Patch Tuesday: December 2025 (Expel’s version)
ID: a361ea0a-9a6e-5888-a060-92e91cf473a2
STIX ID: report--a361ea0a-9a6e-5888-a060-92e91cf473a2
Feed Name: Expel Blog
Threat Score
December Patch Tuesday (Dec 9, 2025) covers 57 CVEs including three zero-days — notably an actively exploited Windows Cloud Files Mini Filter Driver UAF (CVE-2025-62221) enabling SYSTEM escalation — plus public RCE disclosures for GitHub Copilot and PowerShell and a RRAS heap overflow; the report also highlights massive EPSS score fluctuations in November affecting thousands of CVEs and urges prioritized patching and exploit-risk monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
