Skip to main content
QUIETLYTIC
Advisory

Microsoft Patch Tuesday December 2025: 349 Vulnerabilities Fixed

Microsoft's December 9, 2025 Patch Tuesday fixed 349 vulnerabilities (15 critical, 115 important) — none are currently listed as actively exploited, per CISA…

Microsoft Patch Tuesday December 2025: 349 Vulnerabilities Fixed — Advisory research covering CVE-2025-65037, CVE-2025-65041, CVE-2025-64663, CVE-2025-40242, CVE-2025-40244, CVE-2025-40251, CVE-2025-40262, CVE-2025-68615, CVE-2025-68206, CVE-2025-62554, CVE-2025-62557, CVE-2025-64675, CVE-2025-64677, CVE-2025-64676, CVE-2025-68193, CVE-2025-34468, CVE-2025-68196, CVE-2025-62456, CVE-2025-62549, CVE-2025-62550, CVE-2025-64672, CVE-2025-64678, CVE-2025-40240, CVE-2025-40362, CVE-2025-64671, CVE-2025-58098, CVE-2025-14523, CVE-2025-2296, CVE-2023-54207, CVE-2025-40223, CVE-2025-40272, CVE-2025-40314, CVE-2025-40319, CVE-2025-48637, CVE-2025-66476, CVE-2025-68188, CVE-2025-68190, CVE-2025-68227, CVE-2025-68237, CVE-2025-68285, CVE-2025-68290, CVE-2025-68303, CVE-2025-68311, CVE-2025-68315, CVE-2025-68346, CVE-2025-68973, CVE-2025-54100, CVE-2025-55233, CVE-2025-59516, CVE-2025-59517, CVE-2025-62221, CVE-2025-62454, CVE-2025-62455, CVE-2025-62457, CVE-2025-62458, CVE-2025-62461, CVE-2025-62462, CVE-2025-62464, CVE-2025-62466, CVE-2025-62467, CVE-2025-62470, CVE-2025-62472, CVE-2025-62474, CVE-2025-62552, CVE-2025-62553, CVE-2025-62556, CVE-2025-62558, CVE-2025-62559, CVE-2025-62560, CVE-2025-62561, CVE-2025-62562, CVE-2025-62563, CVE-2025-62564, CVE-2025-62571, CVE-2025-62572, CVE-2025-64661, CVE-2025-64669, CVE-2025-64673, CVE-2025-64679, CVE-2025-64680, CVE-2025-12819, CVE-2025-15284, CVE-2025-59775, CVE-2025-61729, CVE-2025-68156, CVE-2025-68255, CVE-2025-68256, CVE-2025-68265, CVE-2025-64658, CVE-2025-64666, CVE-2025-68261, CVE-2025-62565, CVE-2025-40233, CVE-2025-40312, CVE-2025-68174, CVE-2025-68224, CVE-2025-68231, CVE-2025-68235, CVE-2025-68254, CVE-2025-68266, CVE-2025-68283, CVE-2025-68301, CVE-2025-68331, CVE-2025-62570, CVE-2025-13699, CVE-2025-40258, CVE-2025-68284, CVE-2025-68287, CVE-2025-68297, CVE-2025-68304, CVE-2025-68307, CVE-2025-68367, CVE-2025-68380, CVE-2025-68729, CVE-2025-62469, CVE-2025-62555, CVE-2025-62569, CVE-2025-62573, CVE-2025-62463, CVE-2025-62465, CVE-2025-62473, CVE-2025-64670, CVE-2025-62468, CVE-2025-62567, CVE-2025-64667, CVE-2025-12385, CVE-2025-34297, CVE-2025-66418, CVE-2025-66471, CVE-2025-68476, CVE-2025-55753, CVE-2025-40277, CVE-2025-40345, CVE-2023-53749, CVE-2025-40266, CVE-2025-40283, CVE-2025-40301, CVE-2025-40322, CVE-2025-66293, CVE-2025-40273, CVE-2025-40280, CVE-2025-40281, CVE-2025-40292, CVE-2025-40297, CVE-2025-40305, CVE-2025-40328, CVE-2025-40329, CVE-2025-40331, CVE-2025-40336, CVE-2025-40338
Severity
Critical
Confidence
High
Status
Active

Full CVE Roster

All 150 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search — 1 flagged as actively exploited (KEV).

