Microsoft security patch release for CVE-2025-62221
Security Patch Release
Summary
Hide ▲
Show ▼
Microsoft's December 2025 Patch Tuesday fixes 57 flaws, including CVE-2025-62221 and two publicly disclosed zero-days, reducing exposure to local privilege escalation and code execution. The release covers Windows Cloud Files Mini Filter Driver, GitHub Copilot for JetBrains, and PowerShell. Microsoft says the Windows flaw was actively exploited and could grant SYSTEM privileges. The bulletin also includes three Critical remote code execution vulnerabilities.
Related Happenings
Microsoft security patch release for CVE-2026-45659
Security Patch Release
First: 26.05.2026 14:49
Last: 26.05.2026 14:49
Sources 1
About this happening:
Microsoft released **SharePoint** updates for **CVE-2026-45659**, a **remote code execution** flaw that could let an authenticated attacker run code over the network without eleva...
Microsoft security patch release for CVE-2026-45659
Security Patch ReleaseAbout this happening: Microsoft released **SharePoint** updates for **CVE-2026-45659**, a **remote code execution** flaw that could let an authenticated attacker run code over the network without eleva...
Microsoft MDASH enters limited private preview for AI-driven vulnerability discovery at scale
Security Tool/Service
First: 13.05.2026 16:46
Last: 13.05.2026 16:46
Sources 1
About this happening:
Microsoft's **MDASH** has entered **limited private preview**, adding a new **AI-driven vulnerability discovery** service that can validate and prove exploitable defects at scale....
Microsoft MDASH enters limited private preview for AI-driven vulnerability discovery at scale
Security Tool/ServiceAbout this happening: Microsoft's **MDASH** has entered **limited private preview**, adding a new **AI-driven vulnerability discovery** service that can validate and prove exploitable defects at scale....
Microsoft May 2026 Patch Tuesday release
Security Patch Release
First: 13.05.2026 13:36
Last: 13.05.2026 13:36
Sources 1
About this happening:
Microsoft's **May 13, 2026 Patch Tuesday** release fixed **138 vulnerabilities** across its product portfolio, including **Windows**, **Azure**, and **Edge**. None of the flaws we...
Microsoft May 2026 Patch Tuesday release
Security Patch ReleaseAbout this happening: Microsoft's **May 13, 2026 Patch Tuesday** release fixed **138 vulnerabilities** across its product portfolio, including **Windows**, **Azure**, and **Edge**. None of the flaws we...
Microsoft Windows 11 mandatory Patch Tuesday updates (KB5089549, KB5087420)
Security Patch Release
First: 12.05.2026 21:09
Last: 12.05.2026 21:09
Sources 1
About this happening:
Microsoft released **mandatory Windows 11 cumulative updates** for **KB5089549** and **KB5087420**, delivering the **May 2026 Patch Tuesday** fixes for **120 vulnerabilities** acr...
Microsoft Windows 11 mandatory Patch Tuesday updates (KB5089549, KB5087420)
Security Patch ReleaseAbout this happening: Microsoft released **mandatory Windows 11 cumulative updates** for **KB5089549** and **KB5087420**, delivering the **May 2026 Patch Tuesday** fixes for **120 vulnerabilities** acr...
Microsoft May 2026 Patch Tuesday (120 flaws)
Security Patch Release
First: 12.05.2026 21:08
Last: 12.05.2026 21:08
Sources 1
About this happening:
**Microsoft** released its **May 2026 Patch Tuesday** updates, fixing **120 flaws** and disclosing **no zero-days**. The bundle includes **17 Critical** vulnerabilities, with mult...
Microsoft May 2026 Patch Tuesday (120 flaws)
Security Patch ReleaseAbout this happening: **Microsoft** released its **May 2026 Patch Tuesday** updates, fixing **120 flaws** and disclosing **no zero-days**. The bundle includes **17 Critical** vulnerabilities, with mult...
Timeline
-
09.12.2025 20:38 2 articles · 5mo ago
Microsoft December 2025 Patch Tuesday release
Initial DisclosureMicrosoft's December 2025 Patch Tuesday resolves 57 flaws, including CVE-2025-62221, an actively exploited Windows Cloud Files Mini Filter Driver elevation-of-privilege vulnerability, and two publicly disclosed zero-days, CVE-2025-64671 in GitHub Copilot for Jetbrains and CVE-2025-54100 in PowerShell.
Show sources
- Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws — www.bleepingcomputer.com — 09.12.2025 20:38
- Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws — www.bleepingcomputer.com — 09.12.2025 20:38
-
09.12.2025 20:38 1 articles · 5mo ago
Technical details for the December 2025 zero-days
Technical Analysis UpdateMicrosoft says CVE-2025-62221 in Windows Cloud Files Mini Filter Driver is a use-after-free that lets an authorized attacker elevate privileges locally to SYSTEM, CVE-2025-64671 in GitHub Copilot for Jetbrains can be abused through malicious Cross Prompt Injection in untrusted files or MCP servers to execute additional commands locally, and CVE-2025-54100 in PowerShell can run script code when Invoke-WebRequest retrieves web content unless -UseBasicParsing is used.
Show sources
- Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws — www.bleepingcomputer.com — 09.12.2025 20:38