Microsoft Monthly Security Update (December 2025)
Release Date: 10 Dec 2025
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
Microsoft has released monthly security update for their products:
| Vulnerable Product | Risk Level | Impacts | Notes |
| Browser | Low Risk | Spoofing | |
| Windows | Medium Risk | Elevation of Privilege Remote Code Execution Information Disclosure Denial of Service | CVE-2025-62221 is being exploited in the wild.. This vulnerability exist in Windows Cloud Files Mini Filter Driver. Successful exploitation of this vulnerability could allow a local authorized attacker to elevate privileges on the affected system. Hence, the risk level of this vulnerability is rated as Medium Risk. |
| Extended Security Updates (ESU) | Medium Risk | Elevation of Privilege Information Disclosure Remote Code Execution Spoofing Denial of Service | |
| Microsoft Office | Medium Risk | Remote Code Execution Spoofing | |
| Server Software | Medium Risk | Spoofing Elevation of Privilege | |
| Azure | Medium Risk | Remote Code Execution | |
| Other | Medium Risk | Remote Code Execution |
Number of 'Extremely High Risk' product(s): 0
Number of 'High Risk' product(s): 0
Number of 'Medium Risk' product(s): 6
Number of 'Low Risk' product(s): 1
Evaluation of overall 'Risk Level': Medium Risk
Impact
- Remote Code Execution
- Denial of Service
- Information Disclosure
- Elevation of Privilege
- Spoofing
System / Technologies affected
- Azure
- Browser
- Extended Security Updates (ESU)
- Microsoft Office
- Server Software
- Windows
- Other
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Apply fixes issued by the vendor.


沒有留言:
發佈留言