Microsoft released its December 2025 Patch Tuesday updates, addressing 57 security vulnerabilities across its product suite, including three zero-day flaws. Among the most critical issues patched is CVE-2025-62221, an actively exploited elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver, which could allow attackers to gain SYSTEM privileges. The updates also include a fix for a remote code execution zero-day in PowerShell (CVE-2025-54100), which now prompts users with a security warning when using the Invoke-WebRequest command, and other critical vulnerabilities affecting Windows 10 and 11, as well as related server products. The updates are mandatory for supported systems, including those enrolled in the Extended Security Update (ESU) program, and require a system restart upon installation.
CISA has added CVE-2025-62221 to its Known Exploited Vulnerabilities Catalog, urging all organizations to prioritize remediation due to evidence of active exploitation. Security advisories and technical analyses from multiple sources highlight the importance of promptly applying these patches, as the vulnerabilities present significant risks for privilege escalation and remote code execution. The December update also marks the continued support for Windows 10 through ESU, with no new features introduced, focusing solely on security and bug fixes. Organizations are advised to review the full list of addressed CVEs and ensure all relevant systems are updated to mitigate potential threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On and after 2025-12-09, organizations including the Canadian Centre for Cyber Security and JPCERT/CC issued advisories highlighting active exploitation of CVE-2025-62221. They urged administrators to review Microsoft's guidance and prioritize deployment of the December security updates.
On 2025-12-09, CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2025-6218 in WinRAR and CVE-2025-62221 in Microsoft Windows. CISA directed federal civilian agencies to remediate them by the required deadline under Binding Operational Directive 22-01.
On 2025-12-09, Microsoft released Windows 10 ESU update KB5071546 for eligible Enterprise LTSC and ESU customers. The update addressed the December security vulnerabilities, including zero-days, and advanced systems to builds 19045.6691 or 19044.6691 depending on version.
On 2025-12-09, Microsoft published Windows 11 cumulative updates KB5072033 and KB5071417 for supported versions. The mandatory updates included security fixes, bug fixes, and feature improvements, and Microsoft said no optional December preview updates would be released because of the holiday period.
With the December 2025 security updates, Microsoft changed PowerShell 5.1 behavior so Invoke-WebRequest warns users and recommends the -UseBasicParsing switch. The change was introduced to reduce exploitation risk from the publicly disclosed PowerShell zero-day CVE-2025-54100.
As part of the 2025-12-09 release, Microsoft fixed critical Microsoft Office vulnerabilities CVE-2025-62554 and CVE-2025-62557. Multiple reports said these flaws could enable code execution through the Outlook Preview Pane or specially crafted emails, including low- or no-click attack scenarios.
On 2025-12-09, Microsoft released its December 2025 Patch Tuesday updates, fixing roughly 56-57 vulnerabilities across Windows, Office, PowerShell, Exchange, and other products. The release included three zero-days, with CVE-2025-62221 in the Windows Cloud Files Mini Filter Driver confirmed as actively exploited in the wild.
In November 2025, Microsoft released the first Windows 10 Extended Security Updates (ESU) and patched a Windows Kernel zero-day, CVE-2025-62215. Microsoft also issued out-of-band fixes for Windows Update, XAML-dependent apps, a .LNK vulnerability, and an Excel attachment issue in the new Outlook client.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
29 references tracked. Mallory keeps watching after this page renders.
redmondmag.com
Open sourcesecurityonline.info
Open sourcemsrc.microsoft.com
Open sourceoutpost24.com
Open sourcemsrc.microsoft.com
Open sourcekrebsonsecurity.com
Open sourcedarkreading.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.