{"id":9669,"date":"2025-12-12T14:43:37","date_gmt":"2025-12-12T14:43:37","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=9669"},"modified":"2025-12-12T14:43:37","modified_gmt":"2025-12-12T14:43:37","slug":"a-giant-end-to-2025-in-decembers-patch-tuesday-sophos-information","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=9669","title":{"rendered":"A giant end to 2025 in December\u2019s Patch Tuesday \u2013 Sophos Information"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Microsoft on Tuesday launched 56 patches affecting 10 product households. Two of the addressed points are thought-about by Microsoft to be of Essential severity \u2013 and, unusually, each belong to the blended Workplace-365 product household. Eight have a CVSS base rating of 8.0 or greater. One is understood to be beneath energetic exploit within the wild, and two others are publicly disclosed.<\/p>\n<p>That\u2019s the excellent news. We\u2019ll get to the advisories in a second.<\/p>\n<p>At patch time, six CVEs are judged extra prone to be exploited within the subsequent 30 days by the corporate\u2019s estimation, along with the one already detected to be so. Varied of this month\u2019s points are amenable to direct detection by Sophos protections, and we embody data on these in a desk beneath.<\/p>\n<p>The discharge additionally contains data on 14 Edge patches launched final week, in addition to 12 ColdFusion and 4 Adobe Reader patches launched in the present day. (The only real Edge patch originating with Microsoft is counted on this complete relatively within the basic Patch Tuesday rely of 56; the remainder originated with Chromium itself and had been patched earlier within the month.) We&#8217;ve included data on all these patches in Appendix D. There is no such thing as a replace to the Servicing Stack listed in Microsoft\u2019s manifest this month.<\/p>\n<p>Microsoft additionally launched data on 84 CVEs affecting CBL Mariner and\/or Azure Linux. All 84 CVEs originated with MITRE and have been addressed over the course of the previous week, and all 84 are indicated as exploited in within the wild (although none are marked as publicly disclosed). Little data was made obtainable on these 84 CVEs, however we\u2019ve supplied some steerage in Appendix F on the finish of the publish.<\/p>\n<p>We&#8217;re as at all times together with on the finish of this publish appendices itemizing all Microsoft\u2019s patches sorted by severity (Appendix A), by predicted exploitability timeline and CVSS Base rating (Appendix B), and by product household (Appendix C). Appendix E gives a breakout of the patches affecting the varied Home windows Server platforms.<\/p>\n<p><strong>By the numbers<\/strong><\/p>\n<ul>\n<li>Whole CVEs: 56<\/li>\n<li>Publicly disclosed: 2<\/li>\n<li>Exploit detected: 1<\/li>\n<li>Severity\n<ul>\n<li>Essential: 2<\/li>\n<li>Necessary: 54<\/li>\n<\/ul>\n<\/li>\n<li>Impression\n<ul>\n<li>Denial of Service: 3<\/li>\n<li>Elevation of Privilege: 28<\/li>\n<li>Data Disclosure: 4<\/li>\n<li>Distant Code Execution: 19<\/li>\n<li>Spoofing: 2<\/li>\n<\/ul>\n<\/li>\n<li>CVSS Base rating 9.0 or better: 0<\/li>\n<li>CVSS Base rating 8.0 or better: 8<\/li>\n<\/ul>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig01.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-964273\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig01.png\" alt=\"A bar chart showing the distribution of December 2025 Patch Tuesday CVEs sorted by impact and further indicated by severity; information in text\" width=\"640\" height=\"415\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig01.png 838w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig01.png?resize=300,195 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig01.png?resize=768,499 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/a><\/p>\n<p><em>Determine 1: Elevation of Privilege points had been probably the most quite a few within the December assortment, as soon as once more<\/em><\/p>\n<p><strong>Merchandise<\/strong><\/p>\n<ul>\n<li>Home windows: 38<\/li>\n<li>365: 13<\/li>\n<li>Workplace: 13<\/li>\n<li>Excel: 6<\/li>\n<li>SharePoint: 5<\/li>\n<li>Phrase: 4<\/li>\n<li>Alternate: 2<\/li>\n<li>Entry: 1<\/li>\n<li>Azure: 1<\/li>\n<li>GitHub: 1<\/li>\n<\/ul>\n<p>As is our customized for this record, CVEs that apply to multiple product household are counted as soon as for every household they have an effect on. We notice, by the way in which, that CVE names don\u2019t at all times mirror affected product households carefully. Particularly, some CVEs names within the Workplace household might point out merchandise that don\u2019t seem within the record of merchandise affected by the CVE, and vice versa.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig02.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-964274\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig02.png\" alt=\"A bar chart showing the December Patch Tuesday CVEs sorted by affected product family and further color-coded by severity; information in text\" width=\"640\" height=\"475\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig02.png 810w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig02.png?resize=300,223 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig02.png?resize=768,570 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/a><\/p>\n<p><em>Determine 2: A smaller, closely end-user-oriented group of product households acquired patches this month. Although Home windows accounts for half of them, patches associated to the working system are all Necessary in severity<\/em><\/p>\n<p><strong>Notable December updates<\/strong><\/p>\n<p>Along with the problems mentioned above, a number of particular objects benefit consideration.<\/p>\n<p><strong>CVE-2025-62554 \u2014 Microsoft Workplace Distant Code Execution Vulnerability<br \/>CVE-2025-62555 \u2014 Microsoft Phrase Distant Code Execution Vulnerability<br \/>CVE-2025-62557 \u2014 Microsoft Workplace Distant Code Execution Vulnerability<br \/>CVE-2025-62558 \u2014 Microsoft Phrase Distant Code Execution Vulnerability<br \/>CVE-2025-62559 \u2014 Microsoft Phrase Distant Code Execution Vulnerability<br \/>CVE-2025-62560 \u2014 Microsoft Excel Distant Code Execution Vulnerability<br \/>CVE-2025-62561 \u2014 Microsoft Excel Distant Code Execution Vulnerability<\/strong><\/p>\n<p>All seven of those RCE points have an effect on a number of variations of 365 and Workplace, together with Microsoft Workplace LTSC for Mac 2021 and 2024. Nevertheless, the patches for these Mac variations aren\u2019t prepared but. Customers liable for updating Macs are requested to watch the CVE data for every vulnerability for additional phrase on these patches. Of the seven, pay particular consideration to CVE-2025-62554 and CVE-2025-62257 (the 2 merely known as \u201cWorkplace\u201d vulnerabilities) \u2013 they\u2019re those which Preview Pane is an assault vector. These two CVEs are Essential-severity and have a CVSS Base rating of 8.4. The others are Necessary-severity.<\/p>\n<p><strong>CVE-2025-54100 \u2014 PowerShell Distant Code Execution Vulnerability<\/strong><\/p>\n<p>As with the 84 Mariner vulnerabilities talked about above, the discharge of this patch arrived with much less data than Microsoft-issued CVEs usually do. That mentioned, this Necessary-class difficulty is allotted to Home windows; as with the GitHub difficulty mentioned beneath, it includes improper neutralization of particular parts utilized in a command. For this one, Microsoft notes that after set up, customers making an attempt to deploy the Invoke-WebRequest command will get a brand new affirmation immediate warning them of doubtless undesirable script code execution and recommending that they embody the -UseBasicParsing swap to maintain issues behaving properly.<\/p>\n<p><strong>CVE-2025-64666 \u2014 Microsoft Alternate Server Elevation of Privilege Vulnerability<br \/>CVE-2025-64667 \u2014 Microsoft Alternate Server Spoofing Vulnerability<\/strong><\/p>\n<p>These two Necessary-severity bugs each have an effect on Alternate Server 2016 and 2019, that are out-of-support variations of Alternate \u2013 except you\u2019re paying for Microsoft\u2019s Prolonged Safety Replace (ESU) program, you\u2019re not getting these patches. (Alternate Server Subscription Version subscribers are coated.) The EoP is a reasonably specialised merchandise that might require the attacker to arrange the goal setting forward of time, whereas the Spoofing bug <a rel=\"nofollow\" target=\"_blank\" href=\"http:\/\/techcommunity.microsoft.com\/blog\/exchange\/released-december-2025-exchange-server-security-updates\/4474949\">impacts<\/a>, particularly, how From: addresses are exhibited to the consumer.<\/p>\n<p><strong>CVE-2025-64671 \u2014 GitHub Copilot for Jetbrains Distant Code Execution Vulnerability<\/strong><\/p>\n<p>The one publicly disclosed vulnerability to this point this month permits the Jetbrain AI-based coding assistant to wreck the vibe-coding vibe, because of improper neutralization of particular parts utilized in a command. Based on Microsoft, an attacker may execute extra instructions by appending them to instructions allowed within the consumer\u2019s terminal auto-approve setting. This vulnerability is credited to unbiased researcher Ari Marzouk, who simply final weekend posted evaluation of a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/maccarita.com\/posts\/idesaster\/\">probably energetic<\/a> new class of vulnerabilities in AI IDEs. An intriguing learn.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig03.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-964275\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig03.png\" alt=\"A bar chart showing cumulative Patch Tuesday counts by impact for all of 2025, further color-coded by severity. In order of decreasing occurrence, Elevation of Privilege was the most common impact type, followed by Remote Code Execution, Information Disclosure, Denial of Service, Security Feature Bypass, Spoofing, and Tampering\" width=\"640\" height=\"414\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig03.png 843w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig03.png?resize=300,194 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig03.png?resize=768,497 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/a><\/p>\n<p><em>Determine 3: The yr wrapped up with Elevation of Privilege and Distant Code Execution swapping spots on the high of the charts. Be aware, although, that although there have been fewer RCE bugs squashed this yr, there was the next share of Essential-severity RCEs. General there have been 92 Essential-severity CVEs handle in 2025 in comparison with 55 final yr.<\/em><\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig04.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-964276\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig04.png\" alt=\"A bar chart showing Patch Tuesday counts for every month since January 2020\" width=\"640\" height=\"223\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig04.png 1195w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig04.png?resize=300,105 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig04.png?resize=768,268 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2025\/12\/pt2512-fig04.png?resize=1024,357 1024w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><\/a><\/p>\n<p><em>Determine 4: Behold the ultimate (one hopes) 2025 tally: In the long run, it was probably the most patch-heavy yr (1196 excluding out-of-band patch releases) since 2020 (1245 patches excluding out-of-bands), with two record-breaking months in January and October.<\/em><\/p>\n<p>\u00a0<\/p>\n<p><strong>Sophos protections<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"151\"><strong>CVE<\/strong><\/td>\n<td width=\"227\"><strong>Sophos Intercept X\/Endpoint IPS<\/strong><\/td>\n<td width=\"223\"><strong>Sophos XGS Firewall<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"151\">CVE-2025-59516<\/td>\n<td width=\"227\">Exp\/2559516-A<\/td>\n<td width=\"223\">Exp\/2559516-A<\/td>\n<\/tr>\n<tr>\n<td width=\"151\">CVE-2025-59517<\/td>\n<td width=\"227\">Exp\/2559517-A<\/td>\n<td width=\"223\">Exp\/2559517-A<\/td>\n<\/tr>\n<tr>\n<td width=\"151\">CVE-2025-62221<\/td>\n<td width=\"227\">Exp\/2562221-A<\/td>\n<td width=\"223\">Exp\/2562221-A<\/td>\n<\/tr>\n<tr>\n<td width=\"151\">CVE-2025-62454<\/td>\n<td width=\"227\">Exp\/2562454-A<\/td>\n<td width=\"223\">Exp\/2562454-A<\/td>\n<\/tr>\n<tr>\n<td width=\"151\">CVE-2025-62470<\/td>\n<td width=\"227\">Exp\/2562470-A<\/td>\n<td width=\"223\">Exp\/2562470-A<\/td>\n<\/tr>\n<tr>\n<td width=\"151\">CVE-2025-62472<\/td>\n<td width=\"227\">Exp\/2562472-A<\/td>\n<td width=\"223\">Exp\/2562472-A<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p>As you may each month, for those who don\u2019t need to wait in your system to drag down Microsoft\u2019s updates itself, you may obtain them manually from the Home windows Replace Catalog web site. Run the <strong>winver.exe <\/strong>device to find out which construct of Home windows you\u2019re working, then obtain the Cumulative Replace bundle in your particular system\u2019s structure and construct quantity.<\/p>\n<p><strong>Appendix A: Vulnerability Impression and Severity<\/strong><\/p>\n<p>This can be a record of December patches sorted by affect, then sub-sorted by severity. Every record is additional organized by CVE.<\/p>\n<p><strong>Elevation of Privilege (28 CVEs)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-55233<\/td>\n<td width=\"470\">Home windows Projected File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-59516<\/td>\n<td width=\"470\">Home windows Storage VSP Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-59517<\/td>\n<td width=\"470\">Home windows Storage VSP Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62221<\/td>\n<td width=\"470\">Home windows Cloud Recordsdata Mini Filter Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62454<\/td>\n<td width=\"470\">Home windows Cloud Recordsdata Mini Filter Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62455<\/td>\n<td width=\"470\">Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62457<\/td>\n<td width=\"470\">Home windows Cloud Recordsdata Mini Filter Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62458<\/td>\n<td width=\"470\">Win32k Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62461<\/td>\n<td width=\"470\">Home windows Projected File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62462<\/td>\n<td width=\"470\">Home windows Projected File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62464<\/td>\n<td