CVE ID Title CVSS Severity KEV
CVE-2025-65037 Azure Container Apps Remote Code Execution Vulnerability 10.0 critical
CVE-2025-65041 Microsoft Partner Center Elevation of Privilege Vulnerability 10.0 critical
CVE-2025-64663 Custom Question Answering Elevation of Privilege Vulnerability 9.9 critical
CVE-2025-40242 gfs2: Fix unlikely race in gdlm_put_lock 9.8 critical
CVE-2025-40244 hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent() 9.8 critical
CVE-2025-40251 devlink: rate: Unset parent pointer in devl_rate_nodes_destroy 9.8 critical
CVE-2025-40262 Input: imx_sc_key - fix memory corruption on unload 9.8 critical
CVE-2025-68615 Net-SNMP snmptrapd crash 9.8 critical
CVE-2025-68206 netfilter: nft_ct: add seqadj extension for natted connections 9.1 critical
CVE-2025-62554 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2025-62557 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2025-64675 Azure Cosmos DB Spoofing Vulnerability 8.3 critical
CVE-2025-64677 Office Out-of-Box Experience Spoofing Vulnerability 8.2 critical
CVE-2025-64676 Microsoft Purview eDiscovery Remote Code Execution Vulnerability 7.2 critical
CVE-2025-68193 drm/xe/guc: Add devm release action to safely tear down CT — critical
CVE-2025-34468 libcoap Stack-Based Buffer Overflow in Address Resolution DoS or Potential RCE 9.8 high
CVE-2025-68196 drm/amd/display: Cache streams targeting link when performing LT automation 8.8 high
CVE-2025-62456 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability 8.8 high
CVE-2025-62549 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 8.8 high
CVE-2025-62550 Azure Monitor Agent Remote Code Execution Vulnerability 8.8 high
CVE-2025-64672 Microsoft SharePoint Server Spoofing Vulnerability 8.8 high
CVE-2025-64678 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 8.8 high
CVE-2025-40240 sctp: avoid NULL dereference when chunk data buffer is missing 8.6 high
CVE-2025-40362 ceph: fix multifs mds auth caps issue 8.4 high
CVE-2025-64671 GitHub Copilot for Jetbrains Remote Code Execution Vulnerability 8.4 high
CVE-2025-58098 Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... 8.3 high
CVE-2025-14523 Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins) 8.2 high
CVE-2025-2296 Un-verified kernel bypass Secure Boot mechanism in direct boot mode 8.2 high
CVE-2023-54207 HID: uclogic: Correct devm device reference for hidinput input_dev name 7.8 high
CVE-2025-40223 most: usb: Fix use-after-free in hdm_disconnect 7.8 high
CVE-2025-40272 mm/secretmem: fix use-after-free race in fault handler 7.8 high
CVE-2025-40314 usb: cdns3: gadget: Use-after-free during failed initialization and exit of cdnsp gadget 7.8 high
CVE-2025-40319 bpf: Sync pending IRQ work before freeing ring buffer 7.8 high
CVE-2025-48637 In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. 7.8 high
CVE-2025-66476 Vim for Windows Uncontrolled Search Path Element Remote Code Execution Vulnerability 7.8 high
CVE-2025-68188 tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() 7.8 high
CVE-2025-68190 drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked() 7.8 high
CVE-2025-68227 mptcp: Fix proto fallback detection with BPF 7.8 high
CVE-2025-68237 mtdchar: fix integer overflow in read/write ioctls 7.8 high
CVE-2025-68285 libceph: fix potential use-after-free in have_mon_and_osd_map() 7.8 high
CVE-2025-68290 most: usb: fix double free on late probe failure 7.8 high
CVE-2025-68303 platform/x86: intel: punit_ipc: fix memory corruption 7.8 high
CVE-2025-68311 tty: serial: ip22zilog: Use platform device for probing 7.8 high
CVE-2025-68315 f2fs: fix to detect potential corrupted nid in free_nid_list 7.8 high
CVE-2025-68346 ALSA: dice: fix buffer overflow in detect_stream_formats() 7.8 high
CVE-2025-68973 In GnuPG through 2.4.8, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.) 7.8 high
CVE-2025-54100 PowerShell Remote Code Execution Vulnerability 7.8 high
CVE-2025-55233 Windows Projected File System Elevation of Privilege Vulnerability 7.8 high
