Skip to content
Skip to content
June 25, 2026
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy

Microsoft News Now

The Home of Microsoft News Today

Primary Menu
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy
Light/Dark Button
Subscribe

Home - News - Microsoft November 2025 Patch Tuesday Fixes 63 New Vulnerabilities Including 1 Actively Exploited Zero-Day

  • News
  • Windows

Microsoft November 2025 Patch Tuesday Fixes 63 New Vulnerabilities Including 1 Actively Exploited Zero-Day

Microsoft November 2025 Patch Tuesday rolls out critical patches for 63 vulnerabilities including one zero-day exploited in the wild. Apply updates now.
Dave W. Shanahan 8 months ago 7 minutes read
Microsoft November 2025 Patch Tuesday Fixes 63 New Vulnerabilities Including 1 Actively Exploited Zero-Day

Microsoft’s November 2025 Patch Tuesday update addresses 63 security vulnerabilities across its software product portfolio, including one actively exploited zero-day flaw. The update features critical patches for remote code execution and privilege escalation vulnerabilities that pose significant threat risks, urging users and organizations to promptly apply the fixes.​

November 11, 2025 Patch Tuesday Security Vulnerabilities Fixed

Microsoft November 2025 Patch Tuesday Fixes 63 New Vulnerabilities Including 1 Actively Exploited Zero-Day

As reported by Bleeping Computer, Microsoft’s November 2025 Patch Tuesday fixed 63 vulnerabilities in total, of which five are rated “Critical” severity. Among these critical patches are remote code execution (RCE) flaws and elevation of privilege (EoP) issues that attackers commonly exploit to gain control or move laterally within systems.

  • The most concerning flaw is CVE-2025-62215, a zero-day vulnerability in the Windows Kernel allowing local privilege escalation through a race condition. It is the only actively exploited zero-day observed “in the wild,” making it urgent for all Windows users to install this update.​

  • Other critical flaws include a remote code execution vulnerability in GDI+ (graphics component), which can be triggered by opening a malicious document or uploading a crafted metafile, and additional elevation of privilege bugs impacting Windows components.​

  • The update also fixes 29 elevation of privilege vulnerabilities, 16 remote code execution bugs, 11 information disclosure issues, 3 denial-of-service vulnerabilities, and various spoofing and security bypass flaws across Windows, Office, Azure, Visual Studio, and related products.​

Broad Product Coverage

This Patch Tuesday release touches multiple Microsoft technologies:

  • Windows Kernel, GDI+, and Windows components including License Manager and Speech Recognition.

  • Microsoft Office suite components like Excel.

  • Azure components such as the Monitor Agent.

  • Developer tools including Visual Studio and GitHub Copilot.

  • Dynamics 365 products are affected by spoofing and cross-site scripting vulnerabilities.​

Additional Features and Fixes for Windows 11

windows logo

Beyond security, Microsoft released Windows 11 updates (KB5068861 and KB5067112) introducing UI improvements like a redesigned Start menu and better battery icon behavior, plus fixes for Task Manager bugs. These cumulative updates enhance system stability alongside security reinforcement.​

Extended Security Updates for Windows 10

Noteworthy in this Patch Tuesday is the release of the first Extended Security Update (ESU) for Windows 10 (KB5068781), available after support ended last month. This allows Windows 10 users requiring continued security patches to maintain protection, though migration to Windows 11 remains recommended.​

Importance of Immediate Patching

Microsoft November 2025 Patch Tuesday Fixes 63 New Vulnerabilities Including 1 Actively Exploited Zero-Day

With 63 vulnerabilities patched, including a zero-day actively exploited, this Patch Tuesday, Microsoft stresses onboarding these updates rapidly to minimize attack surface exposure. The rapidly evolving threat landscape and demonstrated exploitation necessitate a proactive patch management approach.​

