logo

Microsoft Fixes Three Zero-Days in Final Patch Tuesday of 2025

ID: 4fda0fe7-c180-5d10-aeae-db7ec091a19e

STIX ID: report--4fda0fe7-c180-5d10-aeae-db7ec091a19e

Feed Name: Infosecurity Magazine (News)

Threat Score
80/100

Date Published: 2025-12-10

Date Updated: 2026-04-22

...
...

Microsoft and other vendors released fixes for multiple high-severity vulnerabilities in their December patches, including an actively exploited Windows kernel elevation-of-privilege zero-day (CVE-2025-62221), publicly disclosed RCEs in PowerShell (CVE-2025-54100) and GitHub Copilot (CVE-2025-64671), plus critical Office/Outlook flaws and an Ivanti EPM stored XSS; administrators are urged to patch promptly due to the risk of escalation to full system and domain compromise when these flaws are chained with other access vectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.