Microsoft released security fixes for 57 issues in its software, including an actively exploited 7.8-rated zero-day in the Windows Cloud Files Mini Filter Driver, as part of this month's Patch Tuesday, reports The Register.The flaw, tracked as CVE-2025-62221, lets an attacker with local code access gain full system privileges. "Privilege escalation vulnerabilities are observed in almost every incident involving host compromises, making this a critical vulnerability to patch to limit an attacker's capabilities," said Kev Breen, senior director of cyber threat research at Immersive.Two other Microsoft bugs were listed as publicly known: CVE-2025-54100, a PowerShell remote code execution issue, and CVE-2025-64671, a GitHub Copilot for JetBrains command injection flaw. Trend Micro's Dustin Childs warned that a remote attacker could trick a user into running malicious commands. Also fixed was a critical Notepad++ updater flaw, which security researcher Kevin Beaumont reported to be exploited in China.Meanwhile, Fortinet patched SAML login bypass bugs tracked as CVE-2025-59719 and CVE-2025-59718. Ivanti addressed a cross-site scripting issue in Endpoint Manager that could allow full session takeover.
Vulnerability Management, Patch/Configuration Management
Multiple Microsoft, Fortinet, Ivanti vulnerabilities addressed

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



