Cyber Security News

Microsoft November 2025 Patch Tuesday – 63 Vulnerabilities, Including 1 Zero-Day Fixed

Microsoft rolled out its November 2025 Patch Tuesday security updates today, addressing 63 vulnerabilities across its product and service ecosystem.

Among these, one zero-day flaw has already been exploited in the wild, underscoring the urgency for organizations and users to apply patches promptly to mitigate potential threats.

The updates cover Windows, Office, Azure, Visual Studio, and other components, with a focus on remote code execution (RCE) and elevation of privilege (EoP) issues that could allow attackers to compromise systems.

ImpactCount
Elevation of Privilege29
Remote Code Execution16
Information Disclosure11
Denial of Service3
Spoofing2
Security Feature Bypass2

The key concern is CVE-2025-62215, a Windows Kernel Elevation of Privilege vulnerability rated as Important, with confirmed exploitation.

This race condition flaw enables an authorized local attacker to escalate privileges by exploiting improper synchronization in shared resources.

Microsoft notes that exploitation is more likely due to its active use, potentially allowing threat actors to gain higher access on affected Windows systems. No workaround exists beyond installing the update, and experts recommend immediate deployment on all supported versions, including Windows 10, 11, and Server editions.

Critical vulnerabilities dominate the release, with five rated as such. Leading the pack is CVE-2025-62199, a use-after-free bug in Microsoft Office leading to RCE, where an unauthorized attacker could execute code locally via malicious documents.

Exploitation is deemed less likely, but its critical severity warrants priority patching for Office users. Similarly, CVE-2025-60716 in Windows DirectX involves a use-after-free error, allowing local privilege escalation to critical levels.

Another high-impact issue, CVE-2025-60724, is a heap-based buffer overflow in GDI+ that permits remote code execution over networks, posing risks to graphics-dependent applications.

CVE-2025-62214 affects Visual Studio with command injection for local RCE, while CVE-2025-30398 in Nuance PowerScribe 360 exposes sensitive information via missing authorization, all released on November 11, 2025.

The bulk of the patches, 57, rated Important target elevation of privilege flaws, which comprised over half the vulnerabilities. Notable examples include CVE-2025-59505 (double free in Windows Smart Card), CVE-2025-60704 (missing crypto in Kerberos for network-based EoP), and CVE-2025-60719 (untrusted pointer in WinSock driver).

Information disclosure issues, like CVE-2025-59509 in Windows Speech Recognition, and denial-of-service bugs, such as CVE-2025-59510 in RRAS, round out the list.

Azure components aren’t spared, with CVE-2025-59504 offering local RCE in the Monitor Agent via buffer overflow. Dynamics 365 sees spoofing via XSS in CVE-2025-62210 and CVE-2025-62211.

