ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft Patch Tuesday security updates for December 2025 fixed an actively exploited zero

criticalVulnerability exploited in the wildimportance 60CVE-2025-62221CVE-2025-64671CVE-2025-54100

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-54100
Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locall

Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
7.82%
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • +1 more
CVE-2025-62221
Use-After-Free Local Privilege Escalation in Windows Cloud Files Mini Filter Driver

CVE-2025-62221 is a use-after-free flaw (CWE-416) in the Windows Cloud Files Mini Filter Driver, the in-box kernel component that handles cloud storage placeholder files. An attacker who already has low-privileged access on a local machine can trigger the flaw through operations involving the affected driver, with no user interaction required. Successful exploitation elevates the attacker's privileges on the local host, with high impact on confidentiality, integrity, and availability (CVSS 7.8), meaning effective full compromise of the machine. All listed Windows 10, Windows 11, and Windows Server builds are affected, and Microsoft shipped fixes in its December 2025 Patch Tuesday releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-09, indicating exploitation in the wild; EPSS is 2.5% (84th percentile) and no public proof-of-concept is known.

Do: Deploy Microsoft's December 2025 Patch Tuesday cumulative updates (released on or around 2025-12-09) for each affected Windows 10, Windows 11, and Windows Server build via Windows Update, WSUS, or Intune, and confirm the update installed before treating hosts as remediated. Prioritize this patch given active exploitation and KEV status (federal agencies must follow BOD 22-01 timelines or the vendor's mitigations); no standalone workaround or public PoC is documented. Because this is a local privilege escalation, roll out first to fleets where low-privileged users routinely execute code, such as workstations and terminal/RDS servers.

7.83% KEV
  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2
  • Microsoft Windows Server 2019, 2022, 2022 23H2, 2025
masshundreds of millions to over 1 billion Windows 10/11 and Windows Server installations
CVE-2025-64671
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft github copilot
Full article258 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 10, 2025

Microsoft Patch Tuesday security updates for December 2025 address 57 vulnerabilities, including three critical flaws.

Microsoft Patch Tuesday security updates for December 2025 addressed 57 vulnerabilities in Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Exchange Server, Azure, Copilot, PowerShell, and Windows Defender. Three vulnerabilities are rated Critical, while the rest are rated Important in severity.

One of these vulnerabilities, tracked as CVE-2025-62221 (CVSS score of 7.8), is actively exploited in attacks in the wild. The vulnerability CVE-2025-62221 is a Windows Cloud Files Mini Filter Driver issue that allows an authorized attacker to elevate privileges locally.

“An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.” reads the advisory. “Exploitation Detected.”

Two other vulnerabilities, tracked as CVE-2025-64671 and CVE-2025-54100, are labeled as publicly known at the time of the release.

The two vulnerabilities are both remote code execution issues: CVE-2025-64671 in GitHub Copilot for JetBrains, which lets attackers run local commands via malicious cross-prompt injections in untrusted files or MCP servers, and CVE-2025-54100 in PowerShell, which can execute scripts embedded in webpages fetched with Invoke-WebRequest. The Copilot flaw was disclosed in research on AI IDE vulnerabilities. For PowerShell, Microsoft added a new warning to prompt users to use -UseBasicParsing to prevent unwanted script execution.

Researchers warn that a proof-of-concept (PoC) exists for CVE-2025-64671.

The full list of CVEs addressed by Microsoft for December 2025 is available here.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft Patch Tuesday)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185515/breaking-news/microsoft-patch-tuesday-security-updates-for-december-2025-fixed-an-actively-exploited-zero-day.html