December 2025 Patch Tuesday forecast: And it’s a wrap
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-62215 | Local Privilege Escalation via Race Condition in Microsoft Windows Kernel A race condition (improper synchronization of concurrent access to shared resources, tracked alongside a double-free issue, CWE-362/CWE-415) in the Microsoft Windows Kernel allows an authenticated local attacker to elevate privileges. To trigger it, an attacker with low privileges must run code that races kernel operations on a shared resource; the high attack complexity means timing must line up, but successful races corrupt kernel state and yield elevated execution. A successful exploit grants the attacker kernel/SYSTEM-level access with high impact on confidentiality, integrity, and availability of the host. All Windows 10 builds from 1809 through 22H2, Windows 11 23H2 through 25H2, and Windows Server 2019 through 2025 are affected. Microsoft patched the flaw in its November 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-12 as actively exploited in the wild; no public PoC is known and ransomware use is unconfirmed. Do: Apply Microsoft's November 2025 Patch Tuesday security updates for every affected Windows 10, Windows 11, and Windows Server version, prioritizing servers, domain controllers, and multi-user hosts where local privilege escalation has the greatest downstream impact. Because the flaw requires only low local privileges, treat any unpatched system where untrusted users or malware can execute code (RDS/VDI, kiosks, developer workstations) as at risk, and US federal agencies must remediate per CISA BOD 22-01 timelines. After deployment, verify the OS build reflects the November 2025 update, as active exploitation is confirmed even though no public PoC is available. | 7.0 | 6% | KEV |
| masshundreds of millions of Windows endpoints and servers (essentially every supported Windows 10/11 desktop and Windows Server 2019+ host worldwide) | |
| CVE-2025-9491 | LNK File UI Misrepresentation RCE in Microsoft Windows CVE-2025-9491 is a user-interface misrepresentation flaw (CWE-451) in Microsoft Windows' handling of .LNK shortcut files: crafted data in an .LNK file can make hazardous content invisible when a user inspects the file through the Windows-provided UI. Exploitation requires user interaction — the target must visit a malicious page or open a malicious file — after which the disguised shortcut causes code execution. A successful attack lets the attacker run arbitrary code in the context of the current user, with no privilege escalation indicated (CVSS 4.0 base score 4.6, local attack vector). The CPE data lists Windows 11 23H2 as the affected product, though the advisory text describes Microsoft Windows generally; no affected build numbers are provided. Exploitation is not hypothetical: reporting indicates Microsoft silently patched the flaw after years of active exploitation, APT groups continue leveraging it, EPSS assigns a 68.9% probability of exploitation within 30 days (99th percentile), and it is not yet in CISA KEV. Do: Ensure Windows endpoints are fully patched with the Microsoft update that fixes .LNK file rendering — verify fleet-wide build levels through Windows Update or your patch-management tooling, since the fix was reportedly shipped silently. Until patched, treat .LNK files arriving via email, web downloads, or removable USB media with suspicion and do not rely on visual inspection of shortcut properties as a safety check. Given reported APT abuse, prioritize detection of malicious .LNK delivery in targeted sectors (government, power) named in current threat reporting. | 4.6 | 69% |
| mass≈100M+ devices (Windows 11 23H2 is one of the most widely deployed Windows 11 releases) |
Full article717 words · extracted from helpnetsecurity.com · click to collapse
It’s hard to believe that we’re in December of 2025 already and the end of the year is fast approaching. Looking back on the year, there are two major items that really stand out in my mind. First, there is the large number of Microsoft products that have come to EOL/EOS near the end of this year. It seemed there was always a reason their products would get official extended support at the last minute, but this time, that didn’t happen – applications and operating systems alike came to an end.

And second, this is the year that AI started to touch everyone in a big way. It’s now possible to interact with it directly in a browser and many companies have included AI technology in their products in various ways. We’ll see what 2026 brings, as I anticipate it will start to be more heavily used with the latest patch technologies.
Windows 10 ESU debuts as Microsoft patches zero-day in November update
November 2025 Patch Tuesday included the first set of Windows 10 Extended Security Updates (ESU). I hope everyone who still needs to run Windows 10 was able to update to 22H2 and apply the ESU, because we already had a zero-day exploitation in CVE-2025-62215 Windows Kernel Elevation of Privilege Vulnerability. There were 38 CVEs fixed for Windows 11 and 11 CVEs for Microsoft 365 Apps; both of which included CVEs rated Critical. There were updates for Windows SharePoint Server and SQL Server, which were both rated Important. It was a nice break after the extensive number of patches from the previous two months.
This month has been a busy one for Microsoft. Following the November hotpatch release of KB5068966, they reported a known issue whereby “on Windows 11, version 25H2, Windows Update might download and install the update again when it scans for updates.” On November 21, they provided out-of-band KB5072753 to address the issue. If you didn’t install the November hotpatch, Microsoft advised to apply the OOB instead.
Microsoft rolls out fixes for XAML app issues, .LNK vulnerability, and Outlook Excel glitch
In late November, Microsoft released KB5072911 titled Explorer, the Start menu, and other XAML-dependent apps might not start or close unexpectedly on some enterprise devices. These issues are confined to Windows 11 and have been reported fixed in the December preview patch, but there appear to still be some side effects, for example, the screen flashes white when dark mode is set and a File Explorer is opened.
And finally, there is a report that Microsoft has quietly made changes to start fixing CVE-2025-9491 which was also covered in Advisory 25258226. This vulnerability exists in the handling of .LNK files and was reported by the Zero Day Initiative back in March. You can read all about this vulnerability including the silent changes made by Microsoft and the coverage provided by 0Patch, in this latest 0Patch blog.
Microsoft announced an issue where some Excel attachments in the new Outlook client were not opening. This was impacting Exchange Online customers. Microsoft has begun deploying a fix, but it may take a while to reach all customers.
December 2025 Patch Tuesday forecast
- The Microsoft releases should be on par with what we saw last month. The usual Windows 10 LTSC, Windows 11, and supported Server versions 2016-2025 will see a moderate number of CVEs addressed.
- Adobe, the most common Creative Cloud apps, received an update last month, so don’t expect any major updates for those apps. Adobe Acrobat and Reader are due for a major update, so be on the lookout for that one.
- Apple is unlikely to provide another update before the end of the year, since their last set of operating systems and other apps was on November 3.
- Google released Chrome beta 144.0.7559.3 for Windows, Mac and Linux yesterday, so expect that version on Patch Tuesday.
- Mozilla has been releasing their updates on Patch Tuesday as of late, so expect them next week as well.
And so, we wrap up another year of Patch Tuesdays. I think we’ll see a standard set of updates next week, which we all know how to handle; and then we can take a little time off to be with family and friends. Wishing you all a Merry Christmas and Happy New Year!
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/12/08/december-2025-patch-tuesday-forecast-and-its-a-wrap/