Loading cryptocurrency prices...

Microsoft patches 63 vulnerabilities including zero-day exploit in Nov 2025 update

Microsoft releases patches for 63 vulnerabilities including a critical zero-day Windows Kernel flaw and updates from multiple major tech vendors

  • Microsoft issued patches for 63 security flaws, including one actively exploited.
  • The zero-day vulnerability CVE-2025-62215 allows local privilege escalation via a race condition in the Windows Kernel.
  • Critical remote code execution flaws were fixed in the Graphics Component and Windows Subsystem for Linux GUI.
  • A Kerberos privilege escalation flaw (CVE-2025-60704) enables attacker impersonation through an adversary-in-the-middle attack.
  • Multiple vendors, including Adobe, Cisco, and Google, released various security updates recently.

Microsoft released security patches on November 12, 2025, addressing 63 vulnerabilities in its software. These include one actively exploited zero-day flaw. Of the vulnerabilities, four are rated Critical and 59 Important, covering privilege escalation, remote code execution, information disclosure, denial-of-service, security feature bypass, and spoofing issues. These updates follow fixes for 27 vulnerabilities in the Chromium-based Edge browser since the October patch.

- Advertisement -

The exploited zero-day, identified as CVE-2025-62215 with a CVSS score of 7.0, is a local privilege escalation vulnerability in the Windows Kernel triggered by a race condition. Discovered by the Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC), it allows an attacker with existing local access to execute a specially crafted application to exploit unsynchronized access to shared kernel memory. According to Microsoft, this can elevate privileges to SYSTEM level.

Additional critical patches include two heap-based buffer overflow vulnerabilities permitting remote code execution. These affect the Microsoft Graphics Component (CVE-2025-60724, CVSS 9.8) and the Windows Subsystem for Linux GUI (CVE-2025-62220, CVSS 8.8).

Another notable update fixes a high-severity privilege escalation flaw in Windows Kerberos (CVE-2025-60704, CVSS 7.5), known as CheckSum by Silverfort. It results from a missing cryptographic step and allows attackers positioned between a user and requested resource to modify or read network communications. Microsoft states that an attacker requires the user to establish a connection to exploit this flaw. According to Silverfort, this attack can lead to domain-wide user impersonation and administrative control in Active Directory environments with Kerberos delegation enabled.

Several other technology providers have rolled out security updates recently. These include Adobe, Amazon Web Services, AMD, Apple, Cisco, Google, Intel, Lenovo, NVIDIA, and Oracle, among others. Various Linux distributions, such as Debian, Red Hat, and Ubuntu, have also published security advisories. Complete details on vendor patches are available on their respective security bulletin pages.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Clear Street Prepares $10B-$12B Crypto IPO Led by Goldman Sachs

Clear Street, a New York brokerage, plans a public offering with a valuation between...

BRICS Expands Gold Pact to 33 Nations, Boosts Dollar-Free Trade

The BRICS Gold pact now includes 33 countries aiming to trade precious metals independently...

Bitcoin Treasury Firms Face “Darwinian Phase” Amid Market Downturn

Bitcoin treasury companies face structural challenges as equity prices drop below Bitcoin net asset...

Shiba Inu Whale Withdraws 169B SHIB from Coinbase Sparking Speculation

A whale withdrew 169.13 billion SHIB tokens from Coinbase in six transfers over 17...

Crypto Firms Raise $16M for Hong Kong Tai Po Fire Relief Efforts

Over 30 cryptocurrency firms and fundraising groups have contributed about $16 million to Hong...
- Advertisement -

Must Read

Sushiswap vs Uniswap, What are the differences between these dex?

It's no secret that the world of decentralized exchanges has exploded in recent years. Many of you are probably wondering what the difference is...