Microsoft Patches 130 Vulnerabilities in July Update
July Patch Tuesday: Visual studio Updates & Kerberos Hardening
Table of Contents
JulyS Patch Tuesday brings critical security updates for Visual Studio and continues a phased rollout of enhanced Kerberos security measures. Administrators should prioritize these updates to mitigate vulnerabilities and strengthen network defenses against evolving threats.
Visual Studio Patches Address Git Vulnerabilities
Seven Common Vulnerabilities and Exposures (CVEs) impacting Visual Studio have been addressed with the latest updates. These vulnerabilities – CVE-2025-27613, CVE-2025-27614, CVE-2025-46334, CVE-2025-46835, CVE-2025-48384, CVE-2025-48385 and CVE-2025-48386 – are related to Git and require immediate attention from advancement teams and IT administrators.
The Importance of Third-Party Library Updates
Regular updates to third-party libraries within the development ecosystem are paramount to preventing “security debt,” according to security expert Goettl.Failing to maintain these components can lead to a gradual accumulation of vulnerabilities that attackers can exploit.
“Most development organizations, if they’re doing a good CI/CD pipeline assessment, are going to see vulnerabilities in the third-party libraries and development tools they’re using,” Goettl explained. Proactive vulnerability management is a cornerstone of a secure software development lifecycle.
Testing and Rollout Strategies for Developer Tools
The process for testing and deploying fixes for developer tools differs significantly from standard OS patching. Smaller organizations can often rely on regression testing after installing updated libraries to validate functionality. Though, larger enterprises typically employ a staged rollout, beginning with lower-risk environments before extending updates to critical systems.This careful approach is necessary because of the potential for disruption to ongoing development work. “It’s quiet a bit different then just an automated patch management process…There’s a bit more of a heavy lift to validate that everything is good,” goettl noted. Thorough validation minimizes the risk of introducing regressions or compatibility issues.
Kerberos Hardening: Moving to Enforcement Mode
Microsoft continues its multi-phase process to bolster Kerberos authentication security, aiming to prevent machine-in-the-middle (MITM) attacks and local network spoofing. July’s Patch Tuesday implemented the second phase of this hardening initiative.
Phase One: Audit Mode
The initial phase, introduced in April’s Patch Tuesday (CVE-2025-26647), focused on identifying noncompliant certificates within Windows Server systems. This was achieved through the introduction of Audit Mode, wich generated logs highlighting certificates that did not meet the new security standards. Administrators were tasked with reviewing these logs, correcting any identified issues, and ensuring overall system compliance.
Phase two: Enforced by Default
The July update transitions domain controllers to “Enforced by Default” mode. This phase mandates checks against the NTAuth store – the repository on Windows domain controllers containing trusted certificate authorities. While enforcement is now active, administrators retain the ability to temporarily revert to Audit Mode for necessary adjustments. This provides a grace period for resolving any remaining compatibility issues. More information on the NTAuth store can be found here.
Phase Three: Full Enforcement
The final stage, scheduled for the october Patch Tuesday release, will place domain controllers into full Enforcement Mode. At this point, the ability to bypass these security checks via registry modifications will be removed, solidifying the enhanced kerberos security posture. Administrators should use the intervening months to ensure full compliance and minimize potential disruptions.
