MS Family November 2025 Secondary Security Update Advisory
Overview
Microsoft(https://www.microsoft.com) has released a security update that fixes vulnerabilities in products it has supplied. Users of affected products are advised to update to the latest version.
Affected Products
Azure family
Azure App Gateway
Azure Bastion Developer
Azure Monitor Control Service
Developer Tools suite
Visual Studio Code
Microsoft Dynamics Suite
Dynamics OmniChannel SDK Storage Containers
Microsoft Office Suite
Microsoft SharePoint Online
Open Source Software Suite
Azl3 kubevirt 1.5.0-5 on Azure Linux 3.0
Cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0
Windows Family
Microsoft 365 Defender Portal
Resolved Vulnerabilities
Seven vulnerabilities rated Critical and two rated Important were found.
Azure Family
Urgent elevation of privilege vulnerability in Application Gateway (CVE-2025-64656)
Critical elevation of privilege vulnerability in Azure Monitor (CVE-2025-62207)
Urgent escalation of privilege vulnerabilities in Software for Open Networking in the Cloud (SONiC) (CVE-2025-64657, CVE-2025-49752)
Developer Tools Suite
Critical-grade security feature bypass vulnerability in GitHub Copilot and Visual Studio Code (CVE-2025-64660)
Microsoft Dynamics Suite
Critical elevation of privilege vulnerability in Dynamics OmniChannel SDK Storage Containers (CVE-2025-64655)
Microsoft Office Suite
Critical remote code execution vulnerability in Microsoft Office SharePoint (CVE-2025-59245)
Open Source Software Suites
Critical-grade vulnerability in Mariner (CVE-2025-64324)
Windows Family
Urgent-rated spoofing vulnerability in Microsoft Defender Portal (CVE-2025-62459)
Vulnerability Patches
The following product-specific Vulnerability Patches were made available in the November 20, 2025 Update. Please use the Windows Update feature for automatic installation or refer to the URLs in the product information below to download and install.