Microsoft’s last Patch Tuesday of 2025 addresses 57 defects, including one zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-59516 | Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. NVD description · AI analysis pending | 7.8 | 2% |
| — | ||
| CVE-2025-62549 | Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 group max | 1% |
| — | ||
| CVE-2025-62221 | Use-After-Free Local Privilege Escalation in Windows Cloud Files Mini Filter Driver CVE-2025-62221 is a use-after-free flaw (CWE-416) in the Windows Cloud Files Mini Filter Driver, the in-box kernel component that handles cloud storage placeholder files. An attacker who already has low-privileged access on a local machine can trigger the flaw through operations involving the affected driver, with no user interaction required. Successful exploitation elevates the attacker's privileges on the local host, with high impact on confidentiality, integrity, and availability (CVSS 7.8), meaning effective full compromise of the machine. All listed Windows 10, Windows 11, and Windows Server builds are affected, and Microsoft shipped fixes in its December 2025 Patch Tuesday releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-09, indicating exploitation in the wild; EPSS is 2.5% (84th percentile) and no public proof-of-concept is known. Do: Deploy Microsoft's December 2025 Patch Tuesday cumulative updates (released on or around 2025-12-09) for each affected Windows 10, Windows 11, and Windows Server build via Windows Update, WSUS, or Intune, and confirm the update installed before treating hosts as remediated. Prioritize this patch given active exploitation and KEV status (federal agencies must follow BOD 22-01 timelines or the vendor's mitigations); no standalone workaround or public PoC is documented. Because this is a local privilege escalation, roll out first to fleets where low-privileged users routinely execute code, such as workstations and terminal/RDS servers. | 7.8 | 3% | KEV |
| masshundreds of millions to over 1 billion Windows 10/11 and Windows Server installations | |
| CVE-2025-62456 | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2025-62550 | Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2025-64672 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spo Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. NVD description · AI analysis pending | 9.0 | 1% |
| — |
Full article563 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Microsoft closed out the year with 1,139 total defects patched, making it the second-largest year in volume behind 2020, according to Trend Micro.
Listen to this article
0:00
Learn more.
Microsoft addressed 57 vulnerabilities affecting its various products for business operations and core systems, including one actively exploited zero-day, the company said in its latest monthly security update.
The zero-day vulnerability — CVE-2025-62221 — affects the Windows Cloud Files Mini Filter Driver and has a CVSS rating of 7.8. Attackers could exploit the use-after-free defect to gain system privileges, Microsoft said.
“These types of bugs are often combined with a code execution bug to take over a system,” Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, said in a blog post, adding that the vulnerability appears to affect every supported version of Windows.
The Cybersecurity and Infrastructure Security Agency added the zero-day to its known exploited vulnerabilities catalog Tuesday.
Microsoft’s final Patch Tuesday release of the year brings the total number of vulnerabilities patched by the vendor in 2025 to 1,139 CVEs, according to Childs. “This makes 2025 the second-largest year in volume, trailing 2020 by a mere 11 CVEs. As Microsoft’s portfolio continues to increase and as AI bugs become more prevalent, this number is likely to go higher in 2026,” he said.
Microsoft disclosed no critical vulnerabilities this month. The most severe defects it disclosed include five high-severity vulnerabilities — CVE-2025-62456 and CVE-2025-64678 affecting the Windows Resilient File System, CVE-2025-62549 affecting the Windows Routing and Remote Access Service, CVE-2025-62550 affecting the Azure Monitor Agent, CVE-2025-64672 affecting Microsoft Office SharePoint — each with CVSS ratings of 8.8.
Microsoft flagged six vulnerabilities as more likely to be exploited this month, including the zero-day, CVE-2025-59516 and CVE-2025-59517 affecting the Windows Storage VSP Driver, CVE-2025-62458 affecting Windows Win32K, CVE-2025-62470 affecting the Windows Common Log File System Driver and CVE-2025-62472 affecting the Windows Remote Access Connection Manager.
The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-december-2025/