
Microsoft’s November 2025 Patch Tuesday has 63 vulnerabilities, of which 29 are Elevation of Privilege. The SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of November 2025 and has produced coverage for 5 of the reported vulnerabilities
CVE | CVE Title | Signature |
| CVE-2025-59512 | Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability | ASPY 7144 Malformed-reg reg.MP_1 |
| CVE-2025-60705 | Windows Client-Side Caching Elevation of Privilege Vulnerability | IPS 21637 Windows Client-Side Caching Privilege Escalation (CVE-2025-60705) |
| CVE-2025-60719 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | ASPY 7145 Exploit-exe exe.MP_477 |
| CVE-2025-62213 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | ASPY 658 Exploit-exe exe.MP_479 |
| CVE-2025-62215 | Windows Kernel Elevation of Privilege Vulnerability | ASPY 657 Exploit-exe exe.MP_478 |
The vulnerabilities can be classified into the following categories:


For November, there are 5 critical and 58 important vulnerabilities.


Microsoft tracks vulnerabilities that are being actively exploited at the time of discovery and those that have been disclosed publicly before the patch Tuesday release for each month. The above chart displays these metrics as seen each month.

Denial of Service Vulnerabilities
| CVE | CVE Title |
| CVE-2025-59510 | Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability |
| CVE-2025-60708 | Storvsp.sys Driver Denial of Service Vulnerability |
| CVE-2025-60723 | DirectX Graphics Kernel Denial of Service Vulnerability |
Elevation of Privilege Vulnerabilities
| CVE | CVE Title |
| CVE-2025-47179 | Configuration Manager Elevation of Privilege Vulnerability |
| CVE-2025-59499 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2025-59505 | Windows Smart Card Reader Elevation of Privilege Vulnerability |
| CVE-2025-59506 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2025-59507 | Windows Speech Runtime Elevation of Privilege Vulnerability |
| CVE-2025-59508 | Windows Speech Recognition Elevation of Privilege Vulnerability |
| CVE-2025-59511 | Windows WLAN Service Elevation of Privilege Vulnerability |
| CVE-2025-59512 | Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability |
| CVE-2025-59514 | Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability |
| CVE-2025-59515 | Windows Broadcast DVR User Service Elevation of Privilege Vulnerability |
| CVE-2025-60703 | Windows Remote Desktop Services Elevation of Privilege Vulnerability |
| CVE-2025-60704 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2025-60705 | Windows Client-Side Caching Elevation of Privilege Vulnerability |
| CVE-2025-60707 | Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability |
| CVE-2025-60709 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2025-60710 | Host Process for Windows Tasks Elevation of Privilege Vulnerability |
| CVE-2025-60713 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability |
| CVE-2025-60716 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2025-60717 | Windows Broadcast DVR User Service Elevation of Privilege Vulnerability |
| CVE-2025-60718 | Windows Administrator Protection Elevation of Privilege Vulnerability |
| CVE-2025-60719 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2025-60720 | Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability |
| CVE-2025-60721 | Windows Administrator Protection Elevation of Privilege Vulnerability |
| CVE-2025-60722 | Microsoft OneDrive for Android Elevation of Privilege Vulnerability |
| CVE-2025-62213 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2025-62215 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2025-62217 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2025-62218 | Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability |
| CVE-2025-62219 | Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability |
Information Disclosure Vulnerabilities
| CVE | CVE Title |
| CVE-2025-30398 | Nuance PowerScribe 360 Information Disclosure Vulnerability |
| CVE-2025-59240 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2025-59509 | Windows Speech Recognition Information Disclosure Vulnerability |
| CVE-2025-59513 | Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability |
| CVE-2025-60706 | Windows Hyper-V Information Disclosure Vulnerability |
| CVE-2025-60726 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2025-60728 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2025-62201 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2025-62202 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2025-62206 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
| CVE-2025-62208 | Windows License Manager Information Disclosure Vulnerability |
| CVE-2025-62209 | Windows License Manager Information Disclosure Vulnerability |
Remote Code Execution Vulnerabilities
| CVE | CVE Title |
| CVE-2025-59504 | Azure Monitor Agent Remote Code Execution Vulnerability |
| CVE-2025-60714 | Windows OLE Remote Code Execution Vulnerability |
| CVE-2025-60715 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| CVE-2025-60724 | GDI+ Remote Code Execution Vulnerability |
| CVE-2025-60727 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2025-62199 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2025-62200 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2025-62203 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2025-62204 | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2025-62205 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2025-62214 | Visual Studio Remote Code Execution Vulnerability |
| CVE-2025-62216 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2025-62220 | Windows Subsystem for Linux GUI Remote Code Execution Vulnerability |
| CVE-2025-62222 | Agentic AI and Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2025-62452 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
Security Feature Bypass Vulnerabilities
| CVE | CVE Title |
| CVE-2025-62449 | Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability |
| CVE-2025-62453 | GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability |
Spoofing Vulnerabilities
| CVE | CVE Title |
| CVE-2025-62210 | Dynamics 365 Field Service (online) Spoofing Vulnerability |
| CVE-2025-62211 | Dynamics 365 Field Service (online) Spoofing Vulnerability |
Share This Article

An Article By
An Article By
Security News
Security News