CVE-2025-59516 Windows Storage VSP Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2025-59517 Windows Storage VSP Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62221 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 7.8 high Yes
CVE-2025-62454 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62455 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62457 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62458 Win32k Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62461 Windows Projected File System Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62462 Windows Projected File System Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62464 Windows Projected File System Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62466 Windows Client-Side Caching Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62467 Windows Projected File System Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62470 Windows Common Log File System Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62472 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62474 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62552 Microsoft Access Remote Code Execution Vulnerability 7.8 high
CVE-2025-62553 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2025-62556 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2025-62558 Microsoft Word Remote Code Execution Vulnerability 7.8 high
CVE-2025-62559 Microsoft Word Remote Code Execution Vulnerability 7.8 high
CVE-2025-62560 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2025-62561 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2025-62562 Microsoft Outlook Remote Code Execution Vulnerability 7.8 high
CVE-2025-62563 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2025-62564 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2025-62571 Windows Installer Elevation of Privilege Vulnerability 7.8 high
CVE-2025-62572 Application Information Service Elevation of Privilege Vulnerability 7.8 high
CVE-2025-64661 Windows Shell Elevation of Privilege Vulnerability 7.8 high
CVE-2025-64669 Windows Admin Center Elevation of Privilege Vulnerability 7.8 high
CVE-2025-64673 Windows Storage VSP Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2025-64679 Windows DWM Core Library Elevation of Privilege Vulnerability 7.8 high
CVE-2025-64680 Windows DWM Core Library Elevation of Privilege Vulnerability 7.8 high
CVE-2025-12819 Untrusted search path in auth_query connection in PgBouncer 7.5 high
CVE-2025-15284 arrayLimit bypass in bracket notation allows DoS via memory exhaustion 7.5 high
CVE-2025-59775 Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF 7.5 high
CVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 7.5 high
CVE-2025-68156 Expr has Denial of Service via Unbounded Recursion in Builtin Functions 7.5 high
CVE-2025-68255 staging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing 7.5 high
CVE-2025-68256 staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser 7.5 high
CVE-2025-68265 nvme: fix admin request_queue lifetime 7.5 high
CVE-2025-64658 Windows File Explorer Elevation of Privilege Vulnerability 7.5 high
CVE-2025-64666 Microsoft Exchange Server Elevation of Privilege Vulnerability 7.5 high
CVE-2025-68261 ext4: add i_data_sem protection in ext4_destroy_inline_data_nolock() 7.3 high
CVE-2025-62565 Windows File Explorer Elevation of Privilege Vulnerability 7.3 high
CVE-2025-40233 ocfs2: clear extent cache after moving/defragmenting extents 7.1 high
CVE-2025-40312 jfs: Verify inode mode when loading from disk 7.1 high
CVE-2025-68174 amd/amdkfd: enhance kfd process check in switch partition 7.1 high
CVE-2025-68224 scsi: core: Fix a regression triggered by scsi_host_busy() 7.1 high
CVE-2025-68231 mm/mempool: fix poisoning order>0 pages with HIGHMEM 7.1 high
CVE-2025-68235 nouveau/firmware: Add missing kfree() of nvkm_falcon_fw::boot 7.1 high
CVE-2025-68254 staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing 7.1 high
CVE-2025-68266 bfs: Reconstruct file type when loading from disk 7.1 high
CVE-2025-68283 libceph: replace BUG_ON with bounds check for map->max_osd 7.1 high
