Microsoft Patch Tuesday Covers WebDAV Flaw Marked as ‘Already Exploited’

Microsoft Patch Tuesday Covers WebDAV Flaw Marked as ‘Already Exploited’

Microsoft released patches for 66 security flaws across Windows, including a highly exploitable WebDAV remote code execution bug. The vulnerability, linked to the APT group Stealth Falcon, affects all supported Windows versions and allows attackers to execute arbitrary code through browser-based attacks. #WebDAV #StealthFalcon

Keypoints

  • Microsoft issued updates for 66 security vulnerabilities in the Windows ecosystem.
  • The WebDAV remote code execution flaw (CVE-2025-33053) is actively exploited by threat actors.
  • Exploit enables remote code execution through browser visits on compromised websites.
  • The vulnerability is linked to the APT group Stealth Falcon, targeting Middle Eastern countries.
  • Other critical patches include, and address, flaws in SharePoint, Office, and Windows Remote Desktop Services.

Read More: https://www.securityweek.com/microsoft-patch-tuesday-covers-webdav-flaw-marked-as-already-exploited/