width=\"470\">Home windows Projected File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62466<\/td>\n<td width=\"470\">Home windows Consumer-Aspect Caching Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62467<\/td>\n<td width=\"470\">Home windows Projected File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62469<\/td>\n<td width=\"470\">Microsoft Brokering File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62470<\/td>\n<td width=\"470\">Home windows Frequent Log File System Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62472<\/td>\n<td width=\"470\">Home windows Distant Entry Connection Supervisor Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62474<\/td>\n<td width=\"470\">Home windows Distant Entry Connection Supervisor Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62565<\/td>\n<td width=\"470\">Home windows File Explorer Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62569<\/td>\n<td width=\"470\">Microsoft Brokering File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62571<\/td>\n<td width=\"470\">Home windows Installer Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62572<\/td>\n<td width=\"470\">Utility Data Service Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62573<\/td>\n<td width=\"470\">DirectX Graphics Kernel Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-64658<\/td>\n<td width=\"470\">Home windows File Explorer Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-64661<\/td>\n<td width=\"470\">Home windows Shell Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-64666<\/td>\n<td width=\"470\">Microsoft Alternate Server Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-64673<\/td>\n<td width=\"470\">Home windows Storage VSP Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-64679<\/td>\n<td width=\"470\">Home windows DWM Core Library Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-64680<\/td>\n<td width=\"470\">Home windows DWM Core Library Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Distant Code Execution (19 CVEs)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Essential severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62554<\/td>\n<td width=\"470\">Microsoft Workplace Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62557<\/td>\n<td width=\"470\">Microsoft Workplace Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-54100<\/td>\n<td width=\"470\">PowerShell Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62456<\/td>\n<td width=\"470\">Home windows Resilient File System (ReFS) Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62549<\/td>\n<td width=\"470\">Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62550<\/td>\n<td width=\"470\">Azure Monitor Agent Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62552<\/td>\n<td width=\"470\">Microsoft Entry Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62553<\/td>\n<td width=\"470\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62555<\/td>\n<td width=\"470\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62556<\/td>\n<td width=\"470\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62558<\/td>\n<td width=\"470\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62559<\/td>\n<td width=\"470\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62560<\/td>\n<td width=\"470\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62561<\/td>\n<td width=\"470\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62562<\/td>\n<td width=\"470\">Microsoft Outlook Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62563<\/td>\n<td width=\"470\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62564<\/td>\n<td width=\"470\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-64671<\/td>\n<td width=\"470\">GitHub Copilot for Jetbrains Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-64678<\/td>\n<td width=\"470\">Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Data Disclosure (4 CVEs)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62468<\/td>\n<td width=\"470\">Home windows Defender Firewall Service Data Disclosure Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62473<\/td>\n<td width=\"470\">Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62570<\/td>\n<td width=\"470\">Home windows Digicam Body Server Monitor Data Disclosure Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-64670<\/td>\n<td width=\"470\">Home windows DirectX Data Disclosure Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p><strong>Denial of Service (3 CVEs)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62463<\/td>\n<td width=\"470\">DirectX Graphics Kernel Denial of Service Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62465<\/td>\n<td width=\"470\">DirectX Graphics Kernel Denial of Service Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62567<\/td>\n<td width=\"470\">Home windows Hyper-V Denial of Service Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p><strong>Spoofing (2 CVEs)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-64667<\/td>\n<td width=\"470\">Microsoft Alternate Server Spoofing Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-64672<\/td>\n<td width=\"470\">Microsoft SharePoint Server Spoofing Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n<p><strong>Appendix B: Exploitability and CVSS<\/strong><\/p>\n<p>This can be a record of the December CVEs judged by Microsoft to be extra prone to be exploited within the wild inside the first 30 days post-release. The record is organized by CVE.<\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Exploitation extra seemingly inside the subsequent 30 days<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-59516<\/td>\n<td width=\"470\">Home windows Storage VSP Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-59517<\/td>\n<td width=\"470\">Home windows Storage VSP Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62454<\/td>\n<td width=\"470\">Home windows Cloud Recordsdata Mini Filter Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62458<\/td>\n<td width=\"470\">Win32k Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62470<\/td>\n<td width=\"470\">Home windows Frequent Log File System Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"131\">CVE-2025-62472<\/td>\n<td width=\"470\">Home windows Distant Entry Connection Supervisor Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p>The CVE listed beneath was recognized to be beneath energetic exploit previous to the discharge of this month\u2019s patches.<\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"132\">CVE-2025-62221<\/td>\n<td width=\"469\">Home windows Cloud Recordsdata Mini Filter Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p>These are the December CVEs with a Microsoft-assessed CVSS Base rating of 8.0 or greater. They&#8217;re organized by rating and additional sorted by CVE. For extra data on how CVSS works, please see our collection on <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.sophos.com\/en-us\/2024\/12\/27\/prioritizing-patching-a-deep-dive-into-frameworks-and-tools-part-1-cvss\/\">patch prioritization schema<\/a>.