BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Microsoft patches 63 vulnerabilities including zero-day exploit in Nov 2025 update

Microsoft releases patches for 63 vulnerabilities including a critical zero-day Windows Kernel flaw and updates from multiple major tech vendors

  • Microsoft issued patches for 63 security flaws, including one actively exploited.
  • The zero-day vulnerability CVE-2025-62215 allows local privilege escalation via a race condition in the Windows Kernel.
  • Critical remote code execution flaws were fixed in the Graphics Component and Windows Subsystem for Linux GUI.
  • A Kerberos privilege escalation flaw (CVE-2025-60704) enables attacker impersonation through an adversary-in-the-middle attack.
  • Multiple vendors, including Adobe, Cisco, and Google, released various security updates recently.

Microsoft released security patches on November 12, 2025, addressing 63 vulnerabilities in its software. These include one actively exploited zero-day flaw. Of the vulnerabilities, four are rated Critical and 59 Important, covering privilege escalation, remote code execution, information disclosure, denial-of-service, security feature bypass, and spoofing issues. These updates follow fixes for 27 vulnerabilities in the Chromium-based Edge browser since the October patch.

- Advertisement -

The exploited zero-day, identified as CVE-2025-62215 with a CVSS score of 7.0, is a local privilege escalation vulnerability in the Windows Kernel triggered by a race condition. Discovered by the Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC), it allows an attacker with existing local access to execute a specially crafted application to exploit unsynchronized access to shared kernel memory. According to Microsoft, this can elevate privileges to SYSTEM level.

Additional critical patches include two heap-based buffer overflow vulnerabilities permitting remote code execution. These affect the Microsoft Graphics Component (CVE-2025-60724, CVSS 9.8) and the Windows Subsystem for Linux GUI (CVE-2025-62220, CVSS 8.8).

Another notable update fixes a high-severity privilege escalation flaw in Windows Kerberos (CVE-2025-60704, CVSS 7.5), known as CheckSum by Silverfort. It results from a missing cryptographic step and allows attackers positioned between a user and requested resource to modify or read network communications. Microsoft states that an attacker requires the user to establish a connection to exploit this flaw. According to Silverfort, this attack can lead to domain-wide user impersonation and administrative control in Active Directory environments with Kerberos delegation enabled.

Several other technology providers have rolled out security updates recently. These include Adobe, Amazon Web Services, AMD, Apple, Cisco, Google, Intel, Lenovo, NVIDIA, and Oracle, among others. Various Linux distributions, such as Debian, Red Hat, and Ubuntu, have also published security advisories. Complete details on vendor patches are available on their respective security bulletin pages.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Fake Ledger App on Apple Store Steals $9.5M in Crypto

Apple removed a fraudulent Ledger wallet app after an investigation revealed it was used...

Alibaba’s Qwen Code Ends Free Tier, Points to Paid Options

Alibaba has discontinued the free tier for its Qwen Code AI coding assistant, directing...

Goldman Sachs: SEC Rule May Boost Robinhood Revenue

The SEC's approval of a new rule eliminating the $25,000 minimum for pattern day...

McLaren Racing joins Hedera governing council

McLaren Racing has officially joined the Hedera Council, signaling major institutional adoption for fan...

Trump Picks Pro-Crypto Kevin Warsh To Lead Fed

Donald Trump has nominated cryptocurrency investor Kevin Warsh to replace Jerome Powell as Federal...

Must Read

10 BEST Companies to Buy Hosting With Bitcoin And Crypto

If you are looking to buy hosting with bitcoin or cryptocurrency then you've come to the right place.I've done the research for you...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading