logo

November 2025 Patch Tuesday: One Zero-Day and Five Critical Vulnerabilities Among 63 CVEs

ID: 2d9ea39f-9ac3-59f4-831d-7d121457bd4e

STIX ID: report--2d9ea39f-9ac3-59f4-831d-7d121457bd4e

Feed Name: Crowdstrike Blog

Threat Score
78/100

Date Published: 2025-11-12

Date Updated: 2026-04-27

Author: Falcon Exposure Management Team

...
...

This report summarizes multiple high-severity vulnerabilities disclosed in a Patch Tuesday bulletin, notably an actively exploited Windows kernel zero-day (CVE-2025-62215) enabling local privilege escalation to SYSTEM, a critical remote code execution flaw in GDI+ (CVE-2025-60724), and additional critical issues in Microsoft Office, DirectX, Visual Studio, and Nuance PowerScribe; it provides CVSS scores, exploitation characteristics, affected versions, and recommends mitigation and patch prioritization using the CrowdStrike Falcon platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.