-54905Microsoft Word Information Disclosure VulnerabilityImportant
Microsoft Virtual Hard DriveCVE-2025-54112Microsoft Virtual Hard Disk Elevation of Privilege VulnerabilityImportant
Role: Windows Hyper-VCVE-2025-54092Windows Hyper-V Elevation of Privilege VulnerabilityImportant
Role: Windows Hyper-VCVE-2025-54091Windows Hyper-V Elevation of Privilege VulnerabilityImportant
Role: Windows Hyper-VCVE-2025-54115Windows Hyper-V Elevation of Privilege VulnerabilityImportant
Role: Windows Hyper-VCVE-2025-54098Windows Hyper-V Elevation of Privilege VulnerabilityImportant
SQL ServerCVE-2025-47997Microsoft SQL Server Information Disclosure VulnerabilityImportant
SQL ServerCVE-2025-55227Microsoft SQL Server Elevation of Privilege VulnerabilityImportant
SQL ServerCVE-2024-21907VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.JsonUnknown
Windows Ancillary Function Driver for WinSockCVE-2025-54099Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows BitLockerCVE-2025-54911Windows BitLocker Elevation of Privilege VulnerabilityImportant
Windows BitLockerCVE-2025-54912Windows BitLocker Elevation of Privilege VulnerabilityImportant
Windows Bluetooth ServiceCVE-2025-53802Windows Bluetooth Service Elevation of Privilege VulnerabilityImportant
Windows Connected Devices Platform ServiceCVE-2025-54102Windows Connected Devices Platform Service Elevation of Privilege VulnerabilityImportant
Windows Connected Devices Platform ServiceCVE-2025-54114Windows Connected Devices Platform Service (Cdpsvc) Denial of Service VulnerabilityImportant
Windows Defender Firewall ServiceCVE-2025-53810Windows Defender Firewall Service Elevation of Privilege VulnerabilityImportant
Windows Defender Firewall ServiceCVE-2025-53808Windows Defender Firewall Service Elevation of Privilege VulnerabilityImportant
Windows Defender Firewall ServiceCVE-2025-54094Windows Defender Firewall Service Elevation of Privilege VulnerabilityImportant
Windows Defender Firewall ServiceCVE-2025-54915Windows Defender Firewall Service Elevation of Privilege VulnerabilityImportant
Windows Defender Firewall ServiceCVE-2025-54109Windows Defender Firewall Service Elevation of Privilege VulnerabilityImportant
Windows Defender Firewall ServiceCVE-2025-54104Windows Defender Firewall Service Elevation of Privilege VulnerabilityImportant
Windows DWMCVE-2025-53801Microsoft DWM Core Library Elevation of Privilege VulnerabilityImportant
Windows Imaging ComponentCVE-2025-53799Windows Imaging Component Information Disclosure VulnerabilityCritical
Windows Internet Information ServicesCVE-2025-53805HTTP.sys Denial of Service VulnerabilityImportant
Windows KernelCVE-2025-53803Windows Kernel Memory Information Disclosure VulnerabilityImportant
Windows KernelCVE-2025-53804Windows Kernel-Mode Driver Information Disclosure VulnerabilityImportant
Windows KernelCVE-2025-54110Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows Local Security Authority Subsystem Service (LSASS)CVE-2025-54894Local Security Authority Subsystem Service Elevation of Privilege VulnerabilityImportant
Windows Local Security Authority Subsystem Service (LSASS)CVE-2025-53809Local Security Authority Subsystem Service (LSASS) Denial of Service VulnerabilityImportant
Windows Management ServicesCVE-2025-54103Windows Management Service Elevation of Privilege VulnerabilityImportant
Windows MapUrlToZoneCVE-2025-54107MapUrlToZone Security Feature Bypass VulnerabilityImportant
Windows MapUrlToZoneCVE-2025-54917MapUrlToZone Security Feature Bypass VulnerabilityImportant
Windows MultiPoint ServicesCVE-2025-54116Windows MultiPoint Services Elevation of Privilege VulnerabilityImportant
Windows NTFSCVE-2025-54916Windows NTFS Remote Code Execution VulnerabilityImportant
Windows NTLMCVE-2025-54918Windows NTLM Elevation of Privilege VulnerabilityCritical
Windows PowerShellCVE-2025-49734PowerShell Direct Elevation of Privilege VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-54095Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-54096Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-53797Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-53796Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-54106Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-54097Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-53798Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-54113Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-55225Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-53806Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityImportant
Windows SMBCVE-2025-55234Windows SMB Elevation of Privilege VulnerabilityImportant
Windows SMBv3 ClientCVE-2025-54101Windows SMB Client Remote Code Execution VulnerabilityImportant
Windows SPNEGO Extended NegotiationCVE-2025-54895SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege VulnerabilityImportant
Windows TCP/IPCVE-2025-54093Windows TCP/IP Driver Elevation of Privilege VulnerabilityImportant
Windows UI XAML Maps MapControlSettingsCVE-2025-54913Windows UI XAML Maps MapControlSettings Elevation of Privilege VulnerabilityImportant
Windows UI XAML Phone DatePickerFlyoutCVE-2025-54111Windows UI XAML Phone DatePickerFlyout Elevation of Privilege VulnerabilityImportant
Windows Win32K – GRFXCVE-2025-55224Windows Hyper-V Remote Code Execution VulnerabilityCritical
Windows Win32K – GRFXCVE-2025-55228Windows Graphics Component Remote Code Execution VulnerabilityCritical
Windows Win32K – GRFXCVE-2025-54919Windows Graphics Component Remote Code Execution VulnerabilityImportant
XboxCVE-2025-55242Xbox Certification Bug Copilot Djando Information Disclosure VulnerabilityCritical
XBox Gaming ServicesCVE-2025-55245Xbox Gaming Services Elevation of Privilege VulnerabilityImportant
📧
Εγγραφείτε στο Newsletter του SecNews

Τα σημαντικότερα νέα Ασφάλειας & Τεχνολογίας στο Inbox σας.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

ΑΝΑΖΗΤΗΣΗ

FOLLOW US

📧
Newsletter SecNews
Τα σημαντικότερα νέα Ασφάλειας & Τεχνολογίας στο inbox σας.

LIVE NEWS