logo

Microsoft December 2025 Patch Tuesday – 56 Vulnerabilities Fixed Including 3 Zero-days

ID: 135868e3-61a5-5f7e-884b-ee53e8cb3193

STIX ID: report--135868e3-61a5-5f7e-884b-ee53e8cb3193

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Guru Baran

...
...

This report is a consolidated vulnerability listing of many Microsoft CVEs (mostly rated Important, with a few Critical entries) affecting Office, Windows kernel and services, Azure Monitor Agent, Exchange, SharePoint, PowerShell and other components; impacts include remote code execution, elevation of privilege, denial of service, information disclosure, and spoofing, with root causes cited such as use-after-free, heap buffer overflows, out-of-bounds reads/writes, null pointer dereferences, race conditions, and command injection. The bulletin provides identifiers, impact types and short technical descriptions but does not include exploit telemetry, mitigation steps, or evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.