ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Microsoft’s last Patch Tuesday of 2025 addresses 57 defects, including one zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-59516
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.82%
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • +1 more
CVE-2025-62549
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.8
group max
1%
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • +1 more
CVE-2025-62221
Use-After-Free Local Privilege Escalation in Windows Cloud Files Mini Filter Driver

CVE-2025-62221 is a use-after-free flaw (CWE-416) in the Windows Cloud Files Mini Filter Driver, the in-box kernel component that handles cloud storage placeholder files. An attacker who already has low-privileged access on a local machine can trigger the flaw through operations involving the affected driver, with no user interaction required. Successful exploitation elevates the attacker's privileges on the local host, with high impact on confidentiality, integrity, and availability (CVSS 7.8), meaning effective full compromise of the machine. All listed Windows 10, Windows 11, and Windows Server builds are affected, and Microsoft shipped fixes in its December 2025 Patch Tuesday releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-09, indicating exploitation in the wild; EPSS is 2.5% (84th percentile) and no public proof-of-concept is known.

Do: Deploy Microsoft's December 2025 Patch Tuesday cumulative updates (released on or around 2025-12-09) for each affected Windows 10, Windows 11, and Windows Server build via Windows Update, WSUS, or Intune, and confirm the update installed before treating hosts as remediated. Prioritize this patch given active exploitation and KEV status (federal agencies must follow BOD 22-01 timelines or the vendor's mitigations); no standalone workaround or public PoC is documented. Because this is a local privilege escalation, roll out first to fleets where low-privileged users routinely execute code, such as workstations and terminal/RDS servers.

7.83% KEV
  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2
  • Microsoft Windows Server 2019, 2022, 2022 23H2, 2025
masshundreds of millions to over 1 billion Windows 10/11 and Windows Server installations
CVE-2025-62456
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.

NVD description · AI analysis pending
8.81%
  • microsoft windows 11 23h2
  • microsoft windows 11 24h2
  • microsoft windows 11 25h2
  • +1 more
CVE-2025-62550
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

NVD description · AI analysis pending
8.8<1%
  • microsoft azure monitor agent
CVE-2025-64672
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spo

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

NVD description · AI analysis pending
9.01%
  • microsoft sharepoint server
Full article563 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Microsoft closed out the year with 1,139 total defects patched, making it the second-largest year in volume behind 2020, according to Trend Micro.

Listen to this article

0:00

Learn more.

Microsoft Headquarters
A sign is seen at the Microsoft headquarters on July 3, 2024, in Redmond, Washington. (David Ryder/Getty Images)

Microsoft addressed 57 vulnerabilities affecting its various products for business operations and core systems, including one actively exploited zero-day, the company said in its latest monthly security update.

The zero-day vulnerability — CVE-2025-62221 — affects the Windows Cloud Files Mini Filter Driver and has a CVSS rating of 7.8. Attackers could exploit the use-after-free defect to gain system privileges, Microsoft said. 

“These types of bugs are often combined with a code execution bug to take over a system,” Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, said in a blog post, adding that the vulnerability appears to affect every supported version of Windows.

The Cybersecurity and Infrastructure Security Agency added the zero-day to its known exploited vulnerabilities catalog Tuesday. 

Microsoft’s final Patch Tuesday release of the year brings the total number of vulnerabilities patched by the vendor in 2025 to 1,139 CVEs, according to Childs. “This makes 2025 the second-largest year in volume, trailing 2020 by a mere 11 CVEs. As Microsoft’s portfolio continues to increase and as AI bugs become more prevalent, this number is likely to go higher in 2026,” he said.

Microsoft disclosed no critical vulnerabilities this month. The most severe defects it disclosed include five high-severity vulnerabilities — CVE-2025-62456 and CVE-2025-64678 affecting the Windows Resilient File System, CVE-2025-62549 affecting the Windows Routing and Remote Access Service, CVE-2025-62550 affecting the Azure Monitor Agent, CVE-2025-64672 affecting Microsoft Office SharePoint — each with CVSS ratings of 8.8.

Microsoft flagged six vulnerabilities as more likely to be exploited this month, including the zero-day, CVE-2025-59516 and CVE-2025-59517 affecting the Windows Storage VSP Driver, CVE-2025-62458 affecting Windows Win32K, CVE-2025-62470 affecting the Windows Common Log File System Driver and CVE-2025-62472 affecting the Windows Remote Access Connection Manager.

The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-december-2025/