logo

December Patch Tuesday fixes three zero-days, including one that hijacks Windows devices

ID: abbedfef-0b11-5f27-b493-f818fab95e97

STIX ID: report--abbedfef-0b11-5f27-b493-f818fab95e97

Feed Name: Malwarebytes Blog

Threat Score
80/100

Date Published: 2025-12-10

Date Updated: 2026-04-28

...
...

Microsoft's Patch Tuesday updates address 57 vulnerabilities across Windows, Office, and related services, including an actively exploited Windows privilege-escalation zero-day (CVE-2025-62221) and two publicly disclosed remote code execution issues (CVE-2025-64671, CVE-2025-54100); PowerShell will now warn when Invoke-WebRequest fetches pages without safe parameters to reduce accidental script execution, and users are advised to apply the updates immediately following the provided steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.