AVLEONOV 9.8 CRITICAL

November Microsoft Patch Tuesday_AVLEONOV:F650807EA92BD5AFC8E12A3836CFE241

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

![November Microsoft Patch Tuesday](https://avleonov.com/wp-content/uploads/2025/11/photo_878@14-11-2025_22-49-29.jpg)

**November Microsoft Patch Tuesday.** A total of 65 vulnerabilities. I'm not comparing this with the October report because I've decided to cover only MSPT-day vulnerabilities. The thing is, Microsoft has started massively adding Linux-product vulnerabilities to their official website, and these clutter the "extended" MSPT reports. ![๐Ÿคทโ€โ™‚๏ธ](https://s.w.org/images/core/emoji/16.0.1/72x72/1f937-200d-2642-fe0f.png)

There is one vulnerability with evidence of in-the-wild exploitation:

![๐Ÿ”ป](https://s.w.org/images/core/emoji/16.0.1/72x72/1f53b.png) **EoP** - Windows Kernel (CVE-2025-62215)

No vulnerabilities have publicly available exploits yet. Notable ones include:

![๐Ÿ”น](https://s.w.org/images/core/emoji/16.0.1/72x72/1f539.png) **RCE** - GDI+ (CVE-2025-60724), Microsoft Office (CVE-2025-62199), Microsoft Office (CVE-2025-62205, CVE-2025-62216), Agentic AI and Visual Studio Code (CVE-2025-62222), Visual Studio (CVE-2025-62214)
![๐Ÿ”น](https://s.w.org/images/core/emoji/16.0.1/72x72/1f539.png) **EoP** - Windows Client-Side Caching (CVE-2025-60705), Windows Ancillary Function Driver for WinSock (CVE-2025-60719, CVE-2025-62213, CVE-2025-62217), Microsoft SQL Server (CVE-2025-59499)

![๐Ÿ—’](https://s.w.org/images/core/emoji/16.0.1/72x72/1f5d2.png) Full Vulristics report

ะะฐ ั€ัƒััะบะพะผ
Visit Original Source

Basic Information

ID AVLEONOV:F650807EA92BD5AFC8E12A3836CFE241
Published Nov 14, 2025 at 19:49

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.