Microsoft once again had a lot of work to do on August's monthly Patch Tuesday, closing nearly 120 security vulnerabilities. Two of these vulnerabilities proved particularly dangerous: CVE-2025-53766 and CVE-2025-50165. Each received a CVSS score of 9.8, giving it a high severity rating. They affect the Microsoft Graphics Component (CVE-2025-50165) and Windows GDI+ (CVE-2025-53766) and could allow unauthorized code execution over the network. CVE-2025-50165 applies only to Windows 11 24H2 and Windows Server 2025, while CVE-2025-53766 affects Windows 10 and Windows 11, as well as all Windows Server variants since 2008.
However, despite the severity and low attack complexity of both vulnerabilities, Microsoft considers exploitation of these two vulnerabilities unlikely. The Redmond-based company did not provide any further information to support this conclusion. At least in both cases, there's still no evidence of active exploitation.
As always, it's still worth quickly installing Microsoft updates. The Redmond-based company closed a total of 119 security vulnerabilities across various products in August. A list can be found in the release notes.