Microsoft Patch Tuesday security updates for November 2025 fixed an actively exploited Windows Kernel bug
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-62199 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-62215 | Local Privilege Escalation via Race Condition in Microsoft Windows Kernel A race condition (improper synchronization of concurrent access to shared resources, tracked alongside a double-free issue, CWE-362/CWE-415) in the Microsoft Windows Kernel allows an authenticated local attacker to elevate privileges. To trigger it, an attacker with low privileges must run code that races kernel operations on a shared resource; the high attack complexity means timing must line up, but successful races corrupt kernel state and yield elevated execution. A successful exploit grants the attacker kernel/SYSTEM-level access with high impact on confidentiality, integrity, and availability of the host. All Windows 10 builds from 1809 through 22H2, Windows 11 23H2 through 25H2, and Windows Server 2019 through 2025 are affected. Microsoft patched the flaw in its November 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-12 as actively exploited in the wild; no public PoC is known and ransomware use is unconfirmed. Do: Apply Microsoft's November 2025 Patch Tuesday security updates for every affected Windows 10, Windows 11, and Windows Server version, prioritizing servers, domain controllers, and multi-user hosts where local privilege escalation has the greatest downstream impact. Because the flaw requires only low local privileges, treat any unpatched system where untrusted users or malware can execute code (RDS/VDI, kiosks, developer workstations) as at risk, and US federal agencies must remediate per CISA BOD 22-01 timelines. After deployment, verify the OS build reflects the November 2025 update, as active exploitation is confirmed even though no public PoC is available. | 7.0 | 6% | KEV |
| masshundreds of millions of Windows endpoints and servers (essentially every supported Windows 10/11 desktop and Windows Server 2019+ host worldwide) |
Full article282 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 12, 2025

Microsoft fixed over 60 flaws, including an actively exploited Windows kernel zero-day, in its latest Patch Tuesday updates.
Microsoft’s Patch Tuesday security updates for November 2025 addressed 63 vulnerabilities impacting Windows and Windows Components, Office and Office Components, Microsoft Edge (Chromium-based), Azure Monitor Agent, Dynamics 365, Hyper-V, SQL Server, and the Windows Subsystem for Linux GUI.
Four of these vulnerabilities are rated as Critical and 59 are rated Important in severity. None of the vulnerabilities addressed this month was publicly known at the time of release.
“This release is a far cry from the 177 CVEs we saw last month, although I don’t think anyone will complain.” reads the post published by ZDI. “This drop could also be due to the fact that this is the first month where Windows 10 is not receiving updates. We will see what December brings and how close we end up to the record total of CVEs set back in 2020. “
Microsoft warns that a Windows Kernel Elevation of Privilege Vulnerability, tracked as CVE-2025-62215 (CVSS score of 7), has been under active attack.
“Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Kernel allows an authorized attacker to elevate privileges locally.” reads the advisory. “Successful exploitation of this vulnerability requires an attacker to win a race condition. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.”
Microsoft also addressed an Office Remote Code Execution Vulnerability tracked as CVE-2025-62199. The issue is a use after free in Microsoft Office that allows an unauthorized attacker to execute code locally.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Patch Tuesday)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/184507/security/microsoft-patch-tuesday-updates-for-november-2025-fixed-an-actively-exploited-windows-kernel-bug.html