30.1 C
Delhi
Monday, March 2, 2026

Microsoft Patches Critical Zero-Day Flaw in November Security Update

Key Takeaways

  • Microsoft patches 63 security vulnerabilities including one actively exploited zero-day
  • CVE-2025-62215 allows attackers to gain complete SYSTEM-level control
  • Update immediately via Windows Update to prevent system compromise

Microsoft has urgently released its November security update addressing 63 vulnerabilities, with one critical zero-day flaw already being actively exploited by attackers. The patch KB5068861 fixes four Critical-rated vulnerabilities, including the dangerous Windows Kernel Elevation of Privilege vulnerability that could give hackers complete system control.

Critical Zero-Day Vulnerability Details

The actively exploited vulnerability CVE-2025-62215 resides in the Windows Kernel, the core operating system component. Successful exploitation enables privilege escalation from standard user accounts to SYSTEM level, granting attackers full access to files, services, and system settings.

Microsoft identified the flaw as a race condition vulnerability, where unsynchronized resource processing allows attackers to inject commands between processes. While full attack details remain undisclosed, the company confirmed active targeting and immediate patch availability.

Vulnerability Breakdown

The November patch addresses these security issues:

  • Elevation of Privilege: 29 vulnerabilities
  • Remote Code Execution (RCE): 16 vulnerabilities
  • Information Disclosure: 11 vulnerabilities
  • Denial of Service: 3 vulnerabilities
  • Security Feature Bypass: 2 vulnerabilities
  • Spoofing: 2 vulnerabilities

Security experts highlight Remote Code Execution and Elevation of Privilege categories as most dangerous, enabling complete system takeover if unpatched.

Affected Products and Components

Beyond the Windows Kernel fix, multiple Microsoft products received security updates:

  • Microsoft Office and Excel: RCE and information disclosure fixes
  • Visual Studio and Copilot Chat Extension: Security bypass and remote execution patches
  • Windows DirectX and Windows OLE: Remote code execution and privilege escalation resolutions
  • Windows Routing and Remote Access Service (RRAS): RCE and DoS vulnerability patches
  • Windows Subsystem for Linux (WSL): GUI system remote code execution fix

Immediate Action Required

All Windows users should install updates immediately via Windows Update, followed by system restart. Critical systems and corporate servers require data backup before patching. Enterprises should deploy patch management systems for comprehensive coverage.

To verify update installation, navigate to Settings > System > About and confirm OS build number 26200.7171 or higher under Windows specifications.

Latest

Sam Altman reveals real reason why OpenAI rushed to partner with US Military after Trump banned Anthropic

OpenAI executives have given more information regarding the AI startup’s contract with the US Department of Defense after facing backlash online. The Sam Altm

After Donald Trump banned Anthropic, US Military used Claude in Iran strikes: Here is what changed

The US Military reportedly used Anthropic’s Claude AI model during its strikes on Iran. The attack on Iran came just a day after US President Donald Trump ins

SIM binding rules go live starting March 1: These WhatsApp, Telegram, Signal and other messaging app users to be impacted

Tech News News: Starting March 1, messaging apps like WhatsApp, Telegram, Signal and others must comply with the Department of Telecommunications' SIM-binding r

More than one year after DeepSeek’s R1 wiped nearly $600 billion off Nvidia market value in single day, Chinese startup planning another launch

Tech News News: DeepSeek, the Chinese AI startup that wiped nearly $600 billion off Nvidia’s market value in a single day with launch of its R1 model, is repo

Nothing Phone 4a and 4a Pro launching on 5 March: Design, expected specs and more

Nothing is set to launch its Phone 4 (a) series on 5 March. The launch event is also likely to see the unveling of new Headphone (a) with bold colors and long b

Topics

Taliban attacks Pak’s Nur Khan base in latest escalation of cross border conflict

Taliban forces reportedly launched armed drone strikes targeting Pakistan’s Command and Control Centre at Nur Khan Air Base in Rawalpindi. Taliban forces carr

Satellite images show damage across Iranian military sites after US-Israel strikes

Fresh satellite imagery shows visible damage to air, drone and naval facilities near Iran’s Konarak region amid escalating regional tensions. The visuals offe

Sensex down 1,000 points: Why is the stock market falling today?

The S&P BSE Sensex fell sharply in early trade, and the NSE Nifty50 also slipped more than 1%, as investors reacted to the fast-changing situation between the U

Qatar, UAE, Syria, Oman: Full list of places that saw attacks amid US-Iran conflict

The Middle East is engulfed in conflict as Iran retaliates against US-Israeli strikes, launching missile and drone attacks across multiple countries. 

AIIMS-trained neurologist warns against repeatedly using reheated cooking oils: ‘Risk of cancer increases manifold…’

Reusing cooking oil is a common practice in many households, but does the money it saves outweigh the health risks? Dr Sehrawat explains the health risks.

Quote of the day by Jon Bon Jovi: ‘You better stand tall when they’re calling you out, don’t bend, don’t break…’

On his birthday, we look back at one of Jon Bon Jovi's most influential quotes, which highlights the importance of standing tall in the face of criticism.

Satellite images show black smoke over Dubai as Iran continues to fire missiles, drones

Iran-US war: Dubai's skyline has dramatically changed after Iranian attacks, with smoke visible in satellite images.

Sam Altman reveals real reason why OpenAI rushed to partner with US Military after Trump banned Anthropic

OpenAI executives have given more information regarding the AI startup’s contract with the US Department of Defense after facing backlash online. The Sam Altm
spot_img

Related Articles

Popular Categories

spot_imgspot_img