ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-59517
+4 in the same advisory: …62472 …54100 …62458 …62470
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.82%
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • +1 more
CVE-2025-59516
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.82%
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • +1 more
CVE-2025-62221
Use-After-Free Local Privilege Escalation in Windows Cloud Files Mini Filter Driver

CVE-2025-62221 is a use-after-free flaw (CWE-416) in the Windows Cloud Files Mini Filter Driver, the in-box kernel component that handles cloud storage placeholder files. An attacker who already has low-privileged access on a local machine can trigger the flaw through operations involving the affected driver, with no user interaction required. Successful exploitation elevates the attacker's privileges on the local host, with high impact on confidentiality, integrity, and availability (CVSS 7.8), meaning effective full compromise of the machine. All listed Windows 10, Windows 11, and Windows Server builds are affected, and Microsoft shipped fixes in its December 2025 Patch Tuesday releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-09, indicating exploitation in the wild; EPSS is 2.5% (84th percentile) and no public proof-of-concept is known.

Do: Deploy Microsoft's December 2025 Patch Tuesday cumulative updates (released on or around 2025-12-09) for each affected Windows 10, Windows 11, and Windows Server build via Windows Update, WSUS, or Intune, and confirm the update installed before treating hosts as remediated. Prioritize this patch given active exploitation and KEV status (federal agencies must follow BOD 22-01 timelines or the vendor's mitigations); no standalone workaround or public PoC is documented. Because this is a local privilege escalation, roll out first to fleets where low-privileged users routinely execute code, such as workstations and terminal/RDS servers.

7.83% KEV
  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2
  • Microsoft Windows Server 2019, 2022, 2022 23H2, 2025
masshundreds of millions to over 1 billion Windows 10/11 and Windows Server installations
CVE-2025-62562
+2 in the same advisory: …62554 …62557
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
  • +1 more
CVE-2025-64671
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft github copilot
Full article585 words · extracted from krebsonsecurity.com · click to collapse

Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. This final Patch Tuesday of 2025 tackles one zero-day bug that is already being exploited, as well as two publicly disclosed vulnerabilities.

Despite releasing a lower-than-normal number of security updates these past few months, Microsoft patched a whopping 1,129 vulnerabilities in 2025, an 11.9% increase from 2024. According to Satnam Narang at Tenable, this year marks the second consecutive year that Microsoft patched over one thousand vulnerabilities, and the third time it has done so since its inception.

The zero-day flaw patched today is CVE-2025-62221, a privilege escalation vulnerability affecting Windows 10 and later editions. The weakness resides in a component called the “Windows Cloud Files Mini Filter Driver” — a system driver that enables cloud applications to access file system functionalities.

“This is particularly concerning, as the mini filter is integral to services like OneDrive, Google Drive, and iCloud, and remains a core Windows component, even if none of those apps were installed,” said Adam Barnett, lead software engineer at Rapid7.

Only three of the flaws patched today earned Microsoft’s most-dire “critical” rating: Both CVE-2025-62554 and CVE-2025-62557 involve Microsoft Office, and both can exploited merely by viewing a booby-trapped email message in the Preview Pane. Another critical bug — CVE-2025-62562 — involves Microsoft Outlook, although Redmond says the Preview Pane is not an attack vector with this one.

But according to Microsoft, the vulnerabilities most likely to be exploited from this month’s patch batch are other (non-critical) privilege escalation bugs, including:

CVE-2025-62458 — Win32k
CVE-2025-62470 — Windows Common Log File System Driver
CVE-2025-62472 — Windows Remote Access Connection Manager
CVE-2025-59516 — Windows Storage VSP Driver
CVE-2025-59517 — Windows Storage VSP Driver

Kev Breen, senior director of threat research at Immersive, said privilege escalation flaws are observed in almost every incident involving host compromises.

“We don’t know why Microsoft has marked these specifically as more likely, but the majority of these components have historically been exploited in the wild or have enough technical detail on previous CVEs that it would be easier for threat actors to weaponize these,” Breen said. “Either way, while not actively being exploited, these should be patched sooner rather than later.”

One of the more interesting vulnerabilities patched this month is CVE-2025-64671, a remote code execution flaw in the Github Copilot Plugin for Jetbrains AI-based coding assistant that is used by Microsoft and GitHub. Breen said this flaw would allow attackers to execute arbitrary code by tricking the large language model (LLM) into running commands that bypass the user’s “auto-approve” settings.

CVE-2025-64671 is part of a broader, more systemic security crisis that security researcher Ari Marzuk has branded IDEsaster (IDE  stands for “integrated development environment”), which encompasses more than 30 separate vulnerabilities reported in nearly a dozen market-leading AI coding platforms, including Cursor, Windsurf, Gemini CLI, and Claude Code.

The other publicly-disclosed vulnerability patched today is CVE-2025-54100, a remote code execution bug in Windows Powershell on Windows Server 2008 and later that allows an unauthenticated attacker to run code in the security context of the user.

For anyone seeking a more granular breakdown of the security updates Microsoft pushed today, check out the roundup at the SANS Internet Storm Center. As always, please leave a note in the comments if you experience problems applying any of this month’s Windows patches.

Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2025/12/microsoft-patch-tuesday-december-2025-edition/