º¸¾È/ÆÐÄ¡

ÀÌÀü ÆäÀÌÁö·Î ¸Þ´ºº¸±â

MS 11¿ù º¸¾È À§Çù¿¡ µû¸¥ Á¤±â º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í

°ü¸®ÀÚ ( hosting@hhosting.co.kr )  2025-11-14 09:15:37

Á¶È¸¼ö 181
¡à 11¿ù º¸¾È¾÷µ¥ÀÌÆ® °³¿ä (ÃÑ 14 Á¾ )

o µî±Þ : ±ä±Þ (Critical) 9 Á¾ , Áß¿ä (Important) 5 Á¾
o ¹ßÇ¥ÀÏ : 2025.11.11.(È­)
o ¾÷µ¥ÀÌÆ® ³»¿ë



Á¦Ç°±º

Á߿䵵

¿µÇâ

Windows 11 25H2

±ä±Þ

±ÇÇÑ »ó½Â

Windows 11 24H2

±ä±Þ

±ÇÇÑ »ó½Â

Windows 11 23H2

±ä±Þ

±ÇÇÑ »ó½Â

Windows Server 2025, Windows Server 2025(Server Core ¼³Ä¡)

±ä±Þ

±ÇÇÑ »ó½Â

Windows Server 2022 23H2 ¹öÀü(Server Core ¼³Ä¡),

Windows Server 2022, Windows Server 2022(Server Core ¼³Ä¡)

±ä±Þ

±ÇÇÑ »ó½Â

Windows Server 2019

±ä±Þ

±ÇÇÑ »ó½Â

Windows Server 2016

±ä±Þ

±ÇÇÑ »ó½Â

Microsoft Office

±ä±Þ

¿ø°Ý ÄÚµå ½ÇÇà

Microsoft SharePoint

Áß¿ä

¿ø°Ý ÄÚµå ½ÇÇà

Microsoft Visual Studio

±ä±Þ

¿ø°Ý ÄÚµå ½ÇÇà

Microsoft Dynamics 365

Áß¿ä

½ºÇªÇÎ

Microsoft SQL Server

Áß¿ä

±ÇÇÑ »ó½Â

Microsoft Azure

Áß¿ä

¿ø°Ý ÄÚµå ½ÇÇà

Microsoft System Center

Áß¿ä

±ÇÇÑ »ó½Â



[Âü°í »çÀÌÆ®]
[1] (ÇѱÛ) https://msrc.microsoft.com/update-guide/ko-kr/
[2] (¿µ¹®) https://msrc.microsoft.com/update-guide/en-us/
[3] https://msrc.microsoft.com/update-guide/ko-kr/releaseNote/2025-Nov



o Ãë¾àÁ¡ ¿ä¾à Á¤º¸ (ÃÑ 134°³)

Á¦Ç° Ä«Å×°í¸®

CVE ¹øÈ£

CVE Á¦¸ñ

Mariner

CVE-2025-64437

KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes

Mariner

CVE-2025-64436

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

Mariner

CVE-2025-64435

KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation

Mariner

CVE-2025-64434

KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing

Mariner

CVE-2025-64433

KubeVirt Arbitrary Container File Read

Mariner

CVE-2025-64432

KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer

Mariner

CVE-2025-64329

containerd CRI server: Host memory exhaustion through Attach goroutine leak

GitHub Copilot and Visual Studio Code

CVE-2025-62453

GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability

Windows Routing and Remote Access Service (RRAS)

CVE-2025-62452

Windows RRAS(Routing and Remote Access Service) ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Visual Studio Code CoPilot Chat Extension

CVE-2025-62449

Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability

Visual Studio Code CoPilot Chat Extension

CVE-2025-62222

¿¡ÀÌÀüÆ® AI ¹× Visual Studio Code ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Windows Subsystem for Linux GUI

