Threat intelligence

Microsoft Security Bulletin Coverage for December 2025

by Security News

Overview

Microsoft’s December 2025 Patch Tuesday has 55 vulnerabilities, of which 27 are Elevation of Privilege. SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of December 2025 and has produced coverage for 7 of the reported vulnerabilities.

Vulnerabilities with Detections

CVE

CVE Title

Signature

CVE-2025-59516Windows Storage VSP Driver Elevation of Privilege VulnerabilityASPY 7154 Exploit-exe exe.MP_481
CVE-2025-59517Windows Storage VSP Driver Elevation of Privilege VulnerabilityASPY 7155 Exploit-exe exe.MP_482
CVE-2025-62221Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityASPY 7152 Exploit-exe exe.MP_480
CVE-2025-62454Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityASPY 7156 Exploit-exe exe.MP_486
CVE-2025-62458Win32k Elevation of Privilege VulnerabilityASPY 661 Exploit-exe exe.MP_485
CVE-2025-62470Windows Common Log File System Driver Elevation of Privilege VulnerabilityASPY 660 Exploit-exe exe.MP_484
CVE-2025-62472Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityASPY 659 Exploit-exe exe.MP_483

Release Breakdown

The vulnerabilities can be classified into the following categories:

Dec_2025_chart_impact_1.png

 

Dec_2025_chart_severity_2.png

For December, there are 2 critical and 52 important vulnerabilities.

 

Dec_2025_chart_Vul_count_3.png
Dec_2025_chart_expl_dis_4.png

Microsoft tracks vulnerabilities that are being actively exploited at the time of discovery and those that have been disclosed publicly before the patch Tuesday release for each month. The above chart displays these metrics as seen each month.

 

Dec_2025_chart_expl_assesment_5.png

Release Detailed Breakdown

Denial of Service Vulnerabilities

CVECVE Title
CVE-2025-62463DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-62465DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-62567Windows Hyper-V Denial of Service Vulnerability

Elevation of Privilege Vulnerabilities

CVECVE Title
CVE-2025-59516Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVE-2025-59517Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVE-2025-62221Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-62454Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-62455Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2025-62457Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-62458Win32k Elevation of Privilege Vulnerability
CVE-2025-62461Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62462Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62464Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62466Windows Client-Side Caching Elevation of Privilege Vulnerability
CVE-2025-62467Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62469Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-62470Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-62472Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2025-62474Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2025-62565Windows File Explorer Elevation of Privilege Vulnerability
CVE-2025-62569Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-62571Windows Installer Elevation of Privilege Vulnerability
CVE-2025-62572Application Information Service Elevation of Privilege Vulnerability
CVE-2025-62573DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-64658Windows File Explorer Elevation of Privilege Vulnerability
CVE-2025-64661Windows Shell Elevation of Privilege Vulnerability
CVE-2025-64666Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-64673Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVE-2025-64679Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-64680Windows DWM Core Library Elevation of Privilege Vulnerability

Information Disclosure Vulnerabilities

CVECVE Title
CVE-2025-62468Windows Defender Firewall Service Information Disclosure Vulnerability
CVE-2025-62473Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-62570Windows Camera Frame Server Monitor Information Disclosure Vulnerability
CVE-2025-64670Windows DirectX Information Disclosure Vulnerability

Remote Code Execution Vulnerabilities

CVECVE Title
CVE-2025-62456Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVE-2025-62549Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-62550Azure Monitor Agent Remote Code Execution Vulnerability
CVE-2025-62552Microsoft Access Remote Code Execution Vulnerability
CVE-2025-62553Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62554Microsoft Office Remote Code Execution Vulnerability
CVE-2025-62555Microsoft Word Remote Code Execution Vulnerability
CVE-2025-62556Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62557Microsoft Office Remote Code Execution Vulnerability
CVE-2025-62558Microsoft Word Remote Code Execution Vulnerability
CVE-2025-62559Microsoft Word Remote Code Execution Vulnerability
CVE-2025-62560Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62561Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62562Microsoft Outlook Remote Code Execution Vulnerability
CVE-2025-62563Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62564Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-64671GitHub Copilot for Jetbrains Remote Code Execution Vulnerability
CVE-2025-64678Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Spoofing Vulnerabilities

CVECVE Title
CVE-2025-64667Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-64672Microsoft SharePoint Server Spoofing Vulnerability

 

 

 

Share This Article

An Article By

Security News

The SonicWall Capture Labs Threat Research Team gathers, analyzes and vets cross-vector threat information from the SonicWall Capture Threat network, consisting of global devices and resources, including more than 1 million security sensors in nearly 200 countries and territories. The research team identifies, analyzes, and mitigates critical vulnerabilities and malware daily through in-depth research, which drives protection for all SonicWall customers. In addition to safeguarding networks globally, the research team supports the larger threat intelligence community by releasing weekly deep technical analyses of the most critical threats to small businesses, providing critical knowledge that defenders need to protect their networks.

Related Articles

  • Nested Deserialization to RCE in Adobe Commerce & Magento (CVE-2025-54236)
    Read More
  • Command Injection in HuangDou UTCMS (CVE-2024-9916) Enables RCE
    Read More