{"id":338238,"date":"2025-12-10T00:05:10","date_gmt":"2025-12-10T00:05:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/338238\/"},"modified":"2025-12-10T00:05:10","modified_gmt":"2025-12-10T00:05:10","slug":"microsoft-patches-windows-zero-day-risky-office-flaws","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/338238\/","title":{"rendered":"Microsoft patches Windows zero-day &#038; risky Office flaws"},"content":{"rendered":"<p>Microsoft has released fixes for 54 security vulnerabilities in its latest monthly security update, including a Windows zero-day already exploited in the wild and Office flaws that can trigger remote code execution when emails are merely received.<\/p>\n<p>The December Patch Tuesday collection is smaller than in recent months. It includes two publicly disclosed remote code execution flaws and one vulnerability that attackers are actively exploiting.<\/p>\n<p>Microsoft has also issued patches for three critical remote code execution vulnerabilities. The company currently assesses those as less likely or unlikely to be exploited.<\/p>\n<p>The latest security updates do not include browser and open source patches. During December, Microsoft has already addressed 14 browser vulnerabilities and more than 80 issues in open source products.<\/p>\n<p>Windows zero-day<\/p>\n<p>The most serious issue in the batch is CVE-2025-62221. This is a local elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver.<\/p>\n<p>Microsoft has evidence that attackers already use this flaw. Successful exploitation grants SYSTEM-level privileges on a compromised machine.<\/p>\n<p>File system filter drivers, also known as minifilters, attach to the system software stack. They intercept requests aimed at a file system. They extend or replace the functions that the original target provides.<\/p>\n<p>Organisations typically use minifilters for data encryption, automated backup, on-the-fly compression, and cloud storage.<\/p>\n<p>The Cloud Files minifilter underpins services such as OneDrive, Google Drive, and iCloud. It is also a core Windows component. It remains present even when none of those cloud storage applications are installed.<\/p>\n<p>Microsoft classifies CVE-2025-62221 as important rather than critical. Attackers need an existing foothold on the target system.<\/p>\n<p>Security teams are likely to rate the bug as a priority because it is under active exploitation and gives an attacker full system control.<\/p>\n<p>PowerShell MotW bypass<\/p>\n<p>Another zero-day, CVE-2025-54100, affects security controls that rely on Windows&#8217; Mark of the Web (MotW) feature.<\/p>\n<p>MotW tracks files that users download from the internet. It adds metadata that indicates the file&#8217;s origin.<\/p>\n<p>Under standard conditions, PowerShell warns users before it runs unsigned code from the internet. It often waits for confirmation. It can also block unexpected code execution.<\/p>\n<p>CVE-2025-54100 allows attackers to bypass defences that depend on MotW. They can execute code before the file is written to disk.<\/p>\n<p>Microsoft is aware of public disclosure of this vulnerability.<\/p>\n<p>The company&#8217;s security update alters the default behaviour of Invoke-WebRequest in PowerShell 5.1. The command now prompts the user rather than processing and executing potentially malicious content while handling the full Document Object Model of a remote resource.<\/p>\n<p>Scripts that depend on the previous behaviour may hang when they encounter the new prompt. Administrators can change scripts by adding the -UseBasicParsing parameter to Invoke-WebRequest. This parameter avoids the chance of script execution.<\/p>\n<p>PowerShell 7 is not affected in the same way. It no longer depends on the legacy MSHTML\/Trident engine that Internet Explorer used.<\/p>\n<p>PowerShell 5.1 still ships by default with new Windows installations. This includes Server 2025 and Windows 11 25H2. Many enterprises continue to rely on older business applications.<\/p>\n<p>AI coding plugin issues<\/p>\n<p>Microsoft has also disclosed CVE-2025-64671. This affects the GitHub Copilot for JetBrains plugin.<\/p>\n<p>The plugin offers an Edit Mode that allows users to adjust code using AI assistance. An attacker who exploits the vulnerability can gain a similar level of control.<\/p>\n<p>The flaw relies on cross-prompt injection. Attackers can hide malicious instructions inside a hostile file or in Model Context Protocol (MCP) server data.<\/p>\n<p>Those instructions can lead to arbitrary command execution. Unsafe commands can pass security checks because they are appended to safe, allowlisted commands.<\/p>\n<p>The underlying security issue affects more than one vendor. The original researcher describes it as part of a wider class of vulnerabilities. The risk arises when an integrated development environment embeds agentic AI functionality and expands its attack surface.<\/p>\n<p>Other large IDE providers have assigned CVEs and released patches for similar problems.<\/p>\n<p>Office email risks<\/p>\n<p>Microsoft Office also receives multiple fixes this month. Two remote code execution issues stand out.<\/p>\n<p>CVE-2025-62554 and CVE-2025-62557 both involve Office and use the Preview Pane as an attack vector.<\/p>\n<p>The advisory FAQs for both flaws state that the Preview Pane is a vector. A user who scrolls past a malicious email in Outlook may trigger exploitation. The same risk applies when users preview a suspicious file in Explorer.<\/p>\n<p>This can happen without any obvious unsafe action by the user.<\/p>\n<p>The analysis also warns that exploitation could start when the targeted user receives a crafted email. The victim does not need to open, read, or click anything inside the message.<\/p>\n<p>The behaviour echoes CVE-2023-23397. That was a widely discussed critical Outlook issue disclosed about two and a half years ago.<\/p>\n<p>Microsoft reported in-the-wild exploitation of that earlier flaw by a Russia-based threat actor. The targets included government, military, and critical infrastructure organisations in Europe.<\/p>\n<p>There is no suggestion that the two new vulnerabilities cause NTLM hash disclosure. That was a core feature of CVE-2023-23397.<\/p>\n<p>The potential for exploitation without user interaction remains a concern for security teams.<\/p>\n<p>Lifecycle notes<\/p>\n<p>Microsoft reports no major product lifecycle changes this month.<\/p>\n<p>Visual Studio 2022 LTSC 17.10 will reach end of life in January. Organisations that still depend on that version face a narrowing window for upgrades and security planning.<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft has released fixes for 54 security vulnerabilities in its latest monthly security update, including a Windows zero-day&hellip;\n","protected":false},"author":2,"featured_media":338239,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,73483,284,116710,188142,53559,21039,144341,116711,188143,38824,188145,188146,2577,109655,75840,188144,13260,51229,184006,76342,105,60500,7116,34523,51228],"class_list":["post-338238","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-au","tag-australia","tag-cloud-storage","tag-cybersecurity","tag-data-encryption","tag-disaster-recovery-dr","tag-email-security","tag-enterprise-security","tag-eol","tag-google-drive","tag-icloud","tag-infosec","tag-integrated-development-environment-ide","tag-jetbrains","tag-microsoft","tag-microsoft-office","tag-model-context-protocol-mcp","tag-onedrive","tag-outlook","tag-patching","tag-powershell","tag-supply-chain-security","tag-technology","tag-threat-actors","tag-windows","tag-windows-11","tag-windows-server"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/338238","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=338238"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/338238\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/338239"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=338238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=338238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=338238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}