CVE-2025-68301 net: atlantic: fix fragment overflow handling in RX path 7.1 high
CVE-2025-68331 usb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer 7.1 high
CVE-2025-62570 Windows Camera Frame Server Monitor Information Disclosure Vulnerability 7.1 high
CVE-2025-13699 MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability 7.0 high
CVE-2025-40258 mptcp: fix race condition in mptcp_schedule_work() 7.0 high
CVE-2025-68284 libceph: prevent potential out-of-bounds writes in handle_auth_session_key() 7.0 high
CVE-2025-68287 usb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call paths 7.0 high
CVE-2025-68297 ceph: fix crash in process_v2_sparse_read() for encrypted directories 7.0 high
CVE-2025-68304 Bluetooth: hci_core: lookup hci_conn on RX path on protocol side 7.0 high
CVE-2025-68307 can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs 7.0 high
CVE-2025-68367 macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse 7.0 high
CVE-2025-68380 wifi: ath11k: fix peer HE MCS assignment 7.0 high
CVE-2025-68729 wifi: ath12k: Fix MSDU buffer types handling in RX error path 7.0 high
CVE-2025-62469 Microsoft Brokering File System Elevation of Privilege Vulnerability 7.0 high
CVE-2025-62555 Microsoft Word Remote Code Execution Vulnerability 7.0 high
CVE-2025-62569 Microsoft Brokering File System Elevation of Privilege Vulnerability 7.0 high
CVE-2025-62573 DirectX Graphics Kernel Elevation of Privilege Vulnerability 7.0 high
CVE-2025-62463 DirectX Graphics Kernel Denial of Service Vulnerability 6.5 high
CVE-2025-62465 DirectX Graphics Kernel Denial of Service Vulnerability 6.5 high
CVE-2025-62473 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability 6.5 high
CVE-2025-64670 Windows DirectX Information Disclosure Vulnerability 6.5 high
CVE-2025-62468 Windows Defender Firewall Service Information Disclosure Vulnerability 5.5 high
CVE-2025-62567 Windows Hyper-V Denial of Service Vulnerability 5.3 high
CVE-2025-64667 Microsoft Exchange Server Spoofing Vulnerability 5.3 high
CVE-2025-12385 Improper validation of <img> tag size in Text component parser — high
CVE-2025-34297 KissFFT Integer Overflow Heap Buffer Overflow via kiss_fft_alloc — high
CVE-2025-66418 urllib3 allows an unbounded number of links in the decompression chain — high
CVE-2025-66471 urllib3 Streaming API improperly handles highly compressed data — high
CVE-2025-68476 KEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Credential — high
CVE-2025-55753 Apache HTTP Server: mod_md (ACME), unintended retry intervals 7.5 medium
CVE-2025-40277 drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE 7.3 medium
CVE-2025-40345 usb: storage: sddr55: Reject out-of-bound new_pba 7.3 medium
CVE-2023-53749 x86: fix clear_user_rep_good() exception handling annotation 7.1 medium
CVE-2025-40266 KVM: arm64: Check the untrusted offset in FF-A memory share 7.1 medium
CVE-2025-40283 Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF 7.1 medium
CVE-2025-40301 Bluetooth: hci_event: validate skb length for unknown CC opcode 7.1 medium
CVE-2025-40322 fbdev: bitblit: bound-check glyph index in bit_putcs* 7.1 medium
CVE-2025-66293 LIBPNG has an out-of-bounds read in png_image_read_composite 7.1 medium
CVE-2025-40273 NFSD: free copynotify stateid in nfs4_free_ol_stateid() 7.0 medium
CVE-2025-40280 tipc: Fix use-after-free in tipc_mon_reinit_self(). 7.0 medium
CVE-2025-40281 sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto 7.0 medium
CVE-2025-40292 virtio-net: fix received length check in big packets 7.0 medium
CVE-2025-40297 net: bridge: fix use-after-free due to MST port state bypass 7.0 medium
CVE-2025-40305 9p/trans_fd: p9_fd_request: kick rx thread if EPOLLIN 7.0 medium
CVE-2025-40328 smb: client: fix potential UAF in smb2_close_cached_fid() 7.0 medium
CVE-2025-40329 drm/sched: Fix deadlock in drm_sched_entity_kill_jobs_cb 7.0 medium
CVE-2025-40331 sctp: Prevent TOCTOU out-of-bounds write 7.0 medium
CVE-2025-40336 drm/gpusvm: fix hmm_pfn_to_map_order() usage 7.0 medium
CVE-2025-40338 ASoC: Intel: avs: Do not share the name pointer between components 7.0 medium

