{"id":9064,"date":"2025-12-10T04:04:06","date_gmt":"2025-12-10T04:04:06","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/10\/32550\/"},"modified":"2025-12-10T04:04:06","modified_gmt":"2025-12-10T04:04:06","slug":"32550","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/10\/32550\/","title":{"rendered":"Microsoft Patch Tuesday December 2025, (Tue, Dec 9th)"},"content":{"rendered":"<p>    Microsoft Patch Tuesday December 2025, (Tue, Dec 9th)<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>This release addresses 57 vulnerabilities. 3 of these vulnerabilities are rated critical. One vulnerability was already exploited, and two were publicly disclosed before the patch was released.<\/p>\n<p>CVE-2025-62221: This privilege escalation vulnerability in the Microsoft Cloud Files Mini Filters driver is already being exploited.<\/p>\n<p>CVE-2025-54100: A PowerShell script using\u00a0Invoke-WebRequest may execute scripts that are included in the response. This is what Invoke-WebRequest is supposed to do. The patch adds a warning suggesting adding the\u00a0-UseBasicParsing parameter to avoid executing scripts.<\/p>\n<p>CVE-2025-64671: The GitHub Copilot plugin for JetBrains may lead to remote code execution. This is overall an issue with many AI code assistance as they have far-reaching access to the IDE.<\/p>\n<p>The critical vulnerabilities are remote code execution vulnerabilities in Office and Outlook.<\/p>\n<p>\u00a0<\/p>\n<table class=\"msfttable\">\n<thead class=\"msftthead\">\n<tr>\n<th colspan=\"8\">Description<\/th>\n<\/tr>\n<tr>\n<th>CVE<\/th>\n<th>Disclosed<\/th>\n<th>Exploited<\/th>\n<th>Exploitability (old versions)<\/th>\n<th>current version<\/th>\n<th>Severity<\/th>\n<th>CVSS Base (AVG)<\/th>\n<th>CVSS Temporal (AVG)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td colspan=\"8\">Application Information Service Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62572%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Azure Monitor Agent Remote Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62550%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>8.8<\/td>\n<td>7.7<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">DirectX Graphics Kernel Denial of Service Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62463%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>6.5<\/td>\n<td>5.7<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62465%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>6.5<\/td>\n<td>5.7<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">DirectX Graphics Kernel Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62573%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.0<\/td>\n<td>6.1<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">GitHub Copilot for Jetbrains Remote Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-64671%%<\/td>\n<td class=\"msftyes\">Yes<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>8.4<\/td>\n<td>7.3<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Microsoft Access Remote Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62552%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Microsoft Brokering File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62469%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.0<\/td>\n<td>6.1<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62569%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.0<\/td>\n<td>6.1<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Microsoft Edge (Chromium-based) for Mac Spoofing Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62223%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftlow\">Low<\/td>\n<td>4.3<\/td>\n<td>3.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Microsoft Excel Remote Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62561%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62563%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62564%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62553%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62556%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62560%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Microsoft Exchange Server Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-64666%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.5<\/td>\n<td>6.5<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Microsoft Exchange Server Spoofing Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-64667%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>5.3<\/td>\n<td>4.6<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62455%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Microsoft Office Remote Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62554%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftcritical\">Critical<\/td>\n<td>8.4<\/td>\n<td>7.3<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62557%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftcritical\">Critical<\/td>\n<td>8.4<\/td>\n<td>7.3<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Microsoft Outlook Remote Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62562%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftcritical\">Critical<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Microsoft SharePoint Server Spoofing Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-64672%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>8.8<\/td>\n<td>7.7<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Microsoft Word Remote Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62555%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.0<\/td>\n<td>6.1<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62558%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62559%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">PowerShell Remote Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-54100%%<\/td>\n<td class=\"msftyes\">Yes<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Win32k Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62458%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Camera Frame Server Monitor Information Disclosure Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62570%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.1<\/td>\n<td>6.2<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Client-Side Caching Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62466%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62454%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62457%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62221%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftyes\">Yes<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Common Log File System Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62470%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows DWM Core Library Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-64679%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-64680%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Defender Firewall Service Information Disclosure Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62468%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>4.4<\/td>\n<td>3.9<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows DirectX Information Disclosure Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-64670%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>6.5<\/td>\n<td>5.7<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows File Explorer Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-64658%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.5<\/td>\n<td>6.5<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62565%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.3<\/td>\n<td>6.4<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Hyper-V Denial of Service Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62567%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>5.3<\/td>\n<td>4.6<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Installer Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62571%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Projected File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62461%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62462%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62464%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-55233%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62467%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Remote Access Connection Manager Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62472%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62474%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Resilient File System (ReFS) Remote Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62456%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>8.8<\/td>\n<td>7.7<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62473%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>6.5<\/td>\n<td>5.7<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-62549%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>8.8<\/td>\n<td>7.7<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-64678%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>8.8<\/td>\n<td>7.7<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Shell Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-64661%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\">Windows Storage VSP Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-64673%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-59516%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<tr>\n<td>%%cve:2025-59517%%<\/td>\n<td class=\"msftno\">No<\/td>\n<td class=\"msftno\">No<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td class=\"msftimportant\">Important<\/td>\n<td>7.8<\/td>\n<td>6.8<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&#8212;<br \/>\nJohannes B. Ullrich, Ph.D. , Dean of Research, <a href=\"https:\/\/sans.edu\/\">SANS.edu<\/a><br \/>\n<a href=\"https:\/\/jbu.me\/164\">Twitter<\/a>|<\/p>\n<p> (c) SANS Internet Storm Center. https:\/\/isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.<\/p><\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><\/p>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/isc.sans.edu\/diary\/rss\/32550\">Go to isc.sans.edu<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Patch Tuesday December 2025, (Tue, Dec 9th) This release addresses 57 vulnerabilities. 3 of these vulnerabilities are rated critical. One vulnerability was already exploited, and two were publicly disclosed before the patch was released. CVE-2025-62221: This privilege escalation vulnerability in the Microsoft Cloud Files Mini Filters driver is already being exploited. CVE-2025-54100: A PowerShell [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[69],"class_list":["post-9064","post","type-post","status-publish","format-standard","hentry","category-isc-sans-edu","tag-isc-sans-edu"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9064"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9064"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9064\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9064"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}