December Patch Tuesday lands with 132 fixes, including 2 critical and 1 actively exploited.
This month’s highlights:
- Cloud Files Mini Filter Driver EoP (CVE-2025-62221) is actively exploited and grants SYSTEM.
- Two critical Office RCEs (CVE-2025-62557, CVE-2025-62554) require no interaction and can trigger via Preview Pane.
- Exchange EoP (CVE-2025-64666) enables admin escalation; fixes for 2016/2019 require ESU or migration.
Get the full breakdown and run the audit to find outdated devices in your network
https://www.lansweeper.com/blog/patch-tuesday/microsoft-patch-tuesday-december-2025/