CVE IDProduct/ComponentDescriptionImpact
CVE-2025-62199Microsoft OfficeUse after free in Microsoft Office allows an unauthorized attacker to execute code locally.Remote Code Execution
CVE-2025-60716DirectX Graphics KernelUse after free in Windows DirectX allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-60724GDI+Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.Remote Code Execution
CVE-2025-62214Visual StudioImproper neutralization of special elements used in a command (‘command injection’) in Visual Studio allows an authorized attacker to execute code locally.Remote Code Execution
CVE-2025-30398Nuance PowerScribe 360Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.Information Disclosure
CVE-2025-59504Azure Monitor AgentHeap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.Remote Code Execution
CVE-2025-59505Windows Smart Card ReaderDouble free in Windows Smart Card allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-59506DirectX Graphics KernelConcurrent execution using shared resource with improper synchronization (‘race condition’) in Windows DirectX allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-59507Windows Speech RuntimeConcurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Speech allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-59508Windows Speech RecognitionConcurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Speech allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-59509Windows Speech RecognitionInsertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.Information Disclosure
CVE-2025-59510Windows Routing and Remote Access Service (RRAS)Improper link resolution before file access (‘link following’) in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.Denial of Service
CVE-2025-59511Windows WLAN ServiceExternal control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-59512Customer Experience Improvement Program (CEIP)Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-59513Windows Bluetooth RFCOM Protocol DriverAn out-of-bounds read in the Windows Bluetooth RFCOMM Protocol Driver allows an authorized attacker to disclose local information.Information Disclosure
CVE-2025-60703Windows Remote Desktop ServicesUntrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-60704Windows KerberosMissing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.Elevation of Privilege
CVE-2025-60705Windows Client-Side CachingImproper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-60706Windows Hyper-VOut-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.Information Disclosure
CVE-2025-60707Multimedia Class Scheduler Service (MMCSS) DriverUse after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-60708Storvsp.sys DriverUntrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.Denial of Service
CVE-2025-60709Windows Common Log File System DriverOut-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-60710Host Process for Windows TasksImproper link resolution before file access (‘link following’) in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-60726Microsoft ExcelOut-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.Information Disclosure
CVE-2025-60727Microsoft ExcelOut-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Remote Code Execution
CVE-2025-60728Microsoft ExcelUntrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.Information Disclosure
CVE-2025-62206Microsoft Dynamics 365 (On-Premises)Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.Information Disclosure
CVE-2025-62210Dynamics 365 Field Service (online)Improper neutralization of input during web page generation (‘cross-site scripting’) in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.Spoofing
CVE-2025-62216Microsoft OfficeUse-after-free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.Remote Code Execution
CVE-2025-60719Windows Ancillary Function Driver for WinSockUntrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-60722Microsoft OneDrive for AndroidImproper limitation of a pathname to a restricted directory (‘path traversal’) in OneDrive for Android allows an authorized attacker to elevate privileges over a network.Elevation of Privilege
CVE-2025-62217Windows Ancillary Function Driver for WinSockConcurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-62218Microsoft Wireless Provisioning SystemConcurrent execution using shared resource with improper synchronization (‘race condition’) in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-62219Microsoft Wireless Provisioning SystemDouble free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-62220Windows Subsystem for Linux GUIHeap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network.Remote Code Execution
CVE-2025-62452Windows Routing and Remote Access Service (RRAS)Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.Remote Code Execution
CVE-2025-59240Microsoft ExcelExposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.Information Disclosure
CVE-2025-47179Configuration ManagerImproper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-59514Microsoft Streaming Service ProxyUse-after-free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-59515Windows Broadcast DVR User ServiceImproper privilege management in the Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-60713Windows Routing and Remote Access Service (RRAS)Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-60714Windows OLEHeap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.Remote Code Execution
CVE-2025-60715Windows Routing and Remote Access Service (RRAS)Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.Remote Code Execution
CVE-2025-60717Windows Broadcast DVR User ServiceUse-after-free in Microsoft Office Word allows an unauthorized attacker to execute code locally.Elevation of Privilege
CVE-2025-60718Windows Administrator ProtectionUntrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-60720Windows Transport Driver Interface (TDI) Translation DriverBuffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-60723DirectX Graphics KernelConcurrent execution using shared resource with improper synchronization (‘race condition’) in Windows DirectX allows an authorized attacker to deny service over a network.Denial of Service
CVE-2025-62200Microsoft ExcelUntrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Remote Code Execution
CVE-2025-62201Microsoft ExcelHeap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Remote Code Execution
CVE-2025-62202Microsoft ExcelOut-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.Information Disclosure
CVE-2025-62203Microsoft ExcelUse-after-free in Microsoft Office allows an unauthorized attacker to execute code locally.Remote Code Execution
CVE-2025-62204Microsoft SharePointDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Remote Code Execution
CVE-2025-62205Microsoft OfficeAn out-of-bounds read in the Windows Bluetooth RFCOMM Protocol Driver allows an authorized attacker to disclose local information.Remote Code Execution
CVE-2025-62208Windows License ManagerInsertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.Information Disclosure
CVE-2025-62209Windows License ManagerInsertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.Information Disclosure
CVE-2025-59499Microsoft SQL ServerImproper neutralization of special elements used in an sql command (‘sql injection’) in SQL Server allows an authorized attacker to elevate privileges over a network.Elevation of Privilege
CVE-2025-62211Dynamics 365 Field Service (online)Improper neutralization of input during web page generation (‘cross-site scripting’) in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.Spoofing
CVE-2025-62215Windows KernelConcurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Kernel allows an authorized attacker to elevate privileges locally. (Zero-day, exploited)Elevation of Privilege
CVE-2025-62213Windows Ancillary Function Driver for WinSockUse-after-free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Elevation of Privilege
CVE-2025-62222Agentic AI and Visual Studio CodeImproper neutralization of special elements used in a command (‘command injection’) in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.Remote Code Execution
CVE-2025-62449Microsoft Visual Studio Code CoPilot Chat ExtensionImproper limitation of a pathname to a restricted directory (‘path traversal’) in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally.Security Feature Bypass
CVE-2025-60721Windows Administrator ProtectionPrivilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.Elevation of Privilege
CVE-2025-62453GitHub Copilot and Visual Studio CodeImproper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.Security Feature Bypass

This Patch Tuesday reflects Microsoft’s ongoing efforts to bolster defenses amid rising threat landscapes, including APT campaigns targeting enterprise software.

Affected products span client OS, servers, productivity tools, and cloud services, emphasizing the need for comprehensive patch management. Security teams should scan environments using tools like Microsoft Update or WSUS, prioritizing internet-facing and privileged systems.

Vulnerability researchers highlight that while no additional zero-days were publicly disclosed, the exploited CVE-2025-62215 aligns with trends in kernel-level attacks.

Other Patch Tuesday Vulnerabilities

  1. Firefox Releases Security Update to Fix Multiple Vulnerabilities Allowing Arbitrary Code Execution
  2. Ivanti Endpoint Manager Vulnerabilities Let Attackers Write Arbitrary Files to Disk
  3. Synology BeeStation 0-Day Vulnerability Let Remote Attackers Execute Arbitrary Code
  4. Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data
  5. SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran is the Co-Founder and Editor-in-Chief of CyberSecurityNews.com, specializing in vulnerability analysis, malware research, ransomware, and computer forensics.

Recent Posts

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless…

45 minutes ago

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…

1 hour ago

Critical Grafana Vulnerability Let Attackers Escalate Privilege

Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…

1 hour ago

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…

2 hours ago

Windows 11 to Hide BSOD Crash Errors on Public Displays

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…

4 hours ago

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

6 hours ago