Microsoft released security updates addressing 63 vulnerabilities as part of its November 2025 Patch Tuesday, including five rated as critical and one zero-day vulnerability actively exploited in the wild. The zero-day, tracked as CVE-2025-62215, is a Windows Kernel elevation of privilege flaw that allows a local, authenticated attacker to gain higher privileges due to a race condition. Other critical vulnerabilities include remote code execution issues in GDI+, Microsoft Office, and Visual Studio, as well as an elevation of privilege vulnerability in the DirectX Graphics Kernel. The GDI+ vulnerability (CVE-2025-60724) is particularly notable for its high CVSS score and the potential for exploitation via specially crafted metafiles, which could be triggered through documents or web services without user interaction.
Security researchers note that while the number of vulnerabilities is significant, the overall risk profile is considered moderate, with no "Patch Now" emergencies aside from the actively exploited zero-day. The update also marks the first extended security update (ESU) for Windows 10, with Microsoft urging organizations still using the unsupported OS to upgrade or enroll in the ESU program. The vulnerabilities span a wide range of Microsoft products and services, including Azure, Dynamics 365, Visual Studio, and various Windows components, emphasizing the need for comprehensive patch management across enterprise environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
By 2025-11-12, organizations such as the Canadian Centre for Cyber Security and CIS, along with numerous security outlets, had issued advisories summarizing the November Microsoft fixes and recommending rapid deployment. Their notices emphasized the risk posed by the actively exploited kernel flaw and other critical vulnerabilities.
On and immediately after release day, multiple security firms and researchers including Talos, ZDI, CrowdStrike, Arctic Wolf, Qualys, and others published reviews of the November 2025 updates. These analyses highlighted the zero-day, identified other critical vulnerabilities, and in some cases provided defensive guidance such as Snort coverage and prioritization recommendations.
Microsoft also patched CVE-2025-60724, a high-severity heap-based buffer overflow in the Windows Graphics Component/GDI+ that could enable remote code execution, including through malicious files or crafted metafiles in documents. Multiple sources highlighted it as one of the most dangerous bugs in the November release.
The November 2025 updates fixed CVE-2025-62215, a Windows Kernel elevation-of-privilege vulnerability caused by a race condition that can let an attacker gain SYSTEM privileges. Microsoft reported the flaw as actively exploited in the wild at the time of patching.
On 2025-11-11, Microsoft issued its November 2025 Patch Tuesday security updates, with most sources reporting fixes for 63 vulnerabilities across Windows, Office, .NET, developer tools, and other products. The release also marked one of the first major monthly security rollups after Windows 10 entered its Extended Security Update phase.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
28 references tracked. Mallory keeps watching after this page renders.
krebsonsecurity.com
Open sourcewindowsforum.com
Open sourcemalwarebytes.com
Open sourcezdnet.com
Open sourcecsoonline.com
Open sourceisc.sans.edu
Open sourcebleepingcomputer.com
Open sourcequalys.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.