# Microsoft's December 2025 Patch Tuesday addresses multiple vulnerabilities, including…

Published: 2025-12-09 · Severity: high
Canonical: https://vorant.io/reports/729c1292-1240-40a8-ac62-c850899d87d0/microsoft-s-december-2025-patch-tuesday-addresses-multiple-vulnerabilities

> Microsoft's December 2025 Patch Tuesday addresses multiple vulnerabilities, including CVE-2025-62221, which is actively exploited in the wild.

On December 10, 2025 (Japan time), Microsoft released its monthly security update addressing multiple vulnerabilities across its product portfolio. The Japan Information-technology Promotion Agency (IPA) issued an advisory urging immediate patching, noting that exploitation of these vulnerabilities could lead to application crashes, system compromise, and attacker-controlled endpoints.

Of particular concern is CVE-2025-62221, for which Microsoft has confirmed active exploitation. The advisory emphasizes the urgent need for organizations to deploy security updates immediately due to the increased risk of widespread attacks. IPA notes that Windows Update typically handles these patches automatically, but organizations with managed update processes should prioritize deployment.

The advisory recommends that users verify patch installation through Windows Update and be prepared for potential system reboots during the update process. Organizations are directed to Microsoft's security bulletin for detailed information on the affected products and deployment guidance.

## Mentioned in this report

- Vulnerabilities: CVE-2025-62221 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/1210-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/729c1292-1240-40a8-ac62-c850899d87d0/microsoft-s-december-2025-patch-tuesday-addresses-multiple-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
