Claude is having a major outage. Status board · Discuss Claude

Patch Tuesday: November 2025

Each month's Microsoft security updates: what to patch first, the Critical fixes, and what CISA says attackers are exploiting.

How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.

Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)

November 2025 Patch Tuesday: Microsoft fixed 63 vulnerabilities, 5 of them Critical. 1 was already being exploited. Released Tue 11 Nov 2025.

  • 63vulnerabilities fixed
  • 5Critical
  • 1exploited before the fix
  • 0publicly disclosed
  • 2now on CISA KEV

By type: 29 elevation of privilege, 16 remote code execution, 11 information disclosure, 3 denial of service, 2 spoofing, 2 security feature bypass.

Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.

Patch these first

Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.

CVEWhatSeverityCVSSWhy first
CVE-2025-60710Host Process for Windows Tasks Elevation of PrivilegeImportant7.8On CISA KEV federal deadline 27 Apr Ransomware
CVE-2025-62215Windows Kernel Elevation of PrivilegeImportant7.0Exploited On CISA KEV federal deadline 3 Dec

Critical (5)

Microsoft’s top rating: usually code execution with little or no user action.

CVEWhatImpactCVSS
CVE-2025-60724GDI+ Remote Code ExecutionRemote Code Execution9.8
CVE-2025-30398Nuance PowerScribe 360 Information DisclosureInformation Disclosure8.1
CVE-2025-62199Microsoft Office Remote Code ExecutionRemote Code Execution7.8
CVE-2025-60716DirectX Graphics Kernel Elevation of PrivilegeElevation of Privilege7.0
CVE-2025-62214Visual Studio Remote Code ExecutionRemote Code Execution6.7

Added to CISA KEV in November 2025 (11)

Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.

CVEVendor and productWhatAddedFederal deadlineRansomware
CVE-2021-26829OpenPLC ScadaBRCross-site Scripting28 Nov19 Dec 2025
CVE-2025-61757Oracle Fusion MiddlewareMissing Authentication for Critical Function21 Nov12 Dec 2025
CVE-2025-13223Google Chromium V8Type Confusion19 Nov10 Dec 2025
CVE-2025-58034Fortinet FortiWebOS Command Injection18 Nov25 Nov 2025
CVE-2025-64446Fortinet FortiWebPath Traversal14 Nov21 Nov 2025
CVE-2025-12480Gladinet TriofoxImproper Access Control12 Nov3 Dec 2025
CVE-2025-62215Microsoft WindowsRace Condition12 Nov3 Dec 2025
CVE-2025-9242WatchGuard FireboxOut-of-Bounds Write12 Nov3 Dec 2025
CVE-2025-21042Samsung Mobile DevicesOut-of-Bounds Write10 Nov1 Dec 2025
CVE-2025-11371Gladinet CentreStack and TriofoxFiles or Directories Accessible to External Parties4 Nov25 Nov 2025
CVE-2025-48703CWP Control Web PanelOS Command Injection4 Nov25 Nov 2025

