Summary
November 2025's Patch Tuesday brought three Microsoft vulnerabilities worth a closer look. CVE-2025-62215, a Windows kernel elevation-of-privilege flaw, is already exploited in the wild and still relies on the same routes: phishing and a malicious file or script a user runs locally. CVE-2025-62220 is a WSL remote code execution bug triggered through a crafted RDP file and msrdc plugins. CVE-2025-62222 is a command-injection flaw in VS Code's CoPilot Chat extension that lets attackers run code on developer machines. Ryan Braunstein and Mat Lee explain that agentic AI extensions turn every developer endpoint into a higher-risk asset, so you need to vet extensions hard and shore up RBAC and IAM.
)
)
)
)
)
)
)