CVE-2025-62220

Windows Subsystem for Linux GUI Remote Code Execution Vulnerability

Microsoft Wireless Provisioning System

CVE-2025-62219

Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability

Microsoft Wireless Provisioning System

CVE-2025-62218

Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability

Windows Ancillary Function Driver for WinSock

CVE-2025-62217

WinSock¿ë Windows º¸Á¶ ±â´É µå¶óÀ̹ö ±ÇÇÑ »ó½Â Ãë¾à¼º

Microsoft Office

CVE-2025-62216

Microsoft Office ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Windows Kernel

CVE-2025-62215

Windows Ä¿³Î ±ÇÇÑ »ó½Â Ãë¾à¼º

Visual Studio

CVE-2025-62214

Visual Studio ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Windows Ancillary Function Driver for WinSock

CVE-2025-62213

WinSock¿ë Windows º¸Á¶ ±â´É µå¶óÀ̹ö ±ÇÇÑ »ó½Â Ãë¾à¼º

Dynamics 365 Field Service (online)

CVE-2025-62211

Dynamics 365 Field Service(¿Â¶óÀÎ) ½ºÇªÇÎ Ãë¾à¼º

Dynamics 365 Field Service (online)

CVE-2025-62210

Dynamics 365 Field Service(¿Â¶óÀÎ) ½ºÇªÇÎ Ãë¾à¼º

Windows License Manager

CVE-2025-62209

Windows License Manager Information Disclosure Vulnerability

Windows License Manager

CVE-2025-62208

Windows License Manager Information Disclosure Vulnerability

Microsoft Dynamics 365 (on-premises)

CVE-2025-62206

Microsoft Dynamics 365(¿Â-ÇÁ·¹¹Ì½º) Á¤º¸ °ø°³ Ãë¾à¼º

Microsoft Office Word

CVE-2025-62205

Microsoft Office ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office SharePoint

CVE-2025-62204

Microsoft SharePoint ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office Excel

CVE-2025-62203

Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office Excel

CVE-2025-62202

Microsoft Excel Á¤º¸ À¯Ãâ Ãë¾à¼º

Microsoft Office Excel

CVE-2025-62201

Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office Excel

CVE-2025-62200

Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office

CVE-2025-62199

Microsoft Office ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Mariner

CVE-2025-60753

An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).

Microsoft Office Excel

CVE-2025-60728

Microsoft Excel Á¤º¸ À¯Ãâ Ãë¾à¼º

Microsoft Office Excel

CVE-2025-60727

Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office Excel

CVE-2025-60726

Microsoft Excel Á¤º¸ À¯Ãâ Ãë¾à¼º

Microsoft Graphics Component

CVE-2025-60724

GDI+ ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Windows DirectX

CVE-2025-60723

DirectX Graphics Ä¿³Î ¼­ºñ½º °ÅºÎ Ãë¾à¼º

OneDrive for Android

CVE-2025-60722

Microsoft OneDrive for Android Elevation of Privilege Vulnerability

Windows Administrator Protection

CVE-2025-60721

Windows Administrator Protection Elevation of Privilege Vulnerability

Windows TDX.sys

CVE-2025-60720

Windows Transport Driver Interface(TDI) º¯È¯ µå¶óÀ̹ö ±ÇÇÑ »ó½Â Ãë¾à¼º

Windows Ancillary Function Driver for WinSock

CVE-2025-60719

WinSock¿ë Windows º¸Á¶ ±â´É µå¶óÀ̹ö ±ÇÇÑ »ó½Â Ãë¾à¼º

Windows Administrator Protection

CVE-2025-60718

Windows Administrator Protection Elevation of Privilege Vulnerability

Windows Broadcast DVR User Service

CVE-2025-60717

Windows Broadcast DVR User Service Elevation of Privilege Vulnerability

Windows DirectX

CVE-2025-60716

DirectX Graphics Ä¿³Î ±ÇÇÑ »ó½Â Ãë¾à¼º

Windows Routing and Remote Access Service (RRAS)

CVE-2025-60715

Windows RRAS(Routing and Remote Access Service) ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Windows OLE

CVE-2025-60714

Windows OLE ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Windows Routing and Remote Access Service (RRAS)

CVE-2025-60713

Windows RRAS(¶ó¿ìÆÃ ¹× ¿ø°Ý ¾×¼¼½º ¼­ºñ½º) ±ÇÇÑ »ó½Â Ãë¾à¼º

Microsoft Edge (Chromium-based)

CVE-2025-60711

Microsoft Edge(Chromium ±â¹Ý) ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Host Process for Windows Tasks

CVE-2025-60710

Host Process for Windows Tasks Elevation of Privilege Vulnerability

Windows Common Log File System Driver

CVE-2025-60709

Windows °ø¿ë ·Î±× ÆÄÀÏ ½Ã½ºÅÛ µå¶óÀ̹ö ±ÇÇÑ »ó½Â Ãë¾à¼º

Storvsp.sys Driver

CVE-2025-60708

Storvsp.sys Driver Denial of Service Vulnerability

Multimedia Class Scheduler Service (MMCSS)

CVE-2025-60707

Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability

Role: Windows Hyper-V

CVE-2025-60706

Windows Hyper-V Á¤º¸ À¯Ãâ Ãë¾à¼º

Windows Client-Side Caching (CSC) Service

CVE-2025-60705

Windows Ŭ¶óÀÌ¾ðÆ® ÂÊ Ä³½Ì ±ÇÇÑ »ó½Â Ãë¾à¼º

Windows Kerberos

CVE-2025-60704

Windows Kerberos ±ÇÇÑ »ó½Â Ãë¾à¼º

Windows Remote Desktop

CVE-2025-60703

Windows ¿ø°Ý µ¥½ºÅ©Åé ¼­ºñ½º ±ÇÇÑ »ó½Â Ãë¾à¼º

Windows Broadcast DVR User Service

CVE-2025-59515

Windows Broadcast DVR User Service Elevation of Privilege Vulnerability

Microsoft Streaming Service

CVE-2025-59514

Microsoft ½ºÆ®¸®¹Ö ¼­ºñ½º ÇÁ·Ï½Ã ±ÇÇÑ »ó½Â Ãë¾à¼º

Windows Bluetooth RFCOM Protocol Driver

CVE-2025-59513

Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability

Customer Experience Improvement Program (CEIP)

CVE-2025-59512

Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability

Windows WLAN Service

CVE-2025-59511

Windows WLAN ¼­ºñ½º ±ÇÇÑ »ó½Â Ãë¾à¼º

Windows Routing and Remote Access Service (RRAS)

CVE-2025-59510

Windows ¶ó¿ìÆÃ ¹× ¿ø°Ý ¾×¼¼½º ¼­ºñ½º(RRAS) ¼­ºñ½º °ÅºÎ Ãë¾à¼º

Windows Speech

CVE-2025-59509

Windows Speech Recognition Information Disclosure Vulnerability

Windows Speech

CVE-2025-59508

Windows Speech Recognition Elevation of Privilege Vulnerability

Windows Speech

CVE-2025-59507

Windows À½¼º ·±Å¸ÀÓ ±ÇÇÑ »ó½Â Ãë¾à¼º

Windows DirectX

CVE-2025-59506

DirectX Graphics Ä¿³Î ±ÇÇÑ »ó½Â Ãë¾à¼º

Windows Smart Card

CVE-2025-59505

Windows Smart Card Reader Elevation of Privilege Vulnerability

Azure Monitor Agent

CVE-2025-59504

Azure Monitor ¿¡ÀÌÀüÆ® ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Azure Compute Gallery

CVE-2025-59503

Azure Compute Resource Provider Elevation of Privilege Vulnerability

Microsoft Configuration Manager

CVE-2025-59501

Microsoft Configuration Manager Spoofing Vulnerability

Azure Notification Service

CVE-2025-59500

Azure Notification Service Elevation of Privilege Vulnerability

SQL Server

CVE-2025-59499

Microsoft SQL Server ±ÇÇÑ »ó½Â Ãë¾à¼º

Internet Explorer

CVE-2025-59295

Windows URL ±¸¹® ºÐ¼® ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Windows Server Update Service