Microsoft’s December 9, 2025 Patch Tuesday release covers 349 CVEs: 15 rated critical, 115 rated important, and 191 rated moderate. Of these, none are currently listed as actively exploited.

Severity Breakdown

Severity Count
Critical 15
Important 115
Moderate 191
Actively exploited (CISA KEV) 0

Highest-Severity Vulnerabilities

Top 20 of 349 total, by CVSS/severity:

CVE Title CVSS
CVE-2025-65037 Azure Container Apps Remote Code Execution Vulnerability 10.0
CVE-2025-65041 Microsoft Partner Center Elevation of Privilege Vulnerability 10.0
CVE-2025-64663 Custom Question Answering Elevation of Privilege Vulnerability 9.9
CVE-2025-40242 gfs2: Fix unlikely race in gdlm_put_lock 9.8
CVE-2025-40244 hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent() 9.8
CVE-2025-40251 devlink: rate: Unset parent pointer in devl_rate_nodes_destroy 9.8
CVE-2025-40262 Input: imx_sc_key - fix memory corruption on unload 9.8
CVE-2025-68615 Net-SNMP snmptrapd crash 9.8
CVE-2025-34468 libcoap Stack-Based Buffer Overflow in Address Resolution DoS or Potential RCE 9.8
CVE-2025-68206 netfilter: nft_ct: add seqadj extension for natted connections 9.1
CVE-2025-68196 drm/amd/display: Cache streams targeting link when performing LT automation 8.8
CVE-2025-62456 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability 8.8
CVE-2025-62549 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 8.8
CVE-2025-62550 Azure Monitor Agent Remote Code Execution Vulnerability 8.8
CVE-2025-64672 Microsoft SharePoint Server Spoofing Vulnerability 8.8
CVE-2025-64678 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 8.8
CVE-2025-40240 sctp: avoid NULL dereference when chunk data buffer is missing 8.6
CVE-2025-62554 Microsoft Office Remote Code Execution Vulnerability 8.4
CVE-2025-62557 Microsoft Office Remote Code Execution Vulnerability 8.4
CVE-2025-40362 ceph: fix multifs mds auth caps issue 8.4

CVSS scores are sourced directly from Microsoft’s CVRF data as of December 9, 2025; exploitation status is cross-checked against CISA’s KEV catalog. Later re-scoring by NVD can shift a CVE’s score after this report was generated.

Why This Matters

No vulnerabilities in this release are yet listed in CISA’s Known Exploited Vulnerabilities catalog, but that can change quickly once a patch is public and attackers reverse-engineer it. Organizations should prioritize the critical- and important-rated CVEs above, especially any with public proof-of-concept exploits.

Frequently Asked Questions

How many vulnerabilities did Microsoft patch in December 2025? 349 CVEs, per Microsoft’s December 9, 2025 Patch Tuesday release.

Were any December 2025 Patch Tuesday vulnerabilities actively exploited? Not as of December 9, 2025, per CISA’s Known Exploited Vulnerabilities (KEV) catalog — this can change as exploitation is discovered after release.


Data sourced from Microsoft Security Response Center (MSRC) CVRF v3.0 and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated December 9, 2025. See more vulnerability research.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 Microsoft Security Response Center (MSRC)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools