Microsoft Patch Tuesday
This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.
Scope
Microsoft only, non-Microsoft, or both. Everything below follows the choice.
Why the two halves are ranked separately
This month's Microsoft Security Update Guide release. CVEs Microsoft republishes from third parties are excluded by default.
Release scope
Off by default: Microsoft's feed republishes CVEs it did not author (the Chromium engine behind Edge, Azure Linux package rebuilds). Rapid7 and Tenable exclude most of these from their own counts, so EVULNABLE does too unless you turn this on.
Methodology: why this count may differ from other vendors
Microsoft's feed for this release contains 1,640 total records: 448 are Microsoft-authored Patch Tuesday CVEs, and 1,192 are CVEs Microsoft republishes from third parties it ships or packages — the Chromium engine behind Microsoft Edge, and Azure Linux open-source package rebuilds, being the two largest categories. Rapid7 and Tenable report smaller headline counts for the same release because they apply their own (not fully published) methodology to exclude most of these. EVULNABLE's Microsoft-only figure is intended to land in the same ballpark, not to match exactly. All counts on this page reflect the scope selected above.
At a glance — Microsoft
- 448 Microsoft-authored CVEs In EVULNABLE's scope for this release. Other vendors publish different totals — why counts differ.
- 84 Critical Microsoft's own severity rating, not CVSS
- 1 Actively Exploited Confirmed exploitation in the wild, per Microsoft and CISA
- 1 CISA KEV Also listed in CISA's Known Exploited Vulnerabilities catalog
- 3 Publicly Disclosed Pre-Patch Details were public before the fix shipped
1 CVE(s) are already being exploited in the wild, 1 are CISA KEV-listed, and 3 were publicly disclosed before this patch shipped — prioritize these regardless of severity.
Patch First
Ranked by EVULNABLE Risk Score v1.1 — CVSS, FIRST EPSS, CISA KEV, confirmed active exploitation, pre-patch public disclosure, and Microsoft's Exploitability Index. Known active exploitation is floored regardless of CVSS alone.
Windows User Profile Service Elevation of Privilege Vulnerability
Microsoft Defender Elevation of Privilege Vulnerability
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability
Windows DHCP Server Remote Code Execution Vulnerability
Release Dashboard
CVEs by Severity (EVULNABLE Risk)
Severity · CVEs
Select a bar to filter the CVE browser below to that severity.
Top 10 CVEs by EVULNABLE Risk
CVE · EVRS Score
Select a bar to open that CVE in the browser below.
CVEs by Impact Type
Impact type · CVEs
1 CVE(s) have no impact classification stated by Microsoft and are excluded from this chart so they don't crowd out the categories that are known.
Top Affected Products
Product · CVEs
Hardware-architecture and Server Core installation variants of the same product are grouped into one bar. Distinct OS versions and Office LTSC years are kept separate, since they matter for what still needs to be patched.
Why do the Microsoft and EVULNABLE Risk severity views look so different?
Microsoft's severity rating (Critical / Important / Moderate / Low) is a technical-impact call: how bad this vulnerability could be if exploited, independent of whether anyone is actually exploiting it — which is why most CVEs in a typical release land in Critical or Important.
EVULNABLE Risk asks a different question: how urgently should this actually be remediated right now? It weights real-world exploitation signals — CISA KEV listing, confirmed active exploitation, FIRST EPSS, and pre-patch public disclosure — far more heavily than CVSS. Since most CVEs in any release are not yet known-exploited, most score Low or Informational under EVRS even when Microsoft calls them Critical. That is the point of a separate score, not a bug.
Any CVE that is CISA KEV-listed or confirmed actively exploited is floored regardless of the weighted total, so it can never get buried. A CVE that is KEV-listed and confirmed exploited and scores CVSS ≥ 9.0 — with a real urgency signal behind it — carries the Exigent flag and is escalated within Critical.
| Band | Score |
|---|---|
| Immediate | 85-100 |
| Urgent | 65-84 |
| Elevated | 10-64 |
| Routine | 4-9 |
| Informational | 0-3 |