On 2025-11-12, Microsoft released security patches addressing 63 vulnerabilities, including an actively exploited zero-day in the Windows Kernel. The zero-day vulnerability, identified by Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC), involves a race-condition privilege escalation flaw.

Critical Vulnerabilities Addressed

The November update contains four Critical and 59 Important vulnerabilities. Key types include privilege escalation (29), remote code execution (16), information disclosure (11), denial-of-service (3), security feature bypass (2), and spoofing bugs (2).

  • The zero-day is rated CVSS 7.0 and allows privilege escalation via a race condition.
  • A Critical buffer overflow in Microsoft's Graphics Component (CVSS 9.8) can lead to remote code execution.
  • Updates also involve the Chromium-based Edge browser.

Exploitation Details

The zero-day vulnerability in the Windows Kernel allows an attacker, who already has local access, to elevate their privileges to SYSTEM level. This has been exploited post-initial access through social engineering or chaining with other vulnerabilities for comprehensive system takeover. Ben McCarthy from Immersive explained that a crafted application exploiting this flaw can trigger kernel heap corruption.

When combined with other vulnerabilities, this flaw can facilitate credential theft and lateral movement within networks. The vulnerability poses significant risk when exploited together with remote code execution bugs or sandbox escapes.

Industry Reactions and Updates

Analysts note the strategic importance of promptly applying these patches, given the ongoing exploitation in the wild. In response to these vulnerabilities, other vendors, including several Linux distributions and Mozilla, have issued related security updates. This coordinated response underscores the critical nature of the threats addressed.

Discover Microsoft Windows XP

Discover Microsoft Windows XP download for free to PC or mobile

Latest update Discover Microsoft Windows XP download for free for Windows PC or Android mobile

3
661 reviews
3953 downloads

News and reviews about Discover Microsoft Windows XP

13 Nov 2025

Windows AI Vision Sparks User Backlash at Microsoft

Microsoft's AI vision for Windows, shared by Pavan Davuluri, faces user backlash, highlighting concerns over AI prioritization.

Read more

12 Nov 2025

Microsoft's Windows to Integrate More AI Features

Windows to become more 'agentic' with AI integration, says Microsoft. The change draws criticism on social media.

Read more

12 Nov 2025

Patch Resolves Windows Kernel Vulnerability

Microsoft issues critical update for Windows Kernel due to active vulnerability exploitation. Immediate update advised for Windows 10 and 11 users.

Read more

12 Nov 2025

Microsoft Fixes Zero-Day Vulnerability in Patch Tuesday Updates

Patch Tuesday sees crucial fixes for Windows zero-day threats, enhancing system security.

Read more

12 Nov 2025

Microsoft Patch Tuesday Fixes 63 Vulnerabilities

On 2025-11-12, Microsoft addressed 63 security flaws in its software, including a critical Windows Kernel zero-day vulnerability.

Read more

23 Oct 2025

Patch SMB Vulnerability to Protect Older Windows Systems

CVE-2025-33073, a severe SMB flaw impacting older Windows, urges immediate updates for SMB security.

Read more

21 Oct 2025

Prioritize CVE-2025-33073 Patch for Windows Users

Windows users urged to update for CVE-2025-33073. This vulnerability affects Server, 10, 11, necessitating quick action to avoid privilege escalation.

Read more

17 Oct 2025

CISA Adds Key Software Flaws to Exploited Vulnerabilities List

CISA updates KEV catalog with vulnerabilities found in several software, urging federal agencies to fix by 2025-11-04.

Read more

15 Oct 2025

October Patch Tuesday Fixes 167 Vulnerabilities Including Critical RCE

Microsoft's October Patch Tuesday addresses 167 vulnerabilities, including critical RCE flaws in WSUS and Microsoft Office.

Read more

05 Oct 2025

How to Recover Files and Folders Hidden by Virus in Windows XP

Learn how to recover files and folders hidden by a virus in Windows XP. Discover Microsoft Windows XP for effective solutions.

Read more