<\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"47\"><strong>CVSS Base<\/strong><\/td>\n<td width=\"76\"><strong>CVSS Temporal<\/strong><\/td>\n<td width=\"123\"><strong>CVE<\/strong><\/td>\n<td width=\"356\"><strong>Title<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"47\">8.8<\/td>\n<td width=\"76\">7.7<\/td>\n<td width=\"123\">CVE-2025-62456<\/td>\n<td width=\"356\">Home windows Resilient File System (ReFS) Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"47\">8.8<\/td>\n<td width=\"76\">7.7<\/td>\n<td width=\"123\">CVE-2025-62549<\/td>\n<td width=\"356\">Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"47\">8.8<\/td>\n<td width=\"76\">7.7<\/td>\n<td width=\"123\">CVE-2025-62550<\/td>\n<td width=\"356\">Azure Monitor Agent Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"47\">8.8<\/td>\n<td width=\"76\">7.7<\/td>\n<td width=\"123\">CVE-2025-64672<\/td>\n<td width=\"356\">Microsoft SharePoint Server Spoofing Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"47\">8.8<\/td>\n<td width=\"76\">7.7<\/td>\n<td width=\"123\">CVE-2025-64678<\/td>\n<td width=\"356\">Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"47\">8.4<\/td>\n<td width=\"76\">7.3<\/td>\n<td width=\"123\">CVE-2025-62554<\/td>\n<td width=\"356\">Microsoft Workplace Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"47\">8.4<\/td>\n<td width=\"76\">7.3<\/td>\n<td width=\"123\">CVE-2025-62557<\/td>\n<td width=\"356\">Microsoft Workplace Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"47\">8.4<\/td>\n<td width=\"76\">7.3<\/td>\n<td width=\"123\">CVE-2025-64671<\/td>\n<td width=\"356\">GitHub Copilot for Jetbrains Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p><strong>Appendix C: Merchandise Affected<\/strong><\/p>\n<p>This can be a record of December\u2019s patches sorted by product household, then sub-sorted by severity. Every record is additional organized by CVE. Patches which might be shared amongst a number of product households are listed a number of occasions, as soon as for every product household. Sure points for which advisories have been issued are coated in Appendix D, and points affecting Home windows Server are additional sorted in Appendix E. All CVE titles are correct as made obtainable by Microsoft; for additional data on why sure merchandise might seem in titles and never product households (or vice versa), please seek the advice of Microsoft.<\/p>\n<p><strong>Home windows (38 CVEs)<\/strong><\/p>\n<table width=\"601\">\n<tbody>\n<tr>\n<td width=\"132\"><strong>Necessary severity<\/strong><\/td>\n<td width=\"469\"\/>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-54100<\/td>\n<td width=\"469\">PowerShell Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-55233<\/td>\n<td width=\"469\">Home windows Projected File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-59516<\/td>\n<td width=\"469\">Home windows Storage VSP Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-59517<\/td>\n<td width=\"469\">Home windows Storage VSP Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62221<\/td>\n<td width=\"469\">Home windows Cloud Recordsdata Mini Filter Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62454<\/td>\n<td width=\"469\">Home windows Cloud Recordsdata Mini Filter Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62455<\/td>\n<td width=\"469\">Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62456<\/td>\n<td width=\"469\">Home windows Resilient File System (ReFS) Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62457<\/td>\n<td width=\"469\">Home windows Cloud Recordsdata Mini Filter Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62458<\/td>\n<td width=\"469\">Win32k Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62461<\/td>\n<td width=\"469\">Home windows Projected File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62462<\/td>\n<td width=\"469\">Home windows Projected File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62463<\/td>\n<td width=\"469\">DirectX Graphics Kernel Denial of Service Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62464<\/td>\n<td width=\"469\">Home windows Projected File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62465<\/td>\n<td width=\"469\">DirectX Graphics Kernel Denial of Service Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62466<\/td>\n<td width=\"469\">Home windows Consumer-Aspect Caching Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62467<\/td>\n<td width=\"469\">Home windows Projected File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62468<\/td>\n<td width=\"469\">Home windows Defender Firewall Service Data Disclosure Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62469<\/td>\n<td width=\"469\">Microsoft Brokering File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62470<\/td>\n<td width=\"469\">Home windows Frequent Log File System Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62472<\/td>\n<td width=\"469\">Home windows Distant Entry Connection Supervisor Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62473<\/td>\n<td width=\"469\">Home windows Routing and Distant Entry Service (RRAS) Data Disclosure Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62474<\/td>\n<td width=\"469\">Home windows Distant Entry Connection Supervisor Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62549<\/td>\n<td width=\"469\">Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62565<\/td>\n<td width=\"469\">Home windows File Explorer Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62567<\/td>\n<td width=\"469\">Home windows Hyper-V Denial of Service Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62569<\/td>\n<td width=\"469\">Microsoft Brokering File System Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62570<\/td>\n<td width=\"469\">Home windows Digicam Body Server Monitor Data Disclosure Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62571<\/td>\n<td width=\"469\">Home windows Installer Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62572<\/td>\n<td width=\"469\">Utility Data Service Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62573<\/td>\n<td width=\"469\">DirectX Graphics Kernel Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-64658<\/td>\n<td width=\"469\">Home windows File Explorer Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-64661<\/td>\n<td width=\"469\">Home windows Shell Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-64670<\/td>\n<td width=\"469\">Home windows DirectX Data Disclosure Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-64673<\/td>\n<td width=\"469\">Home windows Storage VSP Driver Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-64678<\/td>\n<td width=\"469\">Home windows Routing and Distant Entry Service (RRAS) Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-64679<\/td>\n<td width=\"469\">Home windows DWM Core Library Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-64680<\/td>\n<td width=\"469\">Home windows DWM Core Library Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>365 (13 CVEs)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Essential severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62554<\/td>\n<td width=\"469\">Microsoft Workplace Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62557<\/td>\n<td width=\"469\">Microsoft Workplace Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62562<\/td>\n<td width=\"469\">Microsoft Outlook Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62552<\/td>\n<td width=\"469\">Microsoft