Microsoft December 2025 Patch Tuesday Fixes 56 Vulnerabilities Fixed and 3 Zero-days
Microsoft has released the final Patch Tuesday of 2025, addressing 56 vulnerabilities across its product suite. This update includes patches for three zero-day vulnerabilities, one of which is actively exploited. Among the resolved flaws, two are rated…
Microsoft has released the final Patch Tuesday of 2025, addressing 56 vulnerabilities across its product suite. This update includes patches for three zero-day vulnerabilities, one of which is actively exploited. Among the resolved flaws, two are rated as "Critical," while the remaining 54 are classified as "Important."
The update targets three zero-day vulnerabilities. CVE-2025-62221, an elevation of privilege flaw in the Windows Cloud Files Mini Filter Driver, has been actively exploited. Attackers can gain elevated privileges on compromised systems using this vulnerability. Two other zero-days, CVE-2025-54100 (a remote code execution vulnerability in PowerShell) and CVE-2025-64671 (an RCE vulnerability affecting GitHub Copilot for JetBrains), were publicly disclosed but not actively exploited.
The update addresses two "Critical" remote code execution vulnerabilities impacting Microsoft Office: CVE-2025-62554 (type confusion) and CVE-2025-62557 (use-after-free), allowing attackers to execute code locally. The majority of vulnerabilities are rated as "Important" and affect a range of products. This includes 25 elevation of privilege vulnerabilities in components like the Windows Cloud Files Mini Filter Driver (CVE-2025-62454, CVE-2025-62457), Win32k (CVE-2025-62458), and the Windows Common Log File System Driver (CVE-2025-62470).
Microsoft has released the final Patch Tuesday of 2025, addressing 56 vulnerabilities across its product suite.
Remote Code Execution: 19 Denial of Service: 3 Elevation of Privilege: 28 Information Disclosure: 4 Spoofing: 2 Total: 56
The patches also resolve 16 RCE vulnerabilities in products such as Microsoft Excel, Word, and the Windows Routing and Remote Access Service (RRAS). Additionally, the update includes fixes for spoofing, information disclosure, and denial-of-service vulnerabilities in Microsoft Exchange Server, Windows DirectX, and other components.
Due to the active exploitation of one of the zero-day vulnerabilities, it is recommended that users and administrators apply these security updates promptly.
Based on reporting by GBHackers.
