Microsoft Fixes Three Zero-Days in Final Patch Tuesday of 2025
ID: 4fda0fe7-c180-5d10-aeae-db7ec091a19e
STIX ID: report--4fda0fe7-c180-5d10-aeae-db7ec091a19e
Feed Name: Infosecurity Magazine (News)
Microsoft and other vendors released fixes for multiple high-severity vulnerabilities in their December patches, including an actively exploited Windows kernel elevation-of-privilege zero-day (CVE-2025-62221), publicly disclosed RCEs in PowerShell (CVE-2025-54100) and GitHub Copilot (CVE-2025-64671), plus critical Office/Outlook flaws and an Ivanti EPM stored XSS; administrators are urged to patch promptly due to the risk of escalation to full system and domain compromise when these flaws are chained with other access vectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
