Microsoft Fixes 56 Security Flaws, Addresses Zero-Day Bug
Microsoft just released updates to fix at least 56 security flaws in its windows operating systems and related software. This final Patch Tuesday of 2025 tackles one zero-day bug that’s already being exploited, plus two publicly known vulnerabilities.
Its been a busy year for security. Though Microsoft released fewer updates than usual in recent months, thay patched a massive 1,129 vulnerabilities in 2025 – an 11.9% jump from 2024.According to Satnam Narang at Tenable, this marks the second year in a row Microsoft patched over one thousand vulnerabilities, and only the third time ever.
The zero-day flaw addressed today is CVE-2025-62221, a privilege escalation vulnerability affecting Windows 10 and newer. It’s located in the “Windows Cloud Files Mini Filter Driver” – a system driver that lets cloud apps access file system features.
“This is particularly concerning,” says Adam Barnett, lead software engineer at Rapid7. “The mini filter is key to services like OneDrive, Google Drive, and iCloud, and it’s a core Windows component even if you don’t have those apps installed.”
Only three of today’s fixes received Microsoft’s “critical” rating. Both CVE-2025-62554 and CVE-2025-62557 impact Microsoft Office and can be exploited simply by viewing a malicious email in the Preview Pane. Another critical bug – CVE-2025-62555 – affects the Microsoft Graphics Component.
Related reading