The B2B Podcast Index
The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups

Urgent: Patch CVE-2025-62221 — December Patch Tuesday Breakdown

The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups · 2025-12-10 · 18 min

Episode notes

Show notes December 2025 just shipped the last Microsoft security fixes of the year. Fifty seven vulnerabilities, three zero days, and one actively exploited Windows privilege escalation that hits almost every supported build. Are you patched before the Christmas break, or are you leaving a present for attackers in January? In this episode, Graham walks through the December Patch Tuesday release for 2025, with a focus on what actually matters for small and medium businesses. You will hear how CVE 2025 62221 in the Windows Cloud Files driver turns a low level account into full system compromise, why Office Preview Pane is once again a risk, and how AI powered tools like GitHub Copilot for JetBrains and PowerShell changes introduce new attack paths. Does your team know about any of that? You also get a fast tour of Adobe and other vendor updates, including ColdFusion, Android, Ivanti, Fortinet, React server components and SAP. Graham then zooms out to review the full year, with more than one thousand one hundred Microsoft vulnerabilities in 2025 and privilege escalation bugs leading the pack.

Listen to this episodeAll The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups episodes →