Summary of Vulnerability Counts by Type

Vulnerability TypeCount
Elevation of Privilege (EoP)29
Remote Code Execution (RCE)16
Information Disclosure11
Denial of Service3
Spoofing2
Security Feature Bypass2
TagCVE IDCVE TitleSeverity
Azure Monitor AgentCVE-2025-59504Azure Monitor Agent Remote Code Execution VulnerabilityImportant
Customer Experience Improvement Program (CEIP)CVE-2025-59512Customer Experience Improvement Program (CEIP) Elevation of Privilege VulnerabilityImportant
Dynamics 365 Field Service (online)CVE-2025-62211Dynamics 365 Field Service (online) Spoofing VulnerabilityImportant
Dynamics 365 Field Service (online)CVE-2025-62210Dynamics 365 Field Service (online) Spoofing VulnerabilityImportant
GitHub Copilot and Visual Studio CodeCVE-2025-62453GitHub Copilot and Visual Studio Code Security Feature Bypass VulnerabilityImportant
Host Process for Windows TasksCVE-2025-60710Host Process for Windows Tasks Elevation of Privilege VulnerabilityImportant
Microsoft Configuration ManagerCVE-2025-47179Configuration Manager Elevation of Privilege VulnerabilityImportant
Microsoft Dynamics 365 (on-premises)CVE-2025-62206Microsoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2025-60724GDI+ Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2025-62216Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2025-62199Microsoft Office Remote Code Execution VulnerabilityCritical
Microsoft Office ExcelCVE-2025-62200Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-62201Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-60726Microsoft Excel Information Disclosure VulnerabilityImportant
Microsoft Office ExcelCVE-2025-62203Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-62202Microsoft Excel Information Disclosure VulnerabilityImportant
Microsoft Office ExcelCVE-2025-60727Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2025-60728Microsoft Excel Information Disclosure VulnerabilityImportant
Microsoft Office ExcelCVE-2025-59240Microsoft Excel Information Disclosure VulnerabilityImportant
Microsoft Office SharePointCVE-2025-62204Microsoft SharePoint Remote Code Execution VulnerabilityImportant
Microsoft Office WordCVE-2025-62205Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft Streaming ServiceCVE-2025-59514Microsoft Streaming Service Proxy Elevation of Privilege VulnerabilityImportant
Microsoft Wireless Provisioning SystemCVE-2025-62218Microsoft Wireless Provisioning System Elevation of Privilege VulnerabilityImportant
Microsoft Wireless Provisioning SystemCVE-2025-62219Microsoft Wireless Provisioning System Elevation of Privilege VulnerabilityImportant
Multimedia Class Scheduler Service (MMCSS)CVE-2025-60707Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege VulnerabilityImportant
Nuance PowerScribeCVE-2025-30398Nuance PowerScribe 360 Information Disclosure VulnerabilityCritical
OneDrive for AndroidCVE-2025-60722Microsoft OneDrive for Android Elevation of Privilege VulnerabilityImportant
Role: Windows Hyper-VCVE-2025-60706Windows Hyper-V Information Disclosure VulnerabilityImportant
SQL ServerCVE-2025-59499Microsoft SQL Server Elevation of Privilege VulnerabilityImportant
Storvsp.sys DriverCVE-2025-60708Storvsp.sys Driver Denial of Service VulnerabilityImportant
Visual StudioCVE-2025-62214Visual Studio Remote Code Execution VulnerabilityCritical
Visual Studio Code CoPilot Chat ExtensionCVE-2025-62449Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass VulnerabilityImportant
Visual Studio Code CoPilot Chat ExtensionCVE-2025-62222Agentic AI and Visual Studio Code Remote Code Execution VulnerabilityImportant
Windows Administrator ProtectionCVE-2025-60721Windows Administrator Protection Elevation of Privilege VulnerabilityImportant
Windows Administrator ProtectionCVE-2025-60718Windows Administrator Protection Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2025-62217Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2025-60719Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2025-62213Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Bluetooth RFCOM Protocol DriverCVE-2025-59513Windows Bluetooth RFCOM Protocol Driver Information Disclosure VulnerabilityImportant
Windows Broadcast DVR User ServiceCVE-2025-59515Windows Broadcast DVR User Service Elevation of Privilege VulnerabilityImportant
Windows Broadcast DVR User ServiceCVE-2025-60717Windows Broadcast DVR User Service Elevation of Privilege VulnerabilityImportant
Windows Client-Side Caching (CSC) ServiceCVE-2025-60705Windows Client-Side Caching Elevation of Privilege VulnerabilityImportant
Windows Common Log File System DriverCVE-2025-60709Windows Common Log File System Driver Elevation of Privilege VulnerabilityImportant
Windows DirectXCVE-2025-59506DirectX Graphics Kernel Elevation of Privilege VulnerabilityImportant
Windows DirectXCVE-2025-60716DirectX Graphics Kernel Elevation of Privilege VulnerabilityCritical
Windows DirectXCVE-2025-60723DirectX Graphics Kernel Denial of Service VulnerabilityImportant
Windows KerberosCVE-2025-60704Windows Kerberos Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2025-62215Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows License ManagerCVE-2025-62208Windows License Manager Information Disclosure VulnerabilityImportant
Windows License ManagerCVE-2025-62209Windows License Manager Information Disclosure VulnerabilityImportant
Windows OLECVE-2025-60714Windows OLE Remote Code Execution VulnerabilityImportant
Windows Remote DesktopCVE-2025-60703Windows Remote Desktop Services Elevation of Privilege VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-62452Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-59510Windows Routing and Remote Access Service (RRAS) Denial of Service VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-60715Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2025-60713Windows Routing and Remote Access Service (RRAS) Elevation of Privilege VulnerabilityImportant
Windows Smart CardCVE-2025-59505Windows Smart Card Reader Elevation of Privilege VulnerabilityImportant
Windows SpeechCVE-2025-59507Windows Speech Runtime Elevation of Privilege VulnerabilityImportant
Windows SpeechCVE-2025-59508Windows Speech Recognition Elevation of Privilege VulnerabilityImportant
Windows SpeechCVE-2025-59509Windows Speech Recognition Information Disclosure VulnerabilityImportant
Windows Subsystem for Linux GUICVE-2025-62220Windows Subsystem for Linux GUI Remote Code Execution VulnerabilityImportant
Windows TDX.sysCVE-2025-60720Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege VulnerabilityImportant
Windows WLAN ServiceCVE-2025-59511Windows WLAN Service Elevation of Privilege VulnerabilityImportant

