Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-60704 | Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network. Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2025-60724 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 9.8 | 6% |
| — | ||
| CVE-2025-62215 | Local Privilege Escalation via Race Condition in Microsoft Windows Kernel A race condition (improper synchronization of concurrent access to shared resources, tracked alongside a double-free issue, CWE-362/CWE-415) in the Microsoft Windows Kernel allows an authenticated local attacker to elevate privileges. To trigger it, an attacker with low privileges must run code that races kernel operations on a shared resource; the high attack complexity means timing must line up, but successful races corrupt kernel state and yield elevated execution. A successful exploit grants the attacker kernel/SYSTEM-level access with high impact on confidentiality, integrity, and availability of the host. All Windows 10 builds from 1809 through 22H2, Windows 11 23H2 through 25H2, and Windows Server 2019 through 2025 are affected. Microsoft patched the flaw in its November 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-12 as actively exploited in the wild; no public PoC is known and ransomware use is unconfirmed. Do: Apply Microsoft's November 2025 Patch Tuesday security updates for every affected Windows 10, Windows 11, and Windows Server version, prioritizing servers, domain controllers, and multi-user hosts where local privilege escalation has the greatest downstream impact. Because the flaw requires only low local privileges, treat any unpatched system where untrusted users or malware can execute code (RDS/VDI, kiosks, developer workstations) as at risk, and US federal agencies must remediate per CISA BOD 22-01 timelines. After deployment, verify the OS build reflects the November 2025 update, as active exploitation is confirmed even though no public PoC is available. | 7.0 | 6% | KEV |
| masshundreds of millions of Windows endpoints and servers (essentially every supported Windows 10/11 desktop and Windows Server 2019+ host worldwide) | |
| CVE-2025-62220 | Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network. Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | <1% |
| — |
Full article824 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananNov 12, 2025Vulnerability / Patch Tuesday
Microsoft on Tuesday released patches for 63 new security vulnerabilities identified in its software, including one that has come under active exploitation in the wild.
Of the 63 flaws, four are rated Critical and 59 are rated Important in severity. Twenty-nine of these vulnerabilities are related to privilege escalation, followed by 16 remote code execution, 11 information disclosure, three denial-of-service (DoS), two security feature bypass, and two spoofing bugs.
The patches are in addition to the 27 vulnerabilities the Windows maker addressed in its Chromium-based Edge browser since the release of October 2025's Patch Tuesday update.
The zero-day vulnerability that has been listed as exploited in Tuesday's update is CVE-2025-62215 (CVSS score: 7.0), a privilege escalation flaw in Windows Kernel. The Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have been credited with discovering and reporting the issue.
"Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally," the company said in an advisory.
That said, successful exploitation hinges on an attacker who has already gained a foothold on a system to win a race condition. Once this criterion is satisfied, it could permit the attacker to obtain SYSTEM privileges.
"An attacker with low-privilege local access can run a specially crafted application that repeatedly attempts to trigger this race condition," Ben McCarthy, lead cybersecurity engineer at Immersive, said.
"The goal is to get multiple threads to interact with a shared kernel resource in an unsynchronized way, confusing the kernel's memory management and causing it to free the same memory block twice. This successful 'double free' corrupts the kernel heap, allowing the attacker to overwrite memory and hijack the system's execution flow."
It's currently not known how this vulnerability is being exploited and by whom, but it's assessed to be used as part of a post-exploitation activity to escalate their privileges after obtaining initial access through some other means, such as social engineering, phishing, or exploitation of another vulnerability, Satnam Narang, senior staff research engineer at Tenable, said.
"When chained with other bugs this kernel race is critical: an RCE or sandbox escape can supply the local code execution needed to turn a remote attack into a SYSTEM takeover, and an initial low‑privilege foothold can be escalated to dump credentials and move laterally," Mike Walters, president and co-founder of Action1, said in a statement.
Also patched as part of the updates are two heap-based buffer overflow flaws in Microsoft's Graphics Component (CVE-2025-60724, CVSS score: 9.8) and Windows Subsystem for Linux GUI (CVE-2025-62220, CVSS score: 8.8) that could result in remote code execution.
Another vulnerability of note is a high-severity privilege escalation flaw in Windows Kerberos (CVE-2025-60704, CVSS score: 7.5) that takes advantage of a missing cryptographic step to gain administrator privileges. The vulnerability has been codenamed CheckSum by Silverfort.
"The attacker must inject themselves into the logical network path between the target and the resource requested by the victim to read or modify network communications," Microsoft said. "An unauthorized attacker must wait for a user to initiate a connection."
Silverfort researchers Eliran Partush and Dor Segal, who discovered the shortcoming, described it as a Kerberos constrained delegation vulnerability that allows an attacker to impersonate arbitrary users and gain control over an entire domain by means of an adversary-in-the-middle (AitM) attack.
An attacker who is able to successfully exploit the flaw could escalate privileges and move laterally to other machines in an organization. More concerning, threat actors could also gain the ability to impersonate any user in the company, allowing them to gain unfettered access or become a domain administrator.
"Any organization using Active Directory, with the Kerberos delegation capability turned on, is impacted," Silverfort said. "Because Kerberos delegation is a feature within Active Directory, an attacker requires initial access to an environment with compromised credentials."
Software Patches from Other Vendors
In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including —
- Adobe
- Amazon Web Services
- AMD
- Apple
- ASUS
- Atlassian
- AutomationDirect
- Bitdefender
- Broadcom (including VMware)
- Cisco
- Citrix
- ConnectWise
- D-Link
- Dell
- Devolutions
- Drupal
- Elastic
- F5
- Fortinet
- GitLab
- Google Android
- Google Chrome
- Google Cloud
- Grafana
- Hitachi Energy
- HP
- HP Enterprise (including Aruba Networking and Juniper Networks)
- IBM
- Intel
- Ivanti
- Jenkins
- Lenovo
- Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu
- MediaTek
- Mitsubishi Electric
- MongoDB
- Moxa
- Mozilla Firefox and Firefox ESR
- NVIDIA
- Oracle
- Palo Alto Networks
- QNAP
- Qualcomm
- Rockwell Automation
- Ruckus Wireless
- Samba
- Samsung
- SAP
- Schneider Electric
- Siemens
- SolarWinds
- SonicWall
- Splunk
- Spring Framework
- Supermicro
- Synology
- TP-Link
- WatchGuard, and
- Zoom
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/11/microsoft-fixes-63-security-flaws.html