BETABOX Technologiescybersecurity

Critical Vulnerabilities in the Second Quarter of 2025

Critical vulnerabilities in the second quarter of 2025: discover the most dangerous flaws and what they mean for your organization's security.

Critical vulnerabilities in the second quarter of 2025

Digital security remains a key topic in 2025. During the second quarter, thousands of new vulnerabilities were recorded that affected operating systems, applications and devices. This article summarizes the most important findings, with updated data and practical advice on how to protect yourself.

What are vulnerabilities and exploits?

Vulnerabilities are flaws in software that can be taken advantage of by attackers. When they are exploited, they make it possible to access systems, steal information or cause damage. Exploits are tools that take advantage of those flaws in order to carry out malicious actions.

Rise in vulnerabilities in 2025

More flaws every month

During the first six months of 2025, there was a steady increase in the number of vulnerabilities. In January, the figure exceeded 4,000, far higher than in previous years. This growth reflects both technological progress and the interest attackers have in finding new weaknesses.

Critical vulnerabilities on the rise

Vulnerabilities rated critical (CVSS > 8.9) also grew. Although not all of them receive this rating, many have detailed descriptions that help improve software security.

Line chart showing the monthly evolution of vulnerabilities detected between 2021 and 2025, with five colored lines representing each year.

Total number of critical vulnerabilities published each month, 2021–2025

Main exploited vulnerabilities

Windows under attack

Microsoft Office products were the most attacked. The most widely used vulnerabilities were:

  • CVE-2018-0802: allows code to be executed remotely.
  • CVE-2017-11882: affects the Equation Editor.
  • CVE-2017-0199: allows an attacker to take control of the system.

Attacks on WinRAR and on the Windows indexing system were also detected, with the goal of stealing credentials.

Bar chart showing the percentage of quarterly increase in vulnerabilities detected between Q1 2024 and Q2 2025.

Percentage of Windows users affected by exploits between the first quarter of 2024 and the second quarter of 2025, using 100% in the first quarter of 2024 as the reference.

Linux is vulnerable too

Linux was not far behind. The most exploited flaws were:

  • Dirty Pipe (CVE-2022-0847): allows privilege escalation.
  • CVE-2019-13272: manipulates inherited privileges.
  • CVE-2021-22555: affects the Netfilter kernel.

These attacks show that Linux is in the sights of criminals, especially because of its growing use in devices.

Bar chart showing the percentage of quarterly increase in vulnerabilities detected between Q1 2024 and Q2 2025.

Percentage of Linux users affected by exploits between the first quarter of 2024 and the second quarter of 2025, using 100% in the first quarter of 2024 as the reference.

Most widespread exploits

Operating systems in the crosshairs

Exploits for operating systems were the most common. Although no new attacks against Microsoft Office were published this quarter, Windows and Linux systems remain the main targets.

APT attacks and key vulnerabilities

What are APT attacks?

APT attacks (Advanced Persistent Threats) are carried out by organized groups. They seek prolonged access to systems in order to steal information or cause damage.

The 10 most used vulnerabilities

Among those most exploited by APT groups are:

  • CVE-2025-31324: affects SAP NetWeaver.
  • CVE-2024-1709: critical vulnerability in ConnectWise.
  • CVE-2024-31839 and CVE-2024-30850: flaws in the CHAOS tool.
  • CVE-2025-33053: allows code to be executed in Windows.

These vulnerabilities were used to gain initial access and to control systems.

C2 frameworks in real attacks

What are C2 frameworks?

They are tools that let attackers keep control over compromised systems. The most used in 2025 were:

  • Sliver
  • Metasploit
  • Havoc
  • Brute Ratel C4

Some allow commands to be run, others require additional configuration. Attackers customize them to avoid being detected.

Bar chart showing the percentage of use of different attack tools in the Q1 and Q2 quarters, with green bars for Q1 and red bars for Q2.

Ranking of the 13 C2 frameworks most used by APT groups in attacks during the first half of 2025

Notable vulnerabilities of the quarter

Flaws that drew attention

Among the most interesting vulnerabilities are:

  • CVE-2025-32433: allows commands to be run on SSH servers without authentication.
  • CVE-2025-6218: directory traversal in WinRAR.
  • CVE-2025-3052: insecure data access in UEFI.
  • CVE-2025-49113: insecure deserialization in Roundcube Webmail.
  • CVE-2025-1533: stack overflow in the AsIO3.sys driver.

These flaws show how attackers take advantage of simple errors to compromise systems.

Recommendations for protecting yourself

Constant updates

Installing security patches is key. Updates fix known flaws and keep exploits from working.

System monitoring

It is important to watch how devices behave. Detecting suspicious activity in time can prevent greater damage.

Workstation protection

Using reliable solutions to block malicious software is essential. Tools such as Kaspersky Next offer comprehensive protection for companies of every size.

The second quarter of 2025 made it clear that digital security must be a priority. With thousands of new vulnerabilities and increasingly sophisticated attacks, protecting systems is more important than ever. Updating software, monitoring devices and using security tools are fundamental steps to stay safe.

Related articles

Contact

Request a complimentary assessment

Tell us what your company needs and a BETABOX advisor will get in touch to schedule a call at your convenience. The initial assessment is 100% free of charge.