BlackTreeCVE IntelligenceCanonical Patch Tuesday catalogue
February 2025 Patch Tuesday catalogue.
Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 71 operational patch records link 123 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.
February 2025 Patch Tuesday
Patch catalogue
Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB25-08 · Updated 2025-02-11Product and releaseAdobe Commerce2.4.8-beta2 for 2.4.8-beta1, 2.4.7-p4 for 2.4.7-p3 and earlier, 2.4.6-p9 for 2.4.6-p8 and earlier, 2.4.5-p11 for 2.4.5-p10 and earlier, 2.4.4-p12 for 2.4.4-p11 and earlier, Isolated patch for CVE-2025-24434Review linked CVEs (31) No confirmed exploitation stated
Operational summary
Adobe published APSB25-08 on Patch Tuesday for Adobe Commerce. The bulletin links 31 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-08
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.4; Adobe priority 2, 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
- CVE-2025-24406
- CVE-2025-24407
- CVE-2025-24408
- CVE-2025-24409
- CVE-2025-24410
- CVE-2025-24411
- CVE-2025-24412
- CVE-2025-24413
- CVE-2025-24414
- CVE-2025-24415
- CVE-2025-24416
- CVE-2025-24417
- CVE-2025-24418
- CVE-2025-24419
- CVE-2025-24420
- CVE-2025-24421
- CVE-2025-24422
- CVE-2025-24423
- CVE-2025-24424
- CVE-2025-24425
- CVE-2025-24426
- CVE-2025-24427
- CVE-2025-24428
- CVE-2025-24429
- CVE-2025-24430
- CVE-2025-24432
- CVE-2025-24434
- CVE-2025-24435
- CVE-2025-24436
- CVE-2025-24437
- CVE-2025-24438
AdobeUpdate Adobe Substance 3D Designer to the fixed Adobe releaseAPSB25-12 · Updated 2025-02-11Product and releaseAdobe Substance 3D Designer14.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-12 on Patch Tuesday for Adobe Substance 3D Designer. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-12
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB25-01 · Updated 2025-02-11Product and releaseAdobe InDesignID20.1, ID19.5.2Review linked CVEs (7) No confirmed exploitation stated
Operational summary
Adobe published APSB25-01 on Patch Tuesday for Adobe InDesign. The bulletin links 7 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-01
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Stager to the fixed Adobe releaseAPSB25-09 · Updated 2025-02-11Product and releaseAdobe Substance 3D Stager3.1.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-09 on Patch Tuesday for Adobe Substance 3D Stager. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-09
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.5; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe InCopy to the fixed Adobe releaseAPSB25-10 · Updated 2025-02-11Product and releaseAdobe InCopy20.1, 19.5.2Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-10 on Patch Tuesday for Adobe InCopy. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-10
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB25-11 · Updated 2025-02-11Product and releaseAdobe Illustrator29.2.1 and above, 28.7.4 and aboveReview linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB25-11 on Patch Tuesday for Adobe Illustrator. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-11
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Photoshop Elements to the fixed Adobe releaseAPSB25-13 · Updated 2025-02-11Product and releaseAdobe Photoshop Elements2025.1 [build: 20250124.PSE.f552973b, 20250124.PSE.5345f07d (Mac ARM)]Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-13 on Patch Tuesday for Adobe Photoshop Elements. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-13
- Platform
- macOS (ARM)
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.0; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
MicrosoftDeploy Microsoft Apps update for Microsoft Outlook for AndroidMSRC-2025-02-apps-release-notes · Updated 2025-02-11Product and releaseMicrosoft Outlook for Android4.2501.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Outlook for Android.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-02-apps-release-notes
- Platform
- Apps
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Apps update for Microsoft PC ManagerMSRC-2025-02-apps-release-notes · Updated 2025-02-11Product and releaseMicrosoft PC Manager3.15.4.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft PC Manager.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-02-apps-release-notes
- Platform
- Apps
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Network Watcher VM ExtensionMSRC-2025-02-azure-release-notes · Updated 2025-02-11Product and releaseAzure Network Watcher VM Extension1.4.3563.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Network Watcher VM Extension.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-02-azure-release-notes
- Platform
- Azure
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Microsoft HPC Pack 2019MSRC-2025-02-azure-release-notes · Updated 2025-02-11Product and releaseMicrosoft HPC Pack 20196.3.8328.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft HPC Pack 2019.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-02-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Microsoft HPC Pack 2016MSRC-2025-02-azure-release-notes · Updated 2025-02-11Product and releaseMicrosoft HPC Pack 20162016.3Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft HPC Pack 2016.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-02-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)MSRC-2025-02-developer-tools-release-notes · Updated 2025-02-11Product and releaseMicrosoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)15.9.70Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8).
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-02-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)MSRC-2025-02-developer-tools-release-notes · Updated 2025-02-11Product and releaseMicrosoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)16.11.44Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10).
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-02-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.8MSRC-2025-02-developer-tools-release-notes · Updated 2025-02-11Product and releaseMicrosoft Visual Studio 2022 version 17.817.8.18Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2022 version 17.8.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-02-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.10MSRC-2025-02-developer-tools-release-notes · Updated 2025-02-11Product and releaseMicrosoft Visual Studio 2022 version 17.1017.10.11Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2022 version 17.10.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-02-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.12MSRC-2025-02-developer-tools-release-notes · Updated 2025-02-11Product and releaseMicrosoft Visual Studio 2022 version 17.1217.12.5Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2022 version 17.12.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-02-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Visual Studio CodeMSRC-2025-02-developer-tools-release-notes · Updated 2025-02-11Product and releaseVisual Studio Code1.97.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Visual Studio Code.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-02-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Visual Studio Code - JS Debug ExtensionMSRC-2025-02-developer-tools-release-notes · Updated 2025-02-11Product and releaseVisual Studio Code - JS Debug Extension1.97.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Visual Studio Code - JS Debug Extension.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-02-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft ESU security update KB5051972KB5051972 · Updated 2025-02-11Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 7 more1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 7 more. Microsoft marks CVE-2025-21377 as publicly disclosed, without that disclosure alone changing the BlackTree action window.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5051972
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.