Content area

Abstract

Microsoft had released an out-of-band update (KB5070881) for Windows Server 2025, which was briefly offered to all Windows Server 2025 machines, regardless of Hotpatch enrollment. Browsers (Microsoft Edge) Microsoft Windows (both desktop and server) Microsoft Office Microsoft Exchange and SQL Server Microsoft Developer Tools (Visual Studio and .NET) Adobe (if you get this far) Browsers Microsoft has released a single update to Microsoft Edge (CVE-2025-62223) and a further 13 Chromium-based updates with this December release. Windows Cloud Files Mini Filter, VSP, Brokering and Windows Resilient File System (ReFS) Win32k, DWM and DirectX Graphics Kernel Windows Common Log File System Windows Remote Access Connection Manager Windows Routing and Remote Access Service (RRAS) Windows Installer and PowerShell Microsoft Hyper-V Windows Shell and Camera codecs Unfortunately, we have three zero-days through reported exploitation and public disclosure (CVE-2025-64671, CVE-2025-54100, and CVE-2025-62221) that affect GitHub, PowerShell, and the Windows mini-driver, respectively.

Details

Company / organization
Title
Ho ho ho! December’s Patch Tuesday delivers three zero-days
Publication title
Computerworld.com; Framingham
Publication year
2025
Publication date
Dec 12, 2025
Section
Endpoint Protection, IT Operations, Microsoft, Security, Windows, Windows Security, Windows Server
Publisher
Foundry
Place of publication
Framingham
Country of publication
United States
Publication subject
Source type
Other Source
Language of publication
English
Document type
News
ProQuest document ID
3282898860
Document URL
https://www.proquest.com/other-sources/ho-december-s-patch-tuesday-delivers-three-zero/docview/3282898860/se-2?accountid=208611
Copyright
Copyright Foundry 2025
Last updated
2025-12-15
Database
ProQuest One Academic