In 2025, Microsoft issued mitigations for 1,246 CVEs, including 158 rated critical. Forty-one of these were zero days, and Tenable estimate that privilege escalation vulnerabilities accounted for about 38.3% of all vulnerabilities on Patch Tuesday 2025, followed by remote code execution vulnerabilities at about 30%.
See also: Microsoft Patch Tuesday December 2025 released

We asked security experts which of these vulnerabilities worried them the most. Here's how they answered.
New tactics and AI are changing the game: Thanks to the use of AI by malicious actors, as well as cunning new tactics, security teams have less time than ever to install patches.
Lower-scoring vulnerabilities: Several lower-scoring vulnerabilities could cause serious damage if not addressed quickly. These included:
See also: Microsoft Patch Tuesday November 2025: Fixes 63 vulnerabilities

- CVE 2025 24993, a Windows NTFS memory corruption issue that affects almost every Windows system by default, allowing local code execution by an unauthorized attacker.
- CVE 2025 24990, an elevation of privilege vulnerability in the Agere modem driver shipped with Windows allowed attackers to elevate to SYSTEM with little effort, and without actually using the Agere modem, turning limited access into full control.
- CVE 2025 62221, a use-after-free flaw in the Windows cloud file mini filter driver, was actively exploited and provided a trusted path to SYSTEM once code execution was achieved.
- CVE 2025 53779, the Kerberos BadSuccessor elevation of privilege, threatened domain-wide compromise by allowing any domain-authenticated account to elevate privileges by spoofing credentials within Active Directory environments.
- CVE-2025-24983 in the Windows kernel, and CVE-2025-29824, in the Windows shared log file system driver, because both were used with the PipeMagic backdoor to spread ransomware.
- CVE-2025-33053, a remote code execution vulnerability affecting Internet shortcut files.
See also: Microsoft Patch Tuesday October 2025: 172 vulnerabilities fixed

A CVSS score is “only part of a puzzle.” Most CSOs lack a fundamental understanding of how vulnerabilities relate to their specific IT environment and concerns.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
