logo

CVE-2025-62221 and CVE-2025-54100: Windows Elevation of Privilege and RCE Zero-Day Vulnerabilities Patched

ID: 863c62e7-8507-50e6-b6ef-e902b7bf5c2a

STIX ID: report--863c62e7-8507-50e6-b6ef-e902b7bf5c2a

Feed Name: SOC Prime Blog

Threat Score
78/100

Date Published: 2025-12-11

Date Updated: 2026-04-30

Author: Veronika Telychko

...
...

Microsoft's December 2025 Patch Tuesday fixed 57 vulnerabilities, notably two zero-days: CVE-2025-62221, an actively exploited use-after-free elevation-of-privilege in the Windows Cloud Files minifilter that can yield SYSTEM access (CISA added it to the KEV catalog), and CVE-2025-54100, a PowerShell parsing RCE that enables code execution via crafted commands and social engineering (no active exploitation reported). Organizations are urged to apply updates immediately and leverage detection content to identify exploitation attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.