Microsoft Patch Tuesday addresses 63 defects, including one actively exploited zero-day
ID: d7bec85c-2516-5474-bccf-256883817b94
STIX ID: report--d7bec85c-2516-5474-bccf-256883817b94
Feed Name: CyberScoop
Microsoft released its November security update addressing 63 vulnerabilities across Windows and core products, including an actively exploited Windows Kernel zero-day (CVE-2025-62215) that leverages a race condition to enable privilege escalation from low-privileged local code, and a critical RCE in Microsoft Graphics Component (CVE-2025-60724, CVSS 9.8). Microsoft also flagged multiple Windows Ancillary Function Driver for WinSock vulnerabilities as likely to be exploited; vendors and researchers note functional exploits exist though public proof-of-concept code is not available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
