Close Menu
    What's Hot

    Inside one London founder house rewriting the founder-house rules 

    Senior Open: Jerry Kelly wins title at Gleneagles as Scotland’s Stephen Gallacher produces round of final day | Golf News

    Forced to Evacuate Amid Spain Wildfires, Residents Wonder if Their Homes Still Stand

    Facebook X (Twitter) Instagram
    Trending
    • Inside one London founder house rewriting the founder-house rules 
    • Senior Open: Jerry Kelly wins title at Gleneagles as Scotland’s Stephen Gallacher produces round of final day | Golf News
    • Forced to Evacuate Amid Spain Wildfires, Residents Wonder if Their Homes Still Stand
    • The Next Fed Rate Hike May Be Coming Soon
    • How Republicans plan to conquer Troy Jackson
    • The Best Motorola Phones, From Razr to Moto G (2026)
    • The Hundred: London Spirit beat Trent Rockets as South African duo Marizanne Kapp and Nadine de Klerk star in Nottingham | Cricket News
    • TechCrunch Mobility: Uber bets on its former CEO
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Microsoft Patch Tuesday, December 2025 Edition – Krebs on Security

    adminBy adminFebruary 12, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Microsoft Patch Tuesday, December 2025 Edition – Krebs on Security
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. This final Patch Tuesday of 2025 tackles one zero-day bug that is already being exploited, as well as two publicly disclosed vulnerabilities.

    Microsoft Patch Tuesday, December 2025 Edition – Krebs on Security

    Despite releasing a lower-than-normal number of security updates these past few months, Microsoft patched a whopping 1,129 vulnerabilities in 2025, an 11.9% increase from 2024. According to Satnam Narang at Tenable, this year marks the second consecutive year that Microsoft patched over one thousand vulnerabilities, and the third time it has done so since its inception.

    The zero-day flaw patched today is CVE-2025-62221, a privilege escalation vulnerability affecting Windows 10 and later editions. The weakness resides in a component called the “Windows Cloud Files Mini Filter Driver” — a system driver that enables cloud applications to access file system functionalities.

    “This is particularly concerning, as the mini filter is integral to services like OneDrive, Google Drive, and iCloud, and remains a core Windows component, even if none of those apps were installed,” said Adam Barnett, lead software engineer at Rapid7.

    Only three of the flaws patched today earned Microsoft’s most-dire “critical” rating: Both CVE-2025-62554 and CVE-2025-62557 involve Microsoft Office, and both can exploited merely by viewing a booby-trapped email message in the Preview Pane. Another critical bug — CVE-2025-62562 — involves Microsoft Outlook, although Redmond says the Preview Pane is not an attack vector with this one.

    But according to Microsoft, the vulnerabilities most likely to be exploited from this month’s patch batch are other (non-critical) privilege escalation bugs, including:

    –CVE-2025-62458 — Win32k
    –CVE-2025-62470 — Windows Common Log File System Driver
    –CVE-2025-62472 — Windows Remote Access Connection Manager
    –CVE-2025-59516 — Windows Storage VSP Driver
    –CVE-2025-59517 — Windows Storage VSP Driver

    Kev Breen, senior director of threat research at Immersive, said privilege escalation flaws are observed in almost every incident involving host compromises.

    “We don’t know why Microsoft has marked these specifically as more likely, but the majority of these components have historically been exploited in the wild or have enough technical detail on previous CVEs that it would be easier for threat actors to weaponize these,” Breen said. “Either way, while not actively being exploited, these should be patched sooner rather than later.”

    One of the more interesting vulnerabilities patched this month is CVE-2025-64671, a remote code execution flaw in the Github Copilot Plugin for Jetbrains AI-based coding assistant that is used by Microsoft and GitHub. Breen said this flaw would allow attackers to execute arbitrary code by tricking the large language model (LLM) into running commands that bypass the user’s “auto-approve” settings.

    CVE-2025-64671 is part of a broader, more systemic security crisis that security researcher Ari Marzuk has branded IDEsaster (IDE  stands for “integrated development environment”), which encompasses more than 30 separate vulnerabilities reported in nearly a dozen market-leading AI coding platforms, including Cursor, Windsurf, Gemini CLI, and Claude Code.

    The other publicly-disclosed vulnerability patched today is CVE-2025-54100, a remote code execution bug in Windows Powershell on Windows Server 2008 and later that allows an unauthenticated attacker to run code in the security context of the user.

    For anyone seeking a more granular breakdown of the security updates Microsoft pushed today, check out the roundup at the SANS Internet Storm Center. As always, please leave a note in the comments if you experience problems applying any of this month’s Windows patches.

    December Edition Krebs Microsoft Patch Security Tuesday
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleYou be the judge: should my wife stop leaving piles of clothes all over the bedroom? | Life and style
    Next Article Breakneck data center growth challenges Microsoft’s sustainability goals
    admin
    • Website

    Related Posts

    Microsoft: One Of The Best Buying Opportunities In Big Tech (NASDAQ:MSFT)

    July 26, 2026

    Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

    July 25, 2026

    DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

    July 25, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Inside one London founder house rewriting the founder-house rules 

    Senior Open: Jerry Kelly wins title at Gleneagles as Scotland’s Stephen Gallacher produces round of final day | Golf News

    Forced to Evacuate Amid Spain Wildfires, Residents Wonder if Their Homes Still Stand

    The Next Fed Rate Hike May Be Coming Soon

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by