Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitywidely-deployed-product-advisoryendpoint-software-vulnerabilityai-platform-security

Microsoft Patch Tuesday December 2025 Addresses Actively Exploited Zero-Days

Updated 3mo agoFirst seen Dec 10, 20252 sources

Microsoft released its December 2025 Patch Tuesday updates, addressing 57 security vulnerabilities across Windows 10, Windows 11, Windows Server, Office, and related services. Among these, three zero-day vulnerabilities were highlighted: CVE-2025-62221, an actively exploited privilege escalation flaw in the Windows Cloud Files Mini Filter Driver; CVE-2025-64671, a remote code execution vulnerability in GitHub Copilot for JetBrains; and CVE-2025-54100, a remote code execution issue in Windows PowerShell. The update also introduced a new warning in PowerShell to alert users when the Invoke-WebRequest command fetches web pages without safe parameters, aiming to prevent script-based attacks that exploit unsafe web content retrieval.

Throughout 2025, Microsoft addressed a total of 1,130 CVEs via Patch Tuesday releases, with 41 zero-day vulnerabilities patched, including 24 that were exploited in the wild. Elevation of Privilege and Remote Code Execution vulnerabilities made up the majority of the year's patches, reflecting ongoing attacker focus on these vectors. The December update continues Microsoft's trend of prioritizing critical and important vulnerabilities, reinforcing the need for organizations to promptly apply security updates to mitigate active threats.

Share:
Microsoft Patch Tuesday December 2025 Addresses Actively Exploited Zero-Days
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Dec 10, 20257mo ago

PowerShell adds warning for web-fetched scripts to counter ClickFix-style abuse

Microsoft introduced a new warning in PowerShell's Invoke-WebRequest command to reduce the risk of users accidentally executing malicious scripts fetched from the web, including techniques associated with ClickFix campaigns.

Microsoft patches three actively exploited zero-days in December

The December 2025 update fixed three zero-days under active exploitation: CVE-2025-62221, a privilege escalation flaw; CVE-2025-64671, a remote code execution bug in GitHub Copilot for JetBrains; and CVE-2025-54100, a remote code execution flaw in Windows PowerShell.

Microsoft releases December 2025 Patch Tuesday updates

On December 2025 Patch Tuesday, Microsoft released fixes for 57 vulnerabilities affecting Windows 10, Windows 11, Windows Server, Office, and related services.

Threat actors exploit major Microsoft zero-days during 2025

Notable 2025 exploitation included CVE-2025-24983 and CVE-2025-29824 in ransomware campaigns, CVE-2025-33053 used by Stealth Falcon to deploy malware, and coordinated SharePoint exploitation by Linen Typhoon, Violet Typhoon, and Storm-2603.

Microsoft fixes 41 zero-days during 2025, including 24 under active exploitation

Over the course of 2025, Microsoft patched 41 zero-day vulnerabilities, 24 of which were reported as actively exploited in the wild. Elevation of Privilege flaws were the most frequently exploited zero-days.

Microsoft patches 1,130 CVEs across 2025 Patch Tuesday releases

Throughout 2025, Microsoft addressed 1,130 vulnerabilities in its monthly Patch Tuesday updates, marking a 12% increase from 2024 and the second straight year with more than 1,000 CVEs patched.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.