Entry Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62553<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62555<\/td>\n<td width=\"469\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62556<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62558<\/td>\n<td width=\"469\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62559<\/td>\n<td width=\"469\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62560<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62561<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62563<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62564<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p><strong>Workplace (13 CVEs)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Essential severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62554<\/td>\n<td width=\"469\">Microsoft Workplace Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62557<\/td>\n<td width=\"469\">Microsoft Workplace Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62552<\/td>\n<td width=\"469\">Microsoft Entry Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62553<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62555<\/td>\n<td width=\"469\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62556<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62558<\/td>\n<td width=\"469\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62559<\/td>\n<td width=\"469\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62560<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62561<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62562<\/td>\n<td width=\"469\">Microsoft Outlook Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62563<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62564<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p><strong>Excel (6 CVEs)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62553<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62556<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62560<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62561<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62563<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62564<\/td>\n<td width=\"469\">Microsoft Excel Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p><strong>SharePoint (5 CVEs)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Essential severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62562<\/td>\n<td width=\"469\">Microsoft Outlook Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62555<\/td>\n<td width=\"469\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62558<\/td>\n<td width=\"469\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62559<\/td>\n<td width=\"469\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-64672<\/td>\n<td width=\"469\">Microsoft SharePoint Server Spoofing Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p><strong>Phrase (4 CVEs)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Essential severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62562<\/td>\n<td width=\"469\">Microsoft Outlook Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62555<\/td>\n<td width=\"469\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62558<\/td>\n<td width=\"469\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62559<\/td>\n<td width=\"469\">Microsoft Phrase Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p><strong>Alternate (2 CVEs)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-64666<\/td>\n<td width=\"469\">Microsoft Alternate Server Elevation of Privilege Vulnerability<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-64667<\/td>\n<td width=\"469\">Microsoft Alternate Server Spoofing Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p><strong>Entry (1 CVE)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62552<\/td>\n<td width=\"469\">Microsoft Entry Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Azure (1 CVE)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-62550<\/td>\n<td width=\"469\">Azure Monitor Agent Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>GitHub (1 CVE)<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">CVE-2025-64671<\/td>\n<td width=\"469\">GitHub Copilot for Jetbrains Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p><strong>Appendix D: Advisories and Different Merchandise<\/strong><\/p>\n<p>There are 14 Edge-related advisories famous in December\u2019s launch. All however CVE-2025-62223 originated with Chrome. All had been patched throughout the earlier week. Please notice that the Microsoft-issued CVE applies solely to Edge for Mac.<\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"123\">CVE-2025-13630<\/td>\n<td width=\"384\">Chromium: CVE-2025-13630 Kind Confusion in V8<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13631<\/td>\n<td width=\"384\">Chromium: CVE-2025-13631 Inappropriate implementation in Google Updater<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13632<\/td>\n<td width=\"384\">Chromium: CVE-2025-13632 Inappropriate implementation in DevTools<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13633<\/td>\n<td width=\"384\">Chromium: CVE-2025-13633 Use after free in Digital Credentials<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13634<\/td>\n<td width=\"384\">Chromium: CVE-2025-13634 Inappropriate implementation in Downloads<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13635<\/td>\n<td width=\"384\">Chromium: CVE-2025-13635 Inappropriate implementation in Downloads<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13636<\/td>\n<td width=\"384\">Chromium: CVE-2025-13636 Inappropriate implementation in Break up View<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13637<\/td>\n<td width=\"384\">Chromium: CVE-2025-13637 Inappropriate implementation in Downloads<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13638<\/td>\n<td width=\"384\">Chromium: CVE-2025-13638 Use after free in Media Stream<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13639<\/td>\n<td width=\"384\">Chromium: CVE-2025-13639 Inappropriate implementation in WebRTC<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13640<\/td>\n<td width=\"384\">Chromium: CVE-2025-13640 Inappropriate implementation in Passwords<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13720<\/td>\n<td width=\"384\">Chromium: CVE-2025-13720 Unhealthy forged in Loader<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13721<\/td>\n<td width=\"384\">Chromium: CVE-2025-13721 Race in v8<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-62223<\/td>\n<td width=\"384\">Microsoft Edge (Chromium-based) for Mac Spoofing Vulnerability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Adobe is releasing patches for 12 ColdFusion points in the present day with Bulletin APSB25-105. All 12 CVEs have an effect on ColdFusion 22, 16, 4 and earlier variations.