Microsoft fixes over 50 flaws, including actively exploited zero-day

Microsoft has released its December 2025 Patch Tuesday updates, addressing 57 security vulnerabilities, including one actively exploited zero-day and two publicly disclosed flaws.

The actively exploited vulnerability is CVE-2025-62221 (Windows Cloud Files Mini Filter Driver Elevation of Privilege), a use-after-free issue that could allow an authorized attacker to gain SYSTEM-level privileges.

Microsoft has not disclosed details about how the flaw was used in the wild.

The two publicly disclosed flaws include CVE-2025-64671 (GitHub Copilot for JetBrains RCE) and CVE-2025-54100 (PowerShell RCE).

December 2025 Patch Tuesday also includes fixes for a number of high-risk security vulnerabilities affecting MS Office, Word, Exel, Outlook, Microsoft Access, Microsoft RRAS, and other products.

Back to the list

Latest Posts

Cyber Security Week in Review: January 16, 2026

In brief: Microsoft fixes a Windows zero-day flaw, Russian hackers target Ukraine posing as charities, and more.
16 January 2026

RedVDS cybercrime platform disrupted in global takedown

RedVDS sold access to disposable virtual Windows servers for as little as $24 a month, allowing criminals to run fraud and phishing operations at scale.
15 January 2026

Administrator of AVCheck malware testing service arrested in the Netherlands

The man is suspected of facilitating cybercrime by allowing malware devs to test whether their software could bypass antivirus protections.
15 January 2026