# Microsoft patches actively exploited CVE-2025-62221

Published: 2025-12-09 · Severity: high
Canonical: https://vorant.io/reports/cb7bae28-73a9-52d9-a146-25259c9d9406/microsoft-patches-actively-exploited-cve-2025-62221

> Microsoft's December 2025 Patch Tuesday addresses CVE-2025-62221, a vulnerability confirmed to be actively exploited in the wild.

Japan's Information-technology Promotion Agency (IPA) issued an alert on December 10, 2025, regarding Microsoft's monthly security updates. The advisory highlights CVE-2025-62221 as a vulnerability Microsoft has confirmed is being actively exploited. Exploitation of these flaws could allow attackers to cause application crashes, achieve system control, or trigger other adverse impacts.

The IPA urges organizations and users to apply the security updates immediately due to the risk of expanding attacks. Windows Update typically applies these patches automatically, but organizations managing update deployments should prioritize rollout based on Microsoft's advisory.

The advisory notes that system restarts may be required after applying the security updates. Users are directed to Microsoft's official resources and Windows Update mechanisms for patch deployment.

## Mentioned in this report

- Vulnerabilities: CVE-2025-62221 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/1210-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/cb7bae28-73a9-52d9-a146-25259c9d9406/microsoft-patches-actively-exploited-cve-2025-62221.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