<\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Essential severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-61808<\/td>\n<td width=\"479\">Unrestricted Add of File with Harmful Kind (CWE-434)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-61809<\/td>\n<td width=\"479\">Improper Enter Validation (CWE-20)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-61810<\/td>\n<td width=\"479\">Deserialization of Untrusted Information (CWE-502)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-61811<\/td>\n<td width=\"479\">Improper Entry Management (CWE-284)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-61812<\/td>\n<td width=\"479\">Improper Enter Validation (CWE-20)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-61813<\/td>\n<td width=\"479\">Improper Restriction of XML Exterior Entity Reference (\u2018XXE\u2019) (CWE-611)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-61830<\/td>\n<td width=\"479\">Deserialization of Untrusted Information (CWE-502)<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-61821<\/td>\n<td width=\"479\">Improper Restriction of XML Exterior Entity Reference (\u2018XXE\u2019) (CWE-611)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-61822<\/td>\n<td width=\"479\">Improper Enter Validation (CWE-20)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-61823<\/td>\n<td width=\"479\">Improper Restriction of XML Exterior Entity Reference (\u2018XXE\u2019) (CWE-611)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-64897<\/td>\n<td width=\"479\">Improper Entry Management (CWE-284)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-64898<\/td>\n<td width=\"479\">Insufficiently Protected Credentials (CWE-522)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p>Adobe can be releasing patches for 4 Adobe Reader points in the present day with Bulletin APSB25-119. All 4 CVEs have an effect on Reader variations 25.001.20982, 25.001.20668, 24.001.30273, 20.005.30793, 20.005.30803 and earlier.<\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Essential severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-64785<\/td>\n<td width=\"479\">Untrusted Search Path (CWE-426)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-64899<\/td>\n<td width=\"479\">Out-of-bounds Learn (CWE-125)<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\" width=\"601\"><strong>Reasonable severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-64786<\/td>\n<td width=\"479\">Improper Verification of Cryptographic Signature (CWE-347)<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-64787<\/td>\n<td width=\"479\">Improper Verification of Cryptographic Signature (CWE-347)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p>For data on the Mariner releases, please scroll to Appendix F.<\/p>\n<p><strong>Appendix E: Affected Home windows Server variations<\/strong><\/p>\n<p>This can be a desk of the 38 CVEs within the December launch affecting Home windows Server variations 2008 by means of 2025. The desk differentiates amongst main variations of the platform however doesn\u2019t go into deeper element (eg., Server Core). An \u201cx\u201d signifies that the CVE doesn&#8217;t apply to that model. Directors are inspired to make use of this appendix as a place to begin to establish their particular publicity, as every reader\u2019s state of affairs, particularly because it issues merchandise out of mainstream assist, will range. For particular Information Base numbers, please seek the advice of Microsoft.<\/p>\n<table width=\"561\">\n<tbody>\n<tr>\n<td width=\"116\"><strong>\u00a0<\/strong><\/td>\n<td width=\"45\"><strong>\u00a0<\/strong><\/td>\n<td width=\"57\"><strong>\u00a0<\/strong><\/td>\n<td width=\"47\"><strong>\u00a0<\/strong><\/td>\n<td width=\"50\"><strong>\u00a0<\/strong><\/td>\n<td width=\"43\"><strong>\u00a0<\/strong><\/td>\n<td width=\"57\"><strong>\u00a0<\/strong><\/td>\n<td width=\"47\"><strong>\u00a0<\/strong><\/td>\n<td width=\"50\"><strong>\u00a0<\/strong><\/td>\n<td width=\"50\"><strong>\u00a0<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"116\"\/>\n<td width=\"45\"\/>\n<td width=\"57\"\/>\n<td width=\"47\"\/>\n<td width=\"50\"\/>\n<td width=\"43\"\/>\n<td width=\"57\"\/>\n<td width=\"47\"\/>\n<td width=\"50\"\/>\n<td width=\"50\"\/>\n<\/tr>\n<tr>\n<td width=\"116\">CVE<\/td>\n<td width=\"45\">S-08<\/td>\n<td width=\"57\">8r2<\/td>\n<td width=\"47\">S-12<\/td>\n<td width=\"50\">12r2<\/td>\n<td width=\"43\">S-16<\/td>\n<td width=\"57\">S-19<\/td>\n<td width=\"47\">S-22<\/td>\n<td width=\"50\">23h2<\/td>\n<td width=\"50\">S-25<\/td>\n<\/tr>\n<tr>\n<td width=\"116\"\/>\n<td width=\"45\"\/>\n<td width=\"57\"\/>\n<td width=\"47\"\/>\n<td width=\"50\"\/>\n<td width=\"43\"\/>\n<td width=\"57\"\/>\n<td width=\"47\"\/>\n<td width=\"50\"\/>\n<td width=\"50\"\/>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-54100<\/td>\n<td width=\"45\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-55233<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-59516<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-59517<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62221<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62454<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62455<\/td>\n<td width=\"45\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62456<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62457<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62458<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62461<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62462<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62463<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62464<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62465<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62466<\/td>\n<td width=\"45\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62467<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62468<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62469<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62470<\/td>\n<td width=\"45\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62472<\/td>\n<td width=\"45\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62473<\/td>\n<td width=\"45\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62474<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62549<\/td>\n<td width=\"45\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62565<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62567<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62569<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62570<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62571<\/td>\n<td width=\"45\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62572<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-62573<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-64658<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-64661<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-64670<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-64673<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u00d7<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-64678<\/td>\n<td width=\"45\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-64679<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<tr>\n<td width=\"116\">CVE-2025-64680<\/td>\n<td width=\"45\">\u00d7<\/td>\n<td width=\"57\">\u00d7<\/td>\n<td width=\"47\">\u00d7<\/td>\n<td width=\"50\">\u00d7<\/td>\n<td width=\"43\">\u25a0<\/td>\n<td width=\"57\">\u25a0<\/td>\n<td width=\"47\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<td width=\"50\">\u25a0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong><br \/>Appendix F: CBL Mariner \/ Azure Linux<\/strong><\/p>\n<p>The next desk gives data on 84 CVEs referring to CBL Mariner and \/ or Azure Linux. All 84 are listed by Microsoft as beneath exploit within the wild. That mentioned, 5 of them even have CVSS Base numbers over 8.5, and we point out these in pink for these needing to prioritize. The CVEs are grouped by severity and additional ordered by CVE.<\/p>\n<table width=\"604\">\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"604\"><strong>Essential severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"color: #ff0000\">CVE-2025-40242<\/span><\/td>\n<td width=\"482\"><span style=\"color: #ff0000\">gfs2: Repair unlikely race in gdlm_put_lock<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"color: #ff0000\">CVE-2025-40244<\/span><\/td>\n<td width=\"482\"><span style=\"color: #ff0000\">hfsplus: repair KMSAN uninit-value difficulty in __hfsplus_ext_cache_extent()<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"color: #ff0000\">CVE-2025-40251<\/span><\/td>\n<td width=\"482\"><span style=\"color: #ff0000\">devlink: fee: Unset guardian pointer in devl_rate_nodes_destroy<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"color: #ff0000\">CVE-2025-40262<\/span><\/td>\n<td width=\"482\"><span style=\"color: #ff0000\">Enter: imx_sc_key \u2013 repair reminiscence corruption on unload<\/span><\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\" width=\"604\"><strong>Necessary severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-12385<\/td>\n<td width=\"482\">Improper validation of\u00a0\u00a0tag measurement in Textual content part parser<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-12819<\/td>\n<td width=\"482\">Untrusted search path in auth_query connection in PgBouncer<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-34297<\/td>\n<td width=\"482\">KissFFT Integer Overflow Heap Buffer Overflow by way of kiss_fft_alloc<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40223<\/td>\n<td width=\"482\">most: usb: Repair use-after-free in hdm_disconnect<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40233<\/td>\n<td width=\"482\">ocfs2: clear extent cache after transferring\/defragmenting extents<\/td>\n<\/tr>\n<tr>\n<td width=\"123\"><span style=\"color: #ff0000\">CVE-2025-40240<\/span><\/td>\n<td width=\"482\"><span style=\"color: #ff0000\">sctp: keep away from NULL dereference when chunk information buffer is lacking<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40258<\/td>\n<td width=\"482\">mptcp: repair race situation in mptcp_schedule_work()<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40272<\/td>\n<td width=\"482\">mm\/secretmem: repair use-after-free race in fault handler<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40312<\/td>\n<td width=\"482\">jfs: Confirm inode mode when loading from disk<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40314<\/td>\n<td width=\"482\">usb: cdns3: gadget: Use-after-free throughout failed initialization and exit of cdnsp gadget<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40319<\/td>\n<td width=\"482\">bpf: Sync pending IRQ work earlier than liberating ring buffer<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-59775<\/td>\n<td width=\"482\">Apache HTTP Server: NTLM Leakage on Home windows by means of UNC SSRF<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-61729<\/td>\n<td width=\"482\">Extreme useful resource consumption when printing error string for host certificates validation in crypto\/x509<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-66476<\/td>\n<td width=\"482\">Vim for Home windows Uncontrolled Search Path Factor Distant Code Execution Vulnerability<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\" width=\"604\"><strong>Reasonable severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2023-53749<\/td>\n<td width=\"482\">x86: repair clear_user_rep_good() exception dealing with annotation<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-12084<\/td>\n<td width=\"482\">Quadratic complexity in node ID cache clearing<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13836<\/td>\n<td width=\"482\">Extreme learn buffering DoS in http.shopper<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40215<\/td>\n<td width=\"482\">xfrm: delete x-&gt;tunnel as we delete x<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40217<\/td>\n<td width=\"482\">pidfs: validate extensible ioctls<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40218<\/td>\n<td width=\"482\">mm\/damon\/vaddr: don&#8217;t repeat pte_offset_map_lock() till success<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40219<\/td>\n<td width=\"482\">PCI\/IOV: Add PCI rescan-remove locking when enabling\/disabling SR-IOV<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40220<\/td>\n<td width=\"482\">fuse: repair livelock in synchronous file put from fuseblk employees<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40243<\/td>\n<td width=\"482\">hfs: repair KMSAN uninit-value difficulty in hfs_find_set_zero_bits()<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40245<\/td>\n<td width=\"482\">nios2: be sure that memblock.current_limit is ready when setting pfn limits<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40247<\/td>\n<td width=\"482\">drm\/msm: Repair pgtable prealloc error path<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40248<\/td>\n<td width=\"482\">vsock: Ignore sign\/timeout on join() if already established<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40250<\/td>\n<td width=\"482\">web\/mlx5: Clear up solely new IRQ glue on request_irq() failure<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40252<\/td>\n<td width=\"482\">web: qlogic\/qede: repair potential out-of-bounds learn in qede_tpa_cont() and qede_tpa_end()<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40253<\/td>\n<td width=\"482\">s390\/ctcm: Repair double-kfree<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40254<\/td>\n<td width=\"482\">web: openvswitch: take away never-working assist for setting nsh fields<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40257<\/td>\n<td width=\"482\">mptcp: repair a race in mptcp_pm_del_add_timer()<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40259<\/td>\n<td width=\"482\">scsi: sg: Don&#8217;t sleep in atomic context<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40261<\/td>\n<td width=\"482\">nvme: nvme-fc: Guarantee -&gt;ioerr_work is cancelled in nvme_fc_delete_ctrl()<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40263<\/td>\n<td width=\"482\">Enter: cros_ec_keyb \u2013 repair an invalid reminiscence entry<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40264<\/td>\n<td width=\"482\">be2net: move wrb_params in case of OS2BMC<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40266<\/td>\n<td width=\"482\">KVM: arm64: Verify the untrusted offset in FF-A reminiscence share<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40268<\/td>\n<td width=\"482\">cifs: shopper: repair reminiscence leak in smb3_fs_context_parse_param<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40269<\/td>\n<td width=\"482\">ALSA: usb-audio: Repair potential overflow of PCM switch buffer<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40273<\/td>\n<td width=\"482\">NFSD: free copynotify stateid in nfs4_free_ol_stateid()<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40275<\/td>\n<td width=\"482\">ALSA: usb-audio: Repair NULL pointer dereference in snd_usb_mixer_controls_badd<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40277<\/td>\n<td width=\"482\">drm\/vmwgfx: Validate command header measurement towards SVGA_CMD_MAX_DATASIZE<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40278<\/td>\n<td width=\"482\">web: sched: act_ife: initialize struct tc_ife to repair KMSAN kernel-infoleak<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40279<\/td>\n<td width=\"482\">web: sched: act_connmark: initialize struct tc_ife to repair kernel leak<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40280<\/td>\n<td width=\"482\">tipc: Repair use-after-free in tipc_mon_reinit_self().<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40281<\/td>\n<td width=\"482\">sctp: forestall potential shift-out-of-bounds in sctp_transport_update_rto<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40282<\/td>\n<td width=\"482\">Bluetooth: 6lowpan: reset link-local header on ipv6 recv path<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40283<\/td>\n<td width=\"482\">Bluetooth: btusb: reorder cleanup in btusb_disconnect to keep away from UAF<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40284<\/td>\n<td width=\"482\">Bluetooth: MGMT: cancel mesh ship timer when hdev eliminated<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40285<\/td>\n<td width=\"482\">smb\/server: repair potential refcount leak in smb2_sess_setup()<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40286<\/td>\n<td width=\"482\">smb\/server: repair potential reminiscence leak in smb2_read()<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40287<\/td>\n<td width=\"482\">exfat: repair improper test of dentry.stream.valid_size<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40288<\/td>\n<td width=\"482\">drm\/amdgpu: Repair NULL pointer dereference in VRAM logic for APU gadgets<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40289<\/td>\n<td width=\"482\">drm\/amdgpu: cover VRAM sysfs attributes on GPUs with out VRAM<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40292<\/td>\n<td width=\"482\">virtio-net: repair acquired size test in massive packets<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40293<\/td>\n<td width=\"482\">iommufd: Don\u2019t overflow throughout division for soiled monitoring<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40294<\/td>\n<td width=\"482\">Bluetooth: MGMT: Repair OOB entry in parse_adv_monitor_pattern()<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40297<\/td>\n<td width=\"482\">web: bridge: repair use-after-free because of MST port state bypass<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40301<\/td>\n<td width=\"482\">Bluetooth: hci_event: validate skb size for unknown CC opcode<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40303<\/td>\n<td width=\"482\">btrfs: guarantee no soiled metadata is written again for an fs with errors<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40304<\/td>\n<td width=\"482\">fbdev: Add bounds checking in bit_putcs to repair vmalloc-out-of-bounds<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40305<\/td>\n<td width=\"482\">9p\/trans_fd: p9_fd_request: kick rx thread if EPOLLIN<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40306<\/td>\n<td width=\"482\">orangefs: repair xattr associated buffer overflow\u2026<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40307<\/td>\n<td width=\"482\">exfat: validate cluster allocation bits of the allocation bitmap<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40308<\/td>\n<td width=\"482\">Bluetooth: bcsp: obtain information provided that registered<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40309<\/td>\n<td width=\"482\">Bluetooth: SCO: Repair UAF on sco_conn_free<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40310<\/td>\n<td width=\"482\">amd\/amdkfd: resolve a race in amdgpu_amdkfd_device_fini_sw<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40311<\/td>\n<td width=\"482\">accel\/habanalabs: assist mapping cb with vmalloc-backed coherent reminiscence<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40313<\/td>\n<td width=\"482\">ntfs3: faux $Prolong data as common recordsdata<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40315<\/td>\n<td width=\"482\">usb: gadget: f_fs: Repair epfile null pointer entry after ep allow.<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40317<\/td>\n<td width=\"482\">regmap: slimbus: repair bus_context pointer in regmap init calls<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40321<\/td>\n<td width=\"482\">wifi: brcmfmac: repair crash whereas sending Motion Frames in standalone AP Mode<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40322<\/td>\n<td width=\"482\">fbdev: bitblit: bound-check glyph index in bit_putcs*<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40323<\/td>\n<td width=\"482\">fbcon: Set fb_display[i]-&gt;mode to NULL when the mode is launched<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-40324<\/td>\n<td width=\"482\">NFSD: Repair crash in nfsd4_read_release()<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-61727<\/td>\n<td width=\"482\">Improper utility of excluded DNS identify constraints when verifying wildcard names in crypto\/x509<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-65082<\/td>\n<td width=\"482\">Apache HTTP Server: CGI setting variable override<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-65637<\/td>\n<td width=\"482\">A denial-of-service vulnerability exists in github.com\/sirupsen\/logrus when utilizing Entry.Author() to log a single-line payload bigger than 64KB with out newline characters.<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-66200<\/td>\n<td width=\"482\">Apache HTTP Server: mod_userdir+suexec bypass by way of AllowOverride FileInfo<\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-66293<\/td>\n<td width=\"482\">LIBPNG has an out-of-bounds learn in png_image_read_composite<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\" width=\"604\"><strong>Low severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"123\">CVE-2025-13837<\/td>\n<td width=\"482\">Out-of-memory when loading Plist<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Microsoft on Tuesday launched 56 patches affecting 10 product households. Two of the addressed points are thought-about by Microsoft to be of Essential severity \u2013 and, unusually, each belong to the blended Workplace-365 product household. Eight have a CVSS base rating of 8.0 or greater. One is understood to be beneath energetic exploit within the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":9671,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[98,6838,3066,121,1077,120,1078],"class_list":["post-9669","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-big","tag-decembers","tag-finish","tag-news","tag-patch","tag-sophos","tag-tuesday"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9669","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9669"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9669\/revisions"}],"predecessor-version":[{"id":9670,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9669\/revisions\/9670"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/9671"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-05 04:52:01 UTC -->