By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack
Computing

Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack

News Room
Last updated: 2025/11/12 at 6:27 AM
News Room Published 12 November 2025
Share
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack
SHARE

Nov 12, 2025Ravie LakshmananVulnerability / Patch Tuesday

Microsoft on Tuesday released patches for 63 new security vulnerabilities identified in its software, including one that has come under active exploitation in the wild.

Of the 63 flaws, four are rated Critical and 59 are rated Important in severity. Twenty-nine of these vulnerabilities are related to privilege escalation, followed by 16 remote code execution, 11 information disclosure, three denial-of-service (DoS), two security feature bypass, and two spoofing bugs.

The patches are in addition to the 27 vulnerabilities the Windows maker addressed in its Chromium-based Edge browser since the release of October 2025’s Patch Tuesday update.

DFIR Retainer Services

The zero-day vulnerability that has been listed as exploited in Tuesday’s update is CVE-2025-62215 (CVSS score: 7.0), a privilege escalation flaw in Windows Kernel. The Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have been credited with discovering and reporting the issue.

“Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Kernel allows an authorized attacker to elevate privileges locally,” the company said in an advisory.

That said, successful exploitation hinges on an attacker who has already gained a foothold on a system to win a race condition. Once this criterion is satisfied, it could permit the attacker to obtain SYSTEM privileges.

“An attacker with low-privilege local access can run a specially crafted application that repeatedly attempts to trigger this race condition,” Ben McCarthy, lead cybersecurity engineer at Immersive, said.

“The goal is to get multiple threads to interact with a shared kernel resource in an unsynchronized way, confusing the kernel’s memory management and causing it to free the same memory block twice. This successful ‘double free’ corrupts the kernel heap, allowing the attacker to overwrite memory and hijack the system’s execution flow.”

It’s currently not known how this vulnerability is being exploited and by whom, but it’s assessed to be used as part of a post-exploitation activity to escalate their privileges after obtaining initial access through some other means, such as social engineering, phishing, or exploitation of another vulnerability, Satnam Narang, senior staff research engineer at Tenable, said.

“When chained with other bugs this kernel race is critical: an RCE or sandbox escape can supply the local code execution needed to turn a remote attack into a SYSTEM takeover, and an initial low‑privilege foothold can be escalated to dump credentials and move laterally,” Mike Walters, president and co-founder of Action1, said in a statement.

Also patched as part of the updates are two heap-based buffer overflow flaws in Microsoft’s Graphics Component (CVE-2025-60724, CVSS score: 9.8) and Windows Subsystem for Linux GUI (CVE-2025-62220, CVSS score: 8.8) that could result in remote code execution.

Another vulnerability of note is a high-severity privilege escalation flaw in Windows Kerberos (CVE-2025-60704, CVSS score: 7.5) that takes advantage of a missing cryptographic step to gain administrator privileges. The vulnerability has been codenamed CheckSum by Silverfort.

“The attacker must inject themselves into the logical network path between the target and the resource requested by the victim to read or modify network communications,” Microsoft said. “An unauthorized attacker must wait for a user to initiate a connection.”

Silverfort researchers Eliran Partush and Dor Segal, who discovered the shortcoming, described it as a Kerberos constrained delegation vulnerability that allows an attacker to impersonate arbitrary users and gain control over an entire domain by means of an adversary-in-the-middle (AitM) attack.

CIS Build Kits

An attacker who is able to successfully exploit the flaw could escalate privileges and move laterally to other machines in an organization. More concerning, threat actors could also gain the ability to impersonate any user in the company, allowing them to gain unfettered access or become a domain administrator.

“Any organization using Active Directory, with the Kerberos delegation capability turned on, is impacted,” Silverfort said. “Because Kerberos delegation is a feature within Active Directory, an attacker requires initial access to an environment with compromised credentials.”

Software Patches from Other Vendors

In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including —

  • Adobe
  • Amazon Web Services
  • AMD
  • Apple
  • ASUS
  • Atlassian
  • AutomationDirect
  • Bitdefender
  • Broadcom (including VMware)
  • Cisco
  • Citrix
  • ConnectWise
  • D-Link
  • Dell
  • Devolutions
  • Drupal
  • Elastic
  • F5
  • Fortinet
  • GitLab
  • Google Android
  • Google Chrome
  • Google Cloud
  • Grafana
  • Hitachi Energy
  • HP
  • HP Enterprise (including Aruba Networking and Juniper Networks)
  • IBM
  • Intel
  • Ivanti
  • Jenkins
  • Lenovo
  • Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu
  • MediaTek
  • Mitsubishi Electric
  • MongoDB
  • Moxa
  • Mozilla Firefox and Firefox ESR
  • NVIDIA
  • Oracle
  • Palo Alto Networks
  • QNAP
  • Qualcomm
  • Rockwell Automation
  • Ruckus Wireless
  • Samba
  • Samsung
  • SAP
  • Schneider Electric
  • Siemens
  • SolarWinds
  • SonicWall
  • Splunk
  • Spring Framework
  • Supermicro
  • Synology
  • TP-Link
  • WatchGuard, and
  • Zoom

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article I used Gemini Live instead of the IKEA manual, and it went better than I thought I used Gemini Live instead of the IKEA manual, and it went better than I thought
Next Article What Does ‘DLAA’ On An Nvidia Graphics Card Actually Mean? – BGR What Does ‘DLAA’ On An Nvidia Graphics Card Actually Mean? – BGR
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Samsung’s trifold could launch in less than a month with a surprisingly decent battery
Samsung’s trifold could launch in less than a month with a surprisingly decent battery
News
Crunchbase Sector Snapshot: It’s Been A Down Year For E-Commerce Funding
Crunchbase Sector Snapshot: It’s Been A Down Year For E-Commerce Funding
News
Visionox tops out world’s first FMM-free 8.6-gen AMOLED line with .7 billion investment · TechNode
Visionox tops out world’s first FMM-free 8.6-gen AMOLED line with $7.7 billion investment · TechNode
Computing
Agentic AI isn’t always the answer
Agentic AI isn’t always the answer
Software

You Might also Like

Visionox tops out world’s first FMM-free 8.6-gen AMOLED line with .7 billion investment · TechNode
Computing

Visionox tops out world’s first FMM-free 8.6-gen AMOLED line with $7.7 billion investment · TechNode

1 Min Read
Obiex says it’s profitable after processing 1M in crypto trades
Computing

Obiex says it’s profitable after processing $731M in crypto trades

7 Min Read
The TechBeat: The Paycheck Era is Dying (11/12/2025) | HackerNoon
Computing

The TechBeat: The Paycheck Era is Dying (11/12/2025) | HackerNoon

7 Min Read
[Webinar] Learn How Leading Security Teams Reduce Attack Surface Exposure with DASR
Computing

[Webinar] Learn How Leading Security Teams Reduce Attack Surface Exposure with DASR

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?