Home › Microsoft Patch Tuesday › December 2025

Microsoft Patch Tuesday, December 2025

·

Microsoft's December 2025 security release, published December 9, 2025: 55 updates fixing 107 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 1 CVE from this release is on the Senserva hot list today (as of 2026-09-27), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
55
Updates (KBs)
107
CVEs fixed
6
On the CISA KEV list
21
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2025-24990Windows Agere Modem Driver Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-59230Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-62221Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-60710Host Process for Windows Tasks Elevation of Privilege VulnerabilityCVSS 7.8ExploitedRansomware Hot now
CVE-2025-62215Windows Kernel Elevation of Privilege VulnerabilityCVSS 7.0Exploited
CVE-2025-47827MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11CVSS 4.6Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2025-49708Microsoft Graphics Component Elevation of Privilege VulnerabilityCVSS 9.9
CVE-2025-60724GDI+ Remote Code Execution VulnerabilityCVSS 9.8
CVE-2025-58715Windows Speech Runtime Elevation of Privilege VulnerabilityCVSS 8.8
CVE-2025-58716Windows Speech Runtime Elevation of Privilege VulnerabilityCVSS 8.8
CVE-2025-59295Windows URL Parsing Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-58718Remote Desktop Client Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-64678Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-62456Windows Resilient File System (ReFS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-62549Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-64672Microsoft SharePoint Server Spoofing VulnerabilityCVSS 8.8

Products fixed this month

Windows Server 2022 (6)Windows Server 2022 (Server Core installation) (6)Windows Server 2025 (Server Core installation) (6)Windows Server 2008 for 32-bit Systems Service Pack 2 (4)Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (4)Windows Server 2008 for x64-based Systems Service Pack 2 (4)Windows Server 2008 R2 for x64-based Systems Service Pack 1 (4)Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (4)Windows 10 Version 1809 for 32-bit Systems (3)Windows 10 Version 1809 for x64-based Systems (3)

Every update in this release

All 55 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5066586 ExploitedCritical9.998Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5066782 ExploitedCritical9.9103Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5066791 ExploitedCritical9.998Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5066793 ExploitedCritical9.9108Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based SystemsSupport · Catalog
KB5066835 ExploitedCritical9.9134Windows Server 2025 (Server Core installation), Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
KB5066780 ExploitedCritical9.9114Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5068791 ExploitedCritical9.834Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5068787 ExploitedCritical9.830Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5068840 ExploitedCritical9.830Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5068781 ExploitedCritical9.833Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5068861 ExploitedCritical9.835Windows Server 2025 (Server Core installation), Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
KB5068966 ExploitedCritical9.835Windows Server 2025 (Server Core installation), Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
KB5068865 ExploitedCritical9.833Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based SystemsSupport · Catalog
KB5068779 ExploitedCritical9.832Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5066837 ExploitedHigh8.868Windows 10 for 32-bit Systems, Windows 10 for x64-based SystemsSupport · Catalog
KB5066836 ExploitedHigh8.878Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016Support · Catalog
KB5072033 Exploited RansomwareHigh8.834Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows Server 2025 (Server Core installation)Support · Catalog
KB5072014 Exploited RansomwareHigh8.833Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows Server 2025 (Server Core installation)Support · Catalog
KB5071544 ExploitedHigh8.826Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5071547 ExploitedHigh8.829Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5071413 ExploitedHigh8.828Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5071546 ExploitedHigh8.828Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5071417 ExploitedHigh8.830Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based SystemsSupport · Catalog
KB5071542 ExploitedHigh8.830Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5068864Critical9.826Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016Support · Catalog
KB5068906Critical9.815Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5068909Critical9.815Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5068904Critical9.815Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5068908Critical9.815Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5068907Critical9.817Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5068905Critical9.818Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5071543High8.815Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016Support · Catalog
KB5071501High8.810Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5071506High8.810Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5071505High8.810Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5071503High8.811Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5071504High8.88Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5071507High8.88Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5002815High8.81Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002819High8.42Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5074353High7.81Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5074204High7.81Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 Version 25H2 for ARM64-based SystemsSupport · Catalog
KB5002821High7.84Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002804High7.84Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002816High7.84Microsoft SharePoint Server 2019Support · Catalog
KB5002802High7.84Microsoft SharePoint Server 2019Support · Catalog
KB5002806High7.84Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)Support · Catalog
KB5002820High7.86Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5002818High7.83Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5002817High7.85Office Online ServerSupport · Catalog
KB5002812High7.81Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition)Support · Catalog
KB5071876High7.52Microsoft Exchange Server Subscription Edition RTMSupport · Catalog
KB5071873High7.52Microsoft Exchange Server 2016 Cumulative Update 23Support · Catalog
KB5071875High7.52Microsoft Exchange Server 2019 Cumulative Update 15Support · Catalog
KB5071874High7.52Microsoft Exchange Server 2019 Cumulative Update 14Support · Catalog
Take this release to your AI

Composed from the December 2025 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.