Microsoft Patch Tuesday, December 2025 Edition
ID: 1ae697a7-fa66-544f-9cdf-7b0acb79ab1a
STIX ID: report--1ae697a7-fa66-544f-9cdf-7b0acb79ab1a
Feed Name: Krebs on Security
**Microsoft December 2025 Patch Tuesday:** Microsoft released fixes for 56 vulnerabilities (part of 1,129 patched in 2025), including an actively exploited zero-day privilege escalation in the Windows Cloud Files Mini Filter Driver (CVE-2025-62221), three critical Office/Outlook RCEs exploitable via email preview in some cases, multiple privilege escalation bugs Microsoft considers likely to be weaponized, a GitHub Copilot plugin RCE tied to broader "IDESaster" issues in IDEs, and a public PowerShell RCE—administrators are advised to prioritize patching affected systems and components.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
