By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Update your PC now — Microsoft’s December 2025 Patch Tuesday fixes 57 flaws
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Update your PC now — Microsoft’s December 2025 Patch Tuesday fixes 57 flaws
News

Update your PC now — Microsoft’s December 2025 Patch Tuesday fixes 57 flaws

News Room
Last updated: 2025/12/09 at 7:07 PM
News Room Published 9 December 2025
Share
Update your PC now — Microsoft’s December 2025 Patch Tuesday fixes 57 flaws
SHARE

If you’ve been putting off updating your laptop or desktop PC, now is a good time to do so as Microsoft just released its December Patch Tuesday which contains fixes for 57 unique flaws including three zero-day vulnerabilities and three critical-severity bugs.

In the total 57 total flaws, 28 are privilege escalation bugs, 19 are remote code execution flaws, four are information disclosures, three are denial of service (DoS) vulnerabilities, and two are spoofing bugs. It’s a very similar list to the November Patch Tuesday which fixed 63 flaws.

Zero Day Flaws

(Image credit: Unsplash)

According to Microsoft, a zero-day flaw is one that has been publicly disclosed or actively exploited while no official fix has been deployed. Bleeding Computer reports that the exploited zero-day vulnerability (tracked as CVE-2025-62221) is privilege elevation vulnerability that affects the Windows Cloud Files Mini Filter Driver.


You may like

Microsoft says that exploiting the flaw lets attacks gain system privileges, meaning they could gain admin access. The company also says the flaw was discovered by its own Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) teams but did not share how the flaw was exploited.

The other two zero-day flaws (tracked as CVE-2025-64671 and CVE-2025-54100) affect GitHub Copilot and PowerShell Remote Code Execution.

The GitHub flaw could allow attackers to execute commands locally andit appears this flaw can be exploited through Cross Prompt Injections in Microsoft’s Copilot AI.

“Via a malicious Cross Prompt Inject in untrusted files or MCP servers, an attacker could execute additional commands by appending them to commands allowed in the user’s terminal auto-approve setting,” Microsoft said.

Get instant access to breaking news, the hottest reviews, great deals and helpful tips.

Meanwhile, the PowerShell flaw can be exploited by using scripts in webpages that go live via an Invoke-WebRequest, which isused to parse links, images and HTML elements on a website. With the fix, a warning will be issued when PowerShell uses the Invoke code and appends -UseBasicParsing to prevent malicious code execution.

How to keep your Windows PC safe


A woman using her laptop securely with a cup of coffee in hand

(Image credit: Shutterstock)

New system updates and patches generally fix flaws and security holes for your Windows laptop or desktop computer andit’s best practice to install them as soon as they become available.

You’ll want to ensure you have Microsoft’s built-in Windows Defender antivirus software set to periodically scan your computer for dangerous malware and malicious code. If you’re looking for extra protection, you may want to consider running one of the best antivirus software programs alongsideDefender.


You may like

Outside of building your digital fortress, you also want to make sure you’re careful online. Don’t click on links or download attachments from unknown senders as they could contain malware or take you to phishing sites designed to steal your personal information or banking data.

Needless to say, you’ll want to avoid pirating software or media like movies and TV shows since malware could easily be attached to those downloads too.

By practicing good cyber hygiene and regularly updating your computer, you should be safe from most attacks, especially those that utilize known Windows security flaws to get in.



Google News

Follow Tom’s Guide on Google News and add us as a preferred source to get our up-to-date news, analysis, and reviews in your feeds.


More from Tom’s Guide

Arrow

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article An ultra-fast method for recycling plastics? This Korean invention could finally reduce our waste An ultra-fast method for recycling plastics? This Korean invention could finally reduce our waste
Next Article Signing Messages in Symfony 7.4: A Deep Dive | HackerNoon Signing Messages in Symfony 7.4: A Deep Dive | HackerNoon
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Safaricom raises 4m in upsized bond deal
Safaricom raises $154m in upsized bond deal
Computing
Galaxy S26 leak reveals Samsung’s big move into magnetic accessories
Galaxy S26 leak reveals Samsung’s big move into magnetic accessories
News
PitchBook: AI is becoming the defining infrastructure layer of the global economy –  News
PitchBook: AI is becoming the defining infrastructure layer of the global economy – News
News
The Invisible Line Item: Why Pollution Is Missing From Every Balance Sheet | HackerNoon
The Invisible Line Item: Why Pollution Is Missing From Every Balance Sheet | HackerNoon
Computing

You Might also Like

Galaxy S26 leak reveals Samsung’s big move into magnetic accessories
News

Galaxy S26 leak reveals Samsung’s big move into magnetic accessories

3 Min Read
PitchBook: AI is becoming the defining infrastructure layer of the global economy –  News
News

PitchBook: AI is becoming the defining infrastructure layer of the global economy – News

6 Min Read
Crunchyroll Kills Free Plan: What Anime Fans Should Know About the Switch
News

Crunchyroll Kills Free Plan: What Anime Fans Should Know About the Switch

3 Min Read
Binge on a Budget With 50% Off a 43-Inch TCL TV at Walmart
News

Binge on a Budget With 50% Off a 43-Inch TCL TV at Walmart

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?