AVLEONOV 9.9 CRITICAL

November “In the Trend of VM” (#21): vulnerabilities in Windows, SharePoint, Redis, XWiki, Zimbra Collaboration, and Linux_AVLEONOV:178C80F37386B03F6E013DEA46A4FC3B

9.9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

![November In the Trend of VM \(#21\): vulnerabilities in Windows, SharePoint, Redis, XWiki, Zimbra Collaboration, and Linux](https://avleonov.com/wp-content/uploads/2025/11/photo_879@14-11-2025_23-44-36.jpg)

**November "In the Trend of VM" (#21): vulnerabilities in Windows, SharePoint, Redis, XWiki, Zimbra Collaboration, and Linux. **The usual monthly roundup. After several months, here's a big one. ![🔥](https://s.w.org/images/core/emoji/16.0.1/72x72/1f525.png)

![🗞](https://s.w.org/images/core/emoji/16.0.1/72x72/1f5de.png) Post on Habr (rus)
![🗞](https://s.w.org/images/core/emoji/16.0.1/72x72/1f5de.png) Post on SecurityLab (rus)
![🗒](https://s.w.org/images/core/emoji/16.0.1/72x72/1f5d2.png) Digest on the PT website (rus)

A total of nine vulnerabilities:

![🔻](https://s.w.org/images/core/emoji/16.0.1/72x72/1f53b.png) **RCE** - Windows Server Update Services (WSUS) (CVE-2025-59287)
![🔻](https://s.w.org/images/core/emoji/16.0.1/72x72/1f53b.png) **RCE** - Microsoft SharePoint "ToolShell" (CVE-2025-49704)
![🔻](https://s.w.org/images/core/emoji/16.0.1/72x72/1f53b.png) **RCE** - Windows LNK File (CVE-2025-9491)
![🔻](https://s.w.org/images/core/emoji/16.0.1/72x72/1f53b.png) **EoP** - Windows Remote Access Connection Manager (CVE-2025-59230)
![🔻](https://s.w.org/images/core/emoji/16.0.1/72x72/1f53b.png) **EoP** - Windows Agere Modem Driver (CVE-2025-24990)
![🔻](https://s.w.org/images/core/emoji/16.0.1/72x72/1f53b.png) **RCE** - Redis "RediShell" (CVE-2025-49844)
![🔻](https://s.w.org/images/core/emoji/16.0.1/72x72/1f53b.png) **RCE** - XWiki Platform (CVE-2025-24893)
![🔻](https://s.w.org/images/core/emoji/16.0.1/72x72/1f53b.png) **XSS** - Zimbra Collaboration (CVE-2025-27915)
![🔻](https://s.w.org/images/core/emoji/16.0.1/72x72/1f53b.png) **EoP** - Linux Kernel (CVE-2025-38001)

![🟥](https://s.w.org/images/core/emoji/16.0.1/72x72/1f7e5.png) Trending Vulnerabilities Portal

На русском
Visit Original Source

Basic Information

ID AVLEONOV:178C80F37386B03F6E013DEA46A4FC3B
Published Nov 14, 2025 at 20:44

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.