BlackTreeCVE IntelligenceCanonical Patch Tuesday catalogue
March 2025 Patch Tuesday catalogue.
Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 88 operational patch records link 123 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.
March 2025 Patch Tuesday
Patch catalogue
Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.
AdobeUpdate Adobe Substance 3D Sampler to the fixed Adobe releaseAPSB25-16 · Updated 2025-03-11Product and releaseAdobe Substance 3D Sampler5.0Review linked CVEs (7) No confirmed exploitation stated
Operational summary
Adobe published APSB25-16 on Patch Tuesday for Adobe Substance 3D Sampler. The bulletin links 7 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-16
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Painter to the fixed Adobe releaseAPSB25-18 · Updated 2025-03-11Product and releaseAdobe Substance 3D Painter11.0Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB25-18 on Patch Tuesday for Adobe Substance 3D Painter. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-18
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Modeler to the fixed Adobe releaseAPSB25-21 · Updated 2025-03-11Product and releaseAdobe Substance 3D Modeler1.21.0Review linked CVEs (4) No confirmed exploitation stated
Operational summary
Adobe published APSB25-21 on Patch Tuesday for Adobe Substance 3D Modeler. The bulletin links 4 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-21
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Designer to the fixed Adobe releaseAPSB25-22 · Updated 2025-03-11Product and releaseAdobe Substance 3D Designer14.1.1Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB25-22 on Patch Tuesday for Adobe Substance 3D Designer. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-22
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Acrobat Reader to the fixed Adobe releaseAPSB25-14 · Updated 2025-03-11Product and releaseAdobe Acrobat ReaderFixed release detail requires source reviewReview linked CVEs (9) No confirmed exploitation stated
Operational summary
Adobe published APSB25-14 on Patch Tuesday for Adobe Acrobat Reader. The bulletin links 9 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-14
- Platform
- See Adobe bulletin
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB25-17 · Updated 2025-03-11Product and releaseAdobe Illustrator29.3 and above, 28.7.5 and aboveReview linked CVEs (6) No confirmed exploitation stated
Operational summary
Adobe published APSB25-17 on Patch Tuesday for Adobe Illustrator. The bulletin links 6 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-17
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB25-19 · Updated 2025-03-11Product and releaseAdobe InDesignID20.2, ID19.5.3Review linked CVEs (9) No confirmed exploitation stated
Operational summary
Adobe published APSB25-19 on Patch Tuesday for Adobe InDesign. The bulletin links 9 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-19
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
MicrosoftDeploy Microsoft Azure update for Azure promptflow-coreMSRC-2025-03-azure-release-notes · Updated 2025-03-11Product and releaseAzure promptflow-core1.17.2Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure promptflow-core.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-03-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure promptflow-toolsMSRC-2025-03-azure-release-notes · Updated 2025-03-11Product and releaseAzure promptflow-tools1.6.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure promptflow-tools.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-03-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Agent for Site RecoveryMSRC-2025-03-azure-release-notes · Updated 2025-03-11Product and releaseAzure Agent for Site Recovery9.30Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Agent for Site Recovery.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-03-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Agent for BackupMSRC-2025-03-azure-release-notes · Updated 2025-03-11Product and releaseAzure Agent for Backup2.0.9940.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Agent for Backup.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-03-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure CLIMSRC-2025-03-azure-release-notes · Updated 2025-03-11Product and releaseAzure CLI2.69.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure CLI.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-03-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure ARCMSRC-2025-03-azure-what-s-new · Updated 2025-03-11Product and releaseAzure ARC1.0.10Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure ARC.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-03-azure-what-s-new
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools security update KB5054229KB5054229 · Updated 2025-03-11Product and releaseASP.NET Core 8.08.0.14Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for ASP.NET Core 8.0.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5054229
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5054230KB5054230 · Updated 2025-03-11Product and releaseASP.NET Core 9.09.0.3Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for ASP.NET Core 9.0.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5054230
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools update for WinDbgMSRC-2025-03-developer-tools-release-notes · Updated 2025-03-11Product and releaseWinDbg1.2502.25002.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for WinDbg.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-03-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.12MSRC-2025-03-developer-tools-release-notes · Updated 2025-03-11Product and releaseMicrosoft Visual Studio 2022 version 17.1217.12.6Review linked CVEs (3) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Visual Studio 2022 version 17.12.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-03-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.13MSRC-2025-03-developer-tools-release-notes · Updated 2025-03-11Product and releaseMicrosoft Visual Studio 2022 version 17.1317.13.3Review linked CVEs (3) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Visual Studio 2022 version 17.13.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-03-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.8MSRC-2025-03-developer-tools-release-notes · Updated 2025-03-11Product and releaseMicrosoft Visual Studio 2022 version 17.817.8.19Review linked CVEs (3) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Visual Studio 2022 version 17.8.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-03-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.10MSRC-2025-03-developer-tools-release-notes · Updated 2025-03-11Product and releaseMicrosoft Visual Studio 2022 version 17.1017.10.12Review linked CVEs (3) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Visual Studio 2022 version 17.10.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-03-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.