Microsoft released patches for 66 security flaws across Windows, including a highly exploitable WebDAV remote code execution bug. The vulnerability, linked to the APT group Stealth Falcon, affects all supported Windows versions and allows attackers to execute arbitrary code through browser-based attacks. #WebDAV #StealthFalcon
Keypoints
- Microsoft issued updates for 66 security vulnerabilities in the Windows ecosystem.
- The WebDAV remote code execution flaw (CVE-2025-33053) is actively exploited by threat actors.
- Exploit enables remote code execution through browser visits on compromised websites.
- The vulnerability is linked to the APT group Stealth Falcon, targeting Middle Eastern countries.
- Other critical patches include, and address, flaws in SharePoint, Office, and Windows Remote Desktop Services.
Read More: https://www.securityweek.com/microsoft-patch-tuesday-covers-webdav-flaw-marked-as-already-exploited/