Microsoft Fixes Zero-Day Vulnerability in Patch Tuesday Updates

12 Nov 2025

On November 12, 2025, Microsoft released critical security updates as part of its regular Patch Tuesday. These updates address significant vulnerabilities in Windows 10, Windows 11, Windows Server, and Microsoft Office.

Security Updates Overview

One of the key fixes addresses Remote Code Execution (RCE) bugs in Microsoft Graphics and Office. These flaws could potentially allow attackers to execute malicious code if users open a specially crafted file.

Moreover, Microsoft tackled a zero-day Windows Kernel Elevation of Privilege (EoP) vulnerability. This flaw, which involves a race condition, allows attackers with local access to escalate their privileges to admin level by chaining attacks.

Specific Vulnerability Insights

Another significant issue fixed is the CVE-2025-60724 bug in the GDI+ component of Microsoft Graphics. Rated at 9.8 out of 10 in severity, this vulnerability is a heap-based buffer overflow. Attackers could exploit it by persuading users to open a crafted metafile or by uploading a malicious file to a susceptible web service.

The updates bring essential protection to users by closing these vulnerabilities, mitigating the risks of unauthorized access and data breaches.

Steps for Updating

  • Access the Start menu and open Settings.
  • Navigate to Windows Update.
  • Select 'Check for updates' and download available patches.
  • Restart your PC if prompted and ensure Windows Update indicates "You're up to date."

By promptly applying these updates, users can enhance their security posture and protect their systems from active threats.

Discover Microsoft Windows XP

Discover Microsoft Windows XP download for free to PC or mobile

Latest update Discover Microsoft Windows XP download for free for Windows PC or Android mobile

3
661 reviews
3953 downloads

News and reviews about Discover Microsoft Windows XP

13 Nov 2025

Windows AI Vision Sparks User Backlash at Microsoft

Microsoft's AI vision for Windows, shared by Pavan Davuluri, faces user backlash, highlighting concerns over AI prioritization.

Read more

12 Nov 2025

Microsoft's Windows to Integrate More AI Features

Windows to become more 'agentic' with AI integration, says Microsoft. The change draws criticism on social media.

Read more

12 Nov 2025

Patch Resolves Windows Kernel Vulnerability

Microsoft issues critical update for Windows Kernel due to active vulnerability exploitation. Immediate update advised for Windows 10 and 11 users.

Read more

12 Nov 2025

Microsoft Fixes Zero-Day Vulnerability in Patch Tuesday Updates

Patch Tuesday sees crucial fixes for Windows zero-day threats, enhancing system security.

Read more

12 Nov 2025

Microsoft Patch Tuesday Fixes 63 Vulnerabilities

On 2025-11-12, Microsoft addressed 63 security flaws in its software, including a critical Windows Kernel zero-day vulnerability.

Read more

23 Oct 2025

Patch SMB Vulnerability to Protect Older Windows Systems

CVE-2025-33073, a severe SMB flaw impacting older Windows, urges immediate updates for SMB security.

Read more

21 Oct 2025

Prioritize CVE-2025-33073 Patch for Windows Users

Windows users urged to update for CVE-2025-33073. This vulnerability affects Server, 10, 11, necessitating quick action to avoid privilege escalation.

Read more

17 Oct 2025

CISA Adds Key Software Flaws to Exploited Vulnerabilities List

CISA updates KEV catalog with vulnerabilities found in several software, urging federal agencies to fix by 2025-11-04.

Read more

15 Oct 2025

October Patch Tuesday Fixes 167 Vulnerabilities Including Critical RCE

Microsoft's October Patch Tuesday addresses 167 vulnerabilities, including critical RCE flaws in WSUS and Microsoft Office.

Read more

05 Oct 2025

How to Recover Files and Folders Hidden by Virus in Windows XP

Learn how to recover files and folders hidden by a virus in Windows XP. Discover Microsoft Windows XP for effective solutions.

Read more