Vulnerability Management, Patch/Configuration Management

Actively exploited zero-day among dozens of patched Microsoft vulnerabilities

Updates have been issued by Microsoft to address 63 security issues impacting its products and systems, including an actively exploited high-severity zero-day in Windows Kernel, as part of this month's Patch Tuesday, reports CyberScoop.

Attacks involving the flaw, tracked as CVE-2025-62215, could enable threat actors with a race condition to achieve system privileges, according to Microsoft.

"Bugs like these are often paired with a code execution bug by malware to completely take over a system," said Trend Micro Zero Day Initiative Head of Threat Awareness Dustin Childs.

Vulnerabilities in the kernel-mode driver were also noted by Immersive's Ben McCarthy to be serious due to the component's importance in Windows operations.

Microsoft has also fixed a critical Graphics Component flaw, tracked as CVE-2025-60724, as well as five other bugs that have increased odds of being abused, three of which are high-severity issues impacting Windows Ancillary Function Driver for WinSock.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds