Microsoft Fixes Three Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10573 | Stored Cross-Site Scripting in Ivanti Endpoint Manager Exposes Admin Sessions CVE-2025-10573 is a stored cross-site scripting (CWE-79) flaw in Ivanti Endpoint Manager versions prior to 2024 SU4 SR1. A remote, unauthenticated attacker can plant malicious script content in the product, and when an administrator interacts with the affected view (user interaction is required), arbitrary JavaScript executes in the context of the administrator's browser session. An attacker who succeeds can act as an EPM administrator, potentially viewing or modifying administrative data, which the scope-changed CVSS 3.1 score of 6.1 reflects via low confidentiality and integrity impact. Organizations running Ivanti EPM on-premises, typically to manage large fleets of corporate endpoints, are affected. As of now there is no known public proof-of-concept and the flaw is not in CISA KEV, but EPSS assigns a 33.5% probability of exploitation within 30 days (98th percentile), indicating elevated risk. Do: Upgrade Ivanti Endpoint Manager to 2024 SU4 SR1 or later as soon as possible, and apply the latest Ivanti patch rollups, since related advisories indicate Ivanti shipped fixes for multiple EPM issues in the same cycle. Until patched, restrict network access to the EPM core server and administrative console, and have administrators avoid engaging with unexpected or untrusted content in the console. After patching, review EPM administrator accounts and recent session activity for signs of unauthorized administrative actions. | 6.1 | 33% |
| largetens of thousands of EPM core deployments worldwide (widely deployed enterprise endpoint-management platform) | ||
| CVE-2025-54100 | Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locall Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 7.8 | 2% |
| — | ||
| CVE-2025-62221 | Use-After-Free Local Privilege Escalation in Windows Cloud Files Mini Filter Driver CVE-2025-62221 is a use-after-free flaw (CWE-416) in the Windows Cloud Files Mini Filter Driver, the in-box kernel component that handles cloud storage placeholder files. An attacker who already has low-privileged access on a local machine can trigger the flaw through operations involving the affected driver, with no user interaction required. Successful exploitation elevates the attacker's privileges on the local host, with high impact on confidentiality, integrity, and availability (CVSS 7.8), meaning effective full compromise of the machine. All listed Windows 10, Windows 11, and Windows Server builds are affected, and Microsoft shipped fixes in its December 2025 Patch Tuesday releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-09, indicating exploitation in the wild; EPSS is 2.5% (84th percentile) and no public proof-of-concept is known. Do: Deploy Microsoft's December 2025 Patch Tuesday cumulative updates (released on or around 2025-12-09) for each affected Windows 10, Windows 11, and Windows Server build via Windows Update, WSUS, or Intune, and confirm the update installed before treating hosts as remediated. Prioritize this patch given active exploitation and KEV status (federal agencies must follow BOD 22-01 timelines or the vendor's mitigations); no standalone workaround or public PoC is documented. Because this is a local privilege escalation, roll out first to fleets where low-privileged users routinely execute code, such as workstations and terminal/RDS servers. | 7.8 | 3% | KEV |
| masshundreds of millions to over 1 billion Windows 10/11 and Windows Server installations | |
| CVE-2025-62562 | Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-64671 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally. Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 7.8 | <1% |
| — |
Full article529 words · extracted from infosecurity-magazine.com · click to collapse
Microsoft patched an actively exploited zero-day vulnerability as part of its monthly security update cycle yesterday.
CVE-2025-62221 is an elevation of privilege (EoP) bug in the Windows Cloud Files Mini Filter Driver, which enables a low-privileged user to achieve system-level code execution through a kernel-mode use-after-free flaw.
Although no confirmed proof-of-concept (PoC) is available, it’s likely that threat actors already have the requisite knowledge to exploit it, warned Action1 president, Mike Walters.
“The real impact of this vulnerability emerges when attackers chain it with other weaknesses. After gaining low-privileged access through phishing, a browser exploit or an application [remote code execution] RCE, they can use CVE-2025-62221 to escalate to system and take full control of the host,” he explained.
“A kernel-level elevation in a widely deployed driver also enables sandbox or browser escape, turning limited execution into full OS compromise. With system privileges, attackers can deploy kernel components or abuse signed drivers to evade defenses and maintain persistence, and when combined with credential theft, this can quickly escalate to domain-wide compromise.”
Read more on Patch Tuesday: Microsoft Fixes Windows Kernel Zero Day in November Patch Tuesday
Microsoft also issued patches for two zero-days which have been publicly disclosed but not yet exploited in the wild.
CVE-2025-54100 is an RCE vulnerability in PowerShell which affects how the Windows tool processes web content.
“It lets an unauthenticated attacker execute arbitrary code in the security context of a user who runs a crafted PowerShell command, such as Invoke-WebRequest,” explained Action1 co-founder, Alex Vovk.
“Given the simplicity of the issue and PowerShell’s central role in offensive tooling, PoC scripts are likely to be straightforward for researchers and attackers who can craft response bodies that trigger the vulnerable parser logic.”
The third zero-day is CVE-2025-64671, an RCE flaw in GitHub Copilot for Jetbrains.
“Via a malicious Cross Prompt Inject in untrusted files or MCP servers, an attacker could execute additional commands by appending them to commands allowed in the user’s terminal auto-approve setting,” said Microsoft.
Elsewhere this month there were just three critical CVEs patched by Microsoft, all of which are classed as RCE.
Two of these (CVE-2025-62554 and CVE-2025-62557) impact Microsoft Office, while the third (CVE-2025-62562) can be found in Outlook.
All told, there were 19 RCE vulnerabilities listed in the December Patch Tuesday, and 28 EoP flaws.
A Busy December For SysAdmins
It’s proving to be a busy end to the year for sysadmins, who are already scrambling to find and patch the React2Shell flaw being widely exploited in attacks.
Ivanti has also released patches as part of its monthly update cycle, including a fix for a stored XSS flaw (CVE-2025-10573) in Ivanti Endpoint Manager (EPM), which has a CVSS score of 9.6.
“An attacker with unauthenticated access to the primary EPM web service can join fake managed endpoints to the EPM server in order to poison the administrator web dashboard with malicious JavaScript,” explained Rapid7 director of vulnerability intelligence, Douglas McKee.
“When an Ivanti EPM administrator views one of the poisoned dashboard interfaces during normal usage, that passive user interaction will trigger client-side JavaScript execution, resulting in the attacker gaining control of the administrator’s session.”
Image credit: Tada Images / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-three-zerodays-patch/