Microsoft Patch Tuesday December 2025 Addresses Actively Exploited Zero-Days
Microsoft released its December 2025 Patch Tuesday updates, addressing 57 security vulnerabilities across Windows 10, Windows 11, Windows Server, Office, and related services. Among these, three zero-day vulnerabilities were highlighted: CVE-2025-62221, an actively exploited privilege escalation flaw in the Windows Cloud Files Mini Filter Driver; CVE-2025-64671, a remote code execution vulnerability in GitHub Copilot for JetBrains; and CVE-2025-54100, a remote code execution issue in Windows PowerShell. The update also introduced a new warning in PowerShell to alert users when the Invoke-WebRequest command fetches web pages without safe parameters, aiming to prevent script-based attacks that exploit unsafe web content retrieval.
Throughout 2025, Microsoft addressed a total of 1,130 CVEs via Patch Tuesday releases, with 41 zero-day vulnerabilities patched, including 24 that were exploited in the wild. Elevation of Privilege and Remote Code Execution vulnerabilities made up the majority of the year's patches, reflecting ongoing attacker focus on these vectors. The December update continues Microsoft's trend of prioritizing critical and important vulnerabilities, reinforcing the need for organizations to promptly apply security updates to mitigate active threats.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
6 events from the most recent confirmed update back to the earliest known activity.
PowerShell adds warning for web-fetched scripts to counter ClickFix-style abuse
Microsoft introduced a new warning in PowerShell's Invoke-WebRequest command to reduce the risk of users accidentally executing malicious scripts fetched from the web, including techniques associated with ClickFix campaigns.
Microsoft patches three actively exploited zero-days in December
The December 2025 update fixed three zero-days under active exploitation: CVE-2025-62221, a privilege escalation flaw; CVE-2025-64671, a remote code execution bug in GitHub Copilot for JetBrains; and CVE-2025-54100, a remote code execution flaw in Windows PowerShell.
Microsoft releases December 2025 Patch Tuesday updates
On December 2025 Patch Tuesday, Microsoft released fixes for 57 vulnerabilities affecting Windows 10, Windows 11, Windows Server, Office, and related services.
Threat actors exploit major Microsoft zero-days during 2025
Notable 2025 exploitation included CVE-2025-24983 and CVE-2025-29824 in ransomware campaigns, CVE-2025-33053 used by Stealth Falcon to deploy malware, and coordinated SharePoint exploitation by Linen Typhoon, Violet Typhoon, and Storm-2603.
Microsoft fixes 41 zero-days during 2025, including 24 under active exploitation
Over the course of 2025, Microsoft patched 41 zero-day vulnerabilities, 24 of which were reported as actively exploited in the wild. Elevation of Privilege flaws were the most frequently exploited zero-days.
Microsoft patches 1,130 CVEs across 2025 Patch Tuesday releases
Throughout 2025, Microsoft addressed 1,130 vulnerabilities in its monthly Patch Tuesday updates, marking a 12% increase from 2024 and the second straight year with more than 1,000 CVEs patched.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


