Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitywidely-deployed-product-advisorygovernment-vulnerability-catalogendpoint-software-vulnerability

Microsoft December 2025 Patch Tuesday Addresses Zero-Days and 57 Vulnerabilities

Updated 3mo agoFirst seen Dec 9, 202529 sources

Microsoft released its December 2025 Patch Tuesday updates, addressing 57 security vulnerabilities across its product suite, including three zero-day flaws. Among the most critical issues patched is CVE-2025-62221, an actively exploited elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver, which could allow attackers to gain SYSTEM privileges. The updates also include a fix for a remote code execution zero-day in PowerShell (CVE-2025-54100), which now prompts users with a security warning when using the Invoke-WebRequest command, and other critical vulnerabilities affecting Windows 10 and 11, as well as related server products. The updates are mandatory for supported systems, including those enrolled in the Extended Security Update (ESU) program, and require a system restart upon installation.

CISA has added CVE-2025-62221 to its Known Exploited Vulnerabilities Catalog, urging all organizations to prioritize remediation due to evidence of active exploitation. Security advisories and technical analyses from multiple sources highlight the importance of promptly applying these patches, as the vulnerabilities present significant risks for privilege escalation and remote code execution. The December update also marks the continued support for Windows 10 through ESU, with no new features introduced, focusing solely on security and bug fixes. Organizations are advised to review the full list of addressed CVEs and ensure all relevant systems are updated to mitigate potential threats.

Share:
Microsoft December 2025 Patch Tuesday Addresses Zero-Days and 57 Vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Dec 9, 20257mo ago

National and industry advisories urge rapid patching of CVE-2025-62221

On and after 2025-12-09, organizations including the Canadian Centre for Cyber Security and JPCERT/CC issued advisories highlighting active exploitation of CVE-2025-62221. They urged administrators to review Microsoft's guidance and prioritize deployment of the December security updates.

CISA adds CVE-2025-6218 and CVE-2025-62221 to KEV catalog

On 2025-12-09, CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2025-6218 in WinRAR and CVE-2025-62221 in Microsoft Windows. CISA directed federal civilian agencies to remediate them by the required deadline under Binding Operational Directive 22-01.

Microsoft releases Windows 10 KB5071546 extended security update

On 2025-12-09, Microsoft released Windows 10 ESU update KB5071546 for eligible Enterprise LTSC and ESU customers. The update addressed the December security vulnerabilities, including zero-days, and advanced systems to builds 19045.6691 or 19044.6691 depending on version.

Microsoft releases Windows 11 December cumulative updates

On 2025-12-09, Microsoft published Windows 11 cumulative updates KB5072033 and KB5071417 for supported versions. The mandatory updates included security fixes, bug fixes, and feature improvements, and Microsoft said no optional December preview updates would be released because of the holiday period.

Microsoft updates PowerShell behavior to mitigate CVE-2025-54100

With the December 2025 security updates, Microsoft changed PowerShell 5.1 behavior so Invoke-WebRequest warns users and recommends the -UseBasicParsing switch. The change was introduced to reduce exploitation risk from the publicly disclosed PowerShell zero-day CVE-2025-54100.

Microsoft patches Office Preview Pane RCE flaws

As part of the 2025-12-09 release, Microsoft fixed critical Microsoft Office vulnerabilities CVE-2025-62554 and CVE-2025-62557. Multiple reports said these flaws could enable code execution through the Outlook Preview Pane or specially crafted emails, including low- or no-click attack scenarios.

Microsoft releases December 2025 Patch Tuesday security updates

On 2025-12-09, Microsoft released its December 2025 Patch Tuesday updates, fixing roughly 56-57 vulnerabilities across Windows, Office, PowerShell, Exchange, and other products. The release included three zero-days, with CVE-2025-62221 in the Windows Cloud Files Mini Filter Driver confirmed as actively exploited in the wild.

Nov 1, 20258mo ago

Microsoft's November Patch Tuesday introduces first Windows 10 ESU updates

In November 2025, Microsoft released the first Windows 10 Extended Security Updates (ESU) and patched a Windows Kernel zero-day, CVE-2025-62215. Microsoft also issued out-of-band fixes for Windows Update, XAML-dependent apps, a .LNK vulnerability, and an Excel attachment issue in the new Outlook client.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

68 LINKEDOpen in app
Vulnerabilities
27 linked
Windows Cloud Files Mini Filter Driver Use-After-Free Privilege EscalationWindows PowerShell Invoke-WebRequest Command Injection RCEGitHub Copilot for JetBrains Command Injection RCEMicrosoft Office Type Confusion Remote Code Execution VulnerabilityMicrosoft Office Use-After-Free Remote Code Execution VulnerabilityWin32kfull Out-of-Bounds Write Local Privilege EscalationElevation of Privilege in Windows Storage VSP DriverWindows Remote Access Connection Manager Elevation of Privilege VulnerabilityWindows Storage VSP Driver Elevation of Privilege VulnerabilityWindows Common Log File System Driver Elevation of Privilege VulnerabilityWindows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityElevation of Privilege in Windows Cloud Files Mini Filter DriverUse-After-Free RCE in Microsoft Office OutlookElevation of Privilege in Microsoft Exchange ServerMicrosoft Windows LNK File UI Misrepresentation Remote Code Execution VulnerabilityRARLAB WinRAR Directory Traversal Remote Code Execution VulnerabilityANSI escape sequence injection in Apache Tomcat log messagesWindows Kernel Elevation of Privilege Race ConditionRelative Path Traversal in Apache Tomcat RewriteValveRCE via deserialization in SAP jConnect (SDK for ASE)Code injection in SAP Solution Manager remote-enabled function moduleMicrosoft SharePoint Server Spoofing VulnerabilityRCE in Windows Routing and Remote Access Service (RRAS)Remote Code Execution in Windows Resilient File System (ReFS)Remote Code Execution in Windows Routing and Remote Access Service (RRAS)Remote Code Execution in Azure Monitor AgentSpoofing in Microsoft Exchange Server UI
Affected products
12 linked
Microsoft OfficeWindows ServerAdobe Experience ManagerWindowsPowershellAzureAdobe ReaderAzure Monitor AgentChromiumChromiumChromiumChromium
Organizations
29 linked
Microsoft CorporationGitHubJetbrainsCISAGoogleArctic WolfAppleJapan Computer Emergency Response Team Coordination CenterOutpost24SecPodTenableAdobeTrend MicroSAPAction1ImmersiveRarlabMozillaRapid7ACROS SecurityASUSMulti-State Information Sharing and Analysis CenterFortinetIvantiCanadian Centre for Cyber SecurityFortraOnapsisNuance CommunicationsReact
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.