logo

Microsoft Patch Tuesday, December 2025 Edition

ID: 1ae697a7-fa66-544f-9cdf-7b0acb79ab1a

STIX ID: report--1ae697a7-fa66-544f-9cdf-7b0acb79ab1a

Feed Name: Krebs on Security

Threat Score
85/100

Date Published: 2025-12-09

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

**Microsoft December 2025 Patch Tuesday:** Microsoft released fixes for 56 vulnerabilities (part of 1,129 patched in 2025), including an actively exploited zero-day privilege escalation in the Windows Cloud Files Mini Filter Driver (CVE-2025-62221), three critical Office/Outlook RCEs exploitable via email preview in some cases, multiple privilege escalation bugs Microsoft considers likely to be weaponized, a GitHub Copilot plugin RCE tied to broader "IDESaster" issues in IDEs, and a public PowerShell RCE—administrators are advised to prioritize patching affected systems and components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.