A back-to-work release aimed squarely at identity and the browser.
September's release is smaller than August's but lands in the places attackers actually go first: sign-in, the browser and the print stack. Most organisations can deploy it inside a normal maintenance window, provided identity servers are sequenced properly.
- Risk theme: Kerberos and Active Directory certificate handling
- Risk theme: Chromium-based Edge and WebView2 flaws
- Risk theme: Windows print and spooler components
- Risk theme: Microsoft 365 Apps document handling
The issues that move the needle this month.
We have focused on the categories with realistic exploitation paths for UK SMEs and regulated firms. Always cross-check with Microsoft's Security Update Guide and your own asset inventory before deployment.
Kerberos and certificate-based authentication weaknesses
Fixes in the Kerberos and certificate validation path address cases where an attacker who already has a low-privileged account could request or misuse a certificate to act as another user. In a single-forest SME domain this is the difference between a nuisance and a domain-wide incident.
Edge and WebView2 remote code execution
Several browser-engine flaws could be triggered by a malicious page. WebView2 matters more than people expect — it sits inside Teams, Outlook and a long list of line-of-business applications, so the browser fix is not just for people who browse.
Print spooler elevation of privilege
The spooler is back again. A local user, or malware running as that user, could raise privileges on the machine. Print servers in shared offices and clinical settings are the ones to look at first.
Office document and preview-pane issues
Parsing flaws in Word and Excel content can be reached through the preview pane, so a user does not have to consciously open anything. Standard phishing fare, and quick to weaponise.
Where the risk lives.
- — Windows 10, 11 and Server (2016–2025)
- — Active Directory domain controllers and AD CS
- — Microsoft Edge, WebView2 and applications that embed it
- — Microsoft 365 Apps, Word and Excel
- — Windows print servers and shared print queues
What to watch for when rolling out.
- Some domain controllers logged a burst of Kerberos warning events for a few hours after patching while tickets were reissued; the noise settled on its own.
- A handful of older multifunction devices needed their print drivers reinstalled after the spooler fix.
- WebView2-based line-of-business apps needed a full application restart, not just a browser restart, before the fix took effect.
- Excel add-ins from smaller vendors required an update before macros ran normally again.
- Closes an identity path that leads directly to domain compromise if left open.
- Fixes browser-engine flaws that reach far beyond the browser itself.
- Removes another local privilege-escalation route through print services.
- Small enough that most estates can complete it in one maintenance window.
- Domain controllers need reboots, and that always needs planning around out-of-hours work.
- Print driver fallout is common on older hardware and tends to surface first thing the next morning.
- Add-in breakage in Excel affects the finance teams who least appreciate surprises.
How experienced teams roll these out without drama.
- Patch domain controllers one at a time and confirm replication and sign-in health before moving to the next.
- Check AD CS templates for anything allowing requester-supplied subject names while you are in there — this month is a good prompt to review it.
- Restart WebView2-hosting applications explicitly; users will otherwise stay unpatched for days.
- Pilot the print fix on one shared queue and one direct-attached device before touching the print server.
- Give finance a short pilot window before the Office update reaches them broadly.
Advice, guidance, or full remediation — your call.
Whether you want a second pair of eyes on this month's release or you would rather hand the entire patching cycle to us, Secure Chain Technology Group can support at any level of involvement.
- Advisory: a prioritised briefing mapped to your estate and risk appetite, with recommended rollout rings.
- Guided deployment: we work alongside your IT team — test plans, rollback procedures and change-management evidence.
- Fully managed remediation: we deploy, validate and report on every patch through our Vulnerability Management-as-a-Service (VMaaS) and Patch Management services.
- Compliance evidence: reporting aligned to Cyber Essentials Plus, ISO 27001 and DSPT requirements.
Always verify against the official Microsoft Security Update Guide and your own asset inventory before deployment.