Don’t forget to check out other Microsoft news happening today, including Microsoft’s $10 Billion AI Data Center in Portugal: Leading Europe’s $16B AI Infrastructure Boom and see what BlueCodeAgent is doing for AI Code Security. This month’s Patch Tuesday underscores Microsoft’s continued commitment to fixing emerging threats across its wide product ecosystem to protect users from sophisticated cyberattacks.​ For more Patch Tuesday coverage, check out our dedicated page.

About The Author

Patch Tuesday

Dave W. Shanahan

I’m Dave W. Shanahan, a Microsoft enthusiast with a passion for Windows, Xbox, Microsoft 365 Copilot, Azure, and more. I started MSFTNewsNow.com to keep the world updated on Microsoft news. Based in Massachusetts, you can email me at davewshanahan@gmail.com.

See author's posts

Like this:

LikeLoading…

Related


Discover more from Microsoft News Now

Subscribe to get the latest posts sent to your email.

Tags: AndroidAzureCopilotData CenterDeveloperDynamics 365GitHubLinuxMicrosoftMicrosoft ExcelMicrosoft OfficeOneDrivePatch TuesdaySecuritySharePointSurfaceVisual StudioWindowsWindows 10Windows 11

Post navigation

Previous: BlueCodeAgent Revolutionizes AI Code Security: Microsoft and Research Partners Unveil Automated Blue Teaming for Safer CodeGen AI
Next: Play Grand Theft Auto (GTA) Online Free on Xbox Series X|S — Free Play Days Delivers Visual Upgrades and $4M Career Builder Bonus

Related Stories

Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI
  • News
  • AI and Copilot

Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI

Dave W. Shanahan 2 days ago 0
Super XBOX News Roundup for June 23, 2026: Age of Empires: Mobile PC Edition Launch, Game Pass Updates, and Xbox Reset Turbulence
  • News
  • XBOX and Gaming

Super XBOX News Roundup for June 23, 2026: Age of Empires: Mobile PC Edition Launch, Game Pass Updates, and Xbox Reset Turbulence

Dave W. Shanahan 2 days ago 0
Next Week on XBOX: Age of Empires Mobile, EMPULSE, and 20+ New Games Drop June 22–26
  • News
  • XBOX and Gaming

Next Week on XBOX: Age of Empires Mobile, EMPULSE, and 20+ New Games Drop June 22–26

Dave W. Shanahan 6 days ago 0

AccessibilityAmazonAndroidAuthenticationAzureCopilotCybersecurityDeveloperEnterpriseFree Play DaysGamingGenerative AIGitHubGoogleLinkedinMicrosoftMicrosoft 365Microsoft 365 CopilotMicrosoft CopilotMicrosoft EdgeMicrosoft StoreMicrosoft TeamsNext Week on XBOXOpenAIOutlookPatch TuesdayPlayStationPrivacySecuritySettingsSharePointSurfaceTwitterWindowsWindows 10Windows 11Windows InsiderXBOXXBOX Game PassXBOX Game Pass UltimateXBOX OneXBOX Play AnywhereXBOX Series XXBOX Series X|SXBOX Wire

Useful Links

  • AI and Copilot (249)
  • Azure & Cloud (35)
  • Developers (3)
  • Enterprise (3)
  • How To Guides (98)
  • Microsoft 365/Office (95)
  • Microsoft Announcements (97)
  • News (1,262)
  • Security (78)
  • Surface (47)
  • Windows (166)
  • XBOX and Gaming (411)

You May Have Missed

Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI
  • News
  • AI and Copilot

Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI

Dave W. Shanahan 2 days ago 0
Super XBOX News Roundup for June 23, 2026: Age of Empires: Mobile PC Edition Launch, Game Pass Updates, and Xbox Reset Turbulence
  • News
  • XBOX and Gaming

Super XBOX News Roundup for June 23, 2026: Age of Empires: Mobile PC Edition Launch, Game Pass Updates, and Xbox Reset Turbulence

Dave W. Shanahan 2 days ago 0
Windows key + G XBOX GAME BAR keyboard shortcut
  • How To Guides
  • XBOX and Gaming

How to Enable XBOX Game Bar and Capture Epic Game Clips on Windows 11 (No Frustrating Setup Required)

Dave W. Shanahan 3 days ago 0
Copilot on Windows: Install and Launch in Under 5 Minutes
  • How To Guides
  • AI and Copilot

Copilot on Windows: Seamless Install and Launch in Under 5 Minutes

Dave W. Shanahan 4 days ago 0
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy
Copyright © 2026 All rights reserved. ReviewNews by AF themes.

    %d