Close Menu
geekfence.comgeekfence.com
    What's Hot

    Russian Hackers Are Inside American Home Routers. The FBI Has a 5-Step Fix

    May 21, 2026

    6 ways to achieve high-speed internet at home

    May 21, 2026

    Should employees be worried that training AI tools could mean they teach the software how to do their jobs?

    May 21, 2026
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook Instagram
    geekfence.comgeekfence.com
    • Home
    • UK Tech News
    • AI
    • Big Data
    • Cyber Security
      • Cloud Computing
      • iOS Development
    • IoT
    • Mobile
    • Software
      • Software Development
      • Software Engineering
    • Technology
      • Green Technology
      • Nanotechnology
    • Telecom
    geekfence.comgeekfence.com
    Home»Cyber Security»Microsoft Patch Tuesday, December 2025 Edition – Krebs on Security
    Cyber Security

    Microsoft Patch Tuesday, December 2025 Edition – Krebs on Security

    AdminBy AdminDecember 12, 2025No Comments3 Mins Read11 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Microsoft Patch Tuesday, December 2025 Edition – Krebs on Security
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. This final Patch Tuesday of 2025 tackles one zero-day bug that is already being exploited, as well as two publicly disclosed vulnerabilities.

    Microsoft Patch Tuesday, December 2025 Edition – Krebs on Security

    Despite releasing a lower-than-normal number of security updates these past few months, Microsoft patched a whopping 1,129 vulnerabilities in 2025, an 11.9% increase from 2024. According to Satnam Narang at Tenable, this year marks the second consecutive year that Microsoft patched over one thousand vulnerabilities, and the third time it has done so since its inception.

    The zero-day flaw patched today is CVE-2025-62221, a privilege escalation vulnerability affecting Windows 10 and later editions. The weakness resides in a component called the “Windows Cloud Files Mini Filter Driver” — a system driver that enables cloud applications to access file system functionalities.

    “This is particularly concerning, as the mini filter is integral to services like OneDrive, Google Drive, and iCloud, and remains a core Windows component, even if none of those apps were installed,” said Adam Barnett, lead software engineer at Rapid7.

    Only three of the flaws patched today earned Microsoft’s most-dire “critical” rating: Both CVE-2025-62554 and CVE-2025-62557 involve Microsoft Office, and both can exploited merely by viewing a booby-trapped email message in the Preview Pane. Another critical bug — CVE-2025-62562 — involves Microsoft Outlook, although Redmond says the Preview Pane is not an attack vector with this one.

    But according to Microsoft, the vulnerabilities most likely to be exploited from this month’s patch batch are other (non-critical) privilege escalation bugs, including:

    –CVE-2025-62458 — Win32k
    –CVE-2025-62470 — Windows Common Log File System Driver
    –CVE-2025-62472 — Windows Remote Access Connection Manager
    –CVE-2025-59516 — Windows Storage VSP Driver
    –CVE-2025-59517 — Windows Storage VSP Driver

    Kev Breen, senior director of threat research at Immersive, said privilege escalation flaws are observed in almost every incident involving host compromises.

    “We don’t know why Microsoft has marked these specifically as more likely, but the majority of these components have historically been exploited in the wild or have enough technical detail on previous CVEs that it would be easier for threat actors to weaponize these,” Breen said. “Either way, while not actively being exploited, these should be patched sooner rather than later.”

    One of the more interesting vulnerabilities patched this month is CVE-2025-64671, a remote code execution flaw in the Github Copilot Plugin for Jetbrains AI-based coding assistant that is used by Microsoft and GitHub. Breen said this flaw would allow attackers to execute arbitrary code by tricking the large language model (LLM) into running commands that bypass the guardrails and add malicious instructions in the user’s “auto-approve” settings.

    CVE-2025-64671 is part of a broader, more systemic security crisis that security researcher Ari Marzuk has branded IDEsaster (IDE  stands for “integrated development environment”), which encompasses more than 30 separate vulnerabilities reported in nearly a dozen market-leading AI coding platforms, including Cursor, Windsurf, Gemini CLI, and Claude Code.

    The other publicly-disclosed vulnerability patched today is CVE-2025-54100, a remote code execution bug in Windows Powershell on Windows Server 2008 and later that allows an unauthenticated attacker to run code in the security context of the user.

    For anyone seeking a more granular breakdown of the security updates Microsoft pushed today, check out the roundup at the SANS Internet Storm Center. As always, please leave a note in the comments if you experience problems applying any of this month’s Windows patches.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Which Should You Wear at Night?

    May 21, 2026

    AI network performance with Cisco Intelligent Packet Flow

    May 20, 2026

    Suspected Dream Market kingpin arrested after gold bars sent to his home address

    May 19, 2026

    Grafana says stolen GitHub token let hackers steal codebase

    May 18, 2026

    NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

    May 17, 2026

    Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab – Krebs on Security

    May 16, 2026
    Top Posts

    Understanding U-Net Architecture in Deep Learning

    November 25, 202541 Views

    Hard-braking events as indicators of road segment crash risk

    January 14, 202629 Views

    Redefining AI efficiency with extreme compression

    March 25, 202627 Views
    Don't Miss

    Russian Hackers Are Inside American Home Routers. The FBI Has a 5-Step Fix

    May 21, 2026

    Most home routers sit in a corner, ignored, and that’s exactly what Russia’s military intelligence…

    6 ways to achieve high-speed internet at home

    May 21, 2026

    Should employees be worried that training AI tools could mean they teach the software how to do their jobs?

    May 21, 2026

    A systematic approach to benchmarking SQL processing engines on AWS

    May 21, 2026
    Stay In Touch
    • Facebook
    • Instagram
    About Us

    At GeekFence, we are a team of tech-enthusiasts, industry watchers and content creators who believe that technology isn’t just about gadgets—it’s about how innovation transforms our lives, work and society. We’ve come together to build a place where readers, thinkers and industry insiders can converge to explore what’s next in tech.

    Our Picks

    Russian Hackers Are Inside American Home Routers. The FBI Has a 5-Step Fix

    May 21, 2026

    6 ways to achieve high-speed internet at home

    May 21, 2026

    Subscribe to Updates

    Please enable JavaScript in your browser to complete this form.
    Loading
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 Geekfence.All Rigt Reserved.

    Type above and press Enter to search. Press Esc to cancel.