All 63 fixes

Show the full list, with a filter
CVEProductWhatSeverityCVSS
CVE-2025-60724Microsoft Graphics ComponentGDI+ Remote Code ExecutionCritical9.8
CVE-2025-30398Nuance PowerScribeNuance PowerScribe 360 Information DisclosureCritical8.1
CVE-2025-62199Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical7.8
CVE-2025-60716Windows DirectXDirectX Graphics Kernel Elevation of PrivilegeCritical7.0
CVE-2025-62214Visual StudioVisual Studio Remote Code ExecutionCritical6.7
CVE-2025-59499SQL ServerMicrosoft SQL Server Elevation of PrivilegeImportant8.8
CVE-2025-62220Windows Subsystem for Linux GUIWindows Subsystem for Linux GUI Remote Code ExecutionImportant8.8
CVE-2025-62222Visual Studio Code CoPilot Chat ExtensionAgentic AI and Visual Studio Code Remote Code ExecutionImportant8.8
CVE-2025-62210Dynamics 365 Field Service (online)Dynamics 365 Field Service (online) SpoofingImportant8.7
CVE-2025-62211Dynamics 365 Field Service (online)Dynamics 365 Field Service (online) SpoofingImportant8.7
CVE-2025-60715Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code ExecutionImportant8.0
CVE-2025-62204Microsoft Office SharePointMicrosoft SharePoint Remote Code ExecutionImportant8.0
CVE-2025-62452Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code ExecutionImportant8.0
CVE-2025-59505Windows Smart CardWindows Smart Card Reader Elevation of PrivilegeImportant7.8
CVE-2025-59511Windows WLAN ServiceWindows WLAN Service Elevation of PrivilegeImportant7.8
CVE-2025-59512Customer Experience Improvement Program (CEIP)Customer Experience Improvement Program (CEIP) Elevation of PrivilegeImportant7.8
CVE-2025-59514Microsoft Streaming ServiceMicrosoft Streaming Service Proxy Elevation of PrivilegeImportant7.8
CVE-2025-60703Windows Remote DesktopWindows Remote Desktop Services Elevation of PrivilegeImportant7.8
CVE-2025-60705Windows Client-Side Caching (CSC) ServiceWindows Client-Side Caching Elevation of PrivilegeImportant7.8
CVE-2025-60707Multimedia Class Scheduler Service (MMCSS)Multimedia Class Scheduler Service (MMCSS) Driver Elevation of PrivilegeImportant7.8
CVE-2025-60709Windows Common Log File System DriverWindows Common Log File System Driver Elevation of PrivilegeImportant7.8
CVE-2025-60710Host Process for Windows TasksHost Process for Windows Tasks Elevation of PrivilegeImportant7.8
CVE-2025-60713Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Elevation of PrivilegeImportant7.8
CVE-2025-60714Windows OLEWindows OLE Remote Code ExecutionImportant7.8
CVE-2025-60718Windows Administrator ProtectionWindows Administrator Protection Elevation of PrivilegeImportant7.8
CVE-2025-60720Windows TDX.sysWindows Transport Driver Interface (TDI) Translation Driver Elevation of PrivilegeImportant7.8
CVE-2025-60721Windows Administrator ProtectionWindows Administrator Protection Elevation of PrivilegeImportant7.8
CVE-2025-60727Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-62200Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-62201Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-62203Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-62205Microsoft Office WordMicrosoft Office Remote Code ExecutionImportant7.8
CVE-2025-62216Microsoft OfficeMicrosoft Office Remote Code ExecutionImportant7.8
CVE-2025-60704Windows KerberosWindows Kerberos Elevation of PrivilegeImportant7.5
CVE-2025-59504Azure Monitor AgentAzure Monitor Agent Remote Code ExecutionImportant7.3
CVE-2025-60726Microsoft Office ExcelMicrosoft Excel Information DisclosureImportant7.1
CVE-2025-62202Microsoft Office ExcelMicrosoft Excel Information DisclosureImportant7.1
CVE-2025-59506Windows DirectXDirectX Graphics Kernel Elevation of PrivilegeImportant7.0
CVE-2025-59507Windows SpeechWindows Speech Runtime Elevation of PrivilegeImportant7.0
CVE-2025-59508Windows SpeechWindows Speech Recognition Elevation of PrivilegeImportant7.0
CVE-2025-59515Windows Broadcast DVR User ServiceWindows Broadcast DVR User Service Elevation of PrivilegeImportant7.0
CVE-2025-60717Windows Broadcast DVR User ServiceWindows Broadcast DVR User Service Elevation of PrivilegeImportant7.0
CVE-2025-60719Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2025-62213Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2025-62215Windows KernelWindows Kernel Elevation of PrivilegeImportant7.0
CVE-2025-62217Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2025-62218Microsoft Wireless Provisioning SystemMicrosoft Wireless Provisioning System Elevation of PrivilegeImportant7.0
CVE-2025-62219Microsoft Wireless Provisioning SystemMicrosoft Wireless Provisioning System Elevation of PrivilegeImportant7.0
CVE-2025-62449Visual Studio Code CoPilot Chat ExtensionMicrosoft Visual Studio Code CoPilot Chat Extension Security Feature BypassImportant6.8
CVE-2025-47179Microsoft Configuration ManagerConfiguration Manager Elevation of PrivilegeImportant6.7
CVE-2025-60708Storvsp.sys DriverStorvsp.sys Driver Denial of ServiceImportant6.5
CVE-2025-60722OneDrive for AndroidMicrosoft OneDrive for Android Elevation of PrivilegeImportant6.5
CVE-2025-62206Microsoft Dynamics 365 (on-premises)Microsoft Dynamics 365 (On-Premises) Information DisclosureImportant6.5
CVE-2025-60723Windows DirectXDirectX Graphics Kernel Denial of ServiceImportant6.3
CVE-2025-59240Microsoft Office ExcelMicrosoft Excel Information DisclosureImportant5.5
CVE-2025-59509Windows SpeechWindows Speech Recognition Information DisclosureImportant5.5
CVE-2025-59510Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Denial of ServiceImportant5.5
CVE-2025-59513Windows Bluetooth RFCOM Protocol DriverWindows Bluetooth RFCOM Protocol Driver Information DisclosureImportant5.5
CVE-2025-60706Role: Windows Hyper-VWindows Hyper-V Information DisclosureImportant5.5
CVE-2025-62208Windows License ManagerWindows License Manager Information DisclosureImportant5.5
CVE-2025-62209Windows License ManagerWindows License Manager Information DisclosureImportant5.5
CVE-2025-62453GitHub Copilot and Visual Studio CodeGitHub Copilot and Visual Studio Code Security Feature BypassImportant5.0
CVE-2025-60728Microsoft Office ExcelMicrosoft Excel Information DisclosureImportant4.3

Published later in the month (8)

Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.

DateCVEWhatSeverityAction
20 NovCVE-2025-49752Azure Bastion Elevation of PrivilegeCriticalFixed by Microsoft
20 NovCVE-2025-59245Microsoft SharePoint Online Elevation of PrivilegeCriticalFixed by Microsoft
20 NovCVE-2025-64657Azure Application Gateway Elevation of PrivilegeCriticalFixed by Microsoft
20 NovCVE-2025-64656Azure Application Gateway Elevation of PrivilegeCriticalFixed by Microsoft
20 NovCVE-2025-64655Dynamics OmniChannel SDK Storage Containers Elevation of PrivilegeCriticalFixed by Microsoft
20 NovCVE-2025-62207Azure Monitor Elevation of PrivilegeCriticalFixed by Microsoft
20 NovCVE-2025-62459Microsoft Defender Portal SpoofingCriticalFixed by Microsoft
20 NovCVE-2025-64660GitHub Copilot and Visual Studio Code Remote Code ExecutionImportantUpdate

From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 1 day ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.

← All tools