CVE-2025-59287

Windows Server ¾÷µ¥ÀÌÆ® ¼­ºñ½º(WSUS) ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Azure Event Grid

CVE-2025-59273

Azure Event Grid ½Ã½ºÅÛ ±ÇÇÑ »ó½Â Ãë¾à¼º

Microsoft Office Excel

CVE-2025-59240

Microsoft Excel Á¤º¸ À¯Ãâ Ãë¾à¼º

Windows USB Video Driver

CVE-2025-55676

Windows USB ºñµð¿À Ŭ·¡½º ½Ã½ºÅÛ µå¶óÀ̹ö Á¤º¸ °ø°³ Ãë¾à¼º

Microsoft Configuration Manager

CVE-2025-55320

±¸¼º °ü¸®ÀÚ ±ÇÇÑ »ó½Â Ãë¾à¼º

ASP.NET Core

CVE-2025-55315

ASP.NET º¸¾È ±â´É ¹ÙÀÌÆÐ½º Ãë¾à¼º

Microsoft Office Word

CVE-2025-53784

Microsoft Word ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Teams

CVE-2025-53783

Microsoft Teams ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office PowerPoint

CVE-2025-53761

Microsoft PowerPoint ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office SharePoint

CVE-2025-53760

Microsoft SharePoint ±ÇÇÑ »ó½Â Ãë¾à¼º

Microsoft Office Excel

CVE-2025-53759

Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office Excel

CVE-2025-53741

Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office

CVE-2025-53740

Microsoft Office ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office Excel

CVE-2025-53739

Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office Word

CVE-2025-53738

Microsoft Word ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office Excel

CVE-2025-53737

Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office Word

CVE-2025-53736

Microsoft Word Á¤º¸ À¯Ãâ Ãë¾à¼º

Microsoft Office Excel

CVE-2025-53735

Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office Word

CVE-2025-53733

Microsoft Word ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Microsoft Office

CVE-2025-53731

Microsoft Office ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º

Mariner

CVE-2025-52881

runc: LSM labels can be bypassed with malicious config using dummy procfs files

Mariner

CVE-2025-52565

container escape due to /dev/console mount and related races

Windows File Explorer

CVE-2025-50154

Microsoft Windows ÆÄÀÏ Å½»ö±â ½ºÇªÇÎ Ãë¾à¼º

Windows Secure Boot

CVE-2025-47827

MITRE CVE-2025-47827: IGEL OS 11 ÀÌÀü ¹öÀü¿¡¼­ º¸¾È ºÎÆÃ ¹ÙÀÌÆÐ½º

Microsoft Configuration Manager

CVE-2025-47179

±¸¼º °ü¸®ÀÚ ±ÇÇÑ »ó½Â Ãë¾à¼º

Mariner

CVE-2025-40109

crypto: rng - Ensure set_ent is always present

Mariner

CVE-2025-40107

can: hi311x: fix null pointer dereference when resuming from sleep before interface was enabled

Mariner

CVE-2025-31133

runc container escape via "masked path" abuse due to mount race conditions

Nuance PowerScribe

CVE-2025-30398

Nuance PowerScribe 360 Á¤º¸ °ø°³ Ãë¾à¼º

Microsoft PowerShell

CVE-2025-25004

PowerShell ±ÇÇÑ »ó½Â Ãë¾à¼º

Mariner

CVE-2025-12875

mruby array.c ary_fill_exec out-of-bounds write

Mariner

CVE-2025-12863

Libxml2: namespace use-after-free in xmlsettreedoc() function of libxml2

Microsoft Edge (Chromium-based)

CVE-2025-12729

Chromium: CVE-2025-12729 Omnibox¿¡¼­ ºÎÀûÀýÇÑ ±¸Çö

Microsoft Edge (Chromium-based)

CVE-2025-12728

Chromium: CVE-2025-12728 Omnibox¿¡¼­ ºÎÀûÀýÇÑ ±¸Çö

Microsoft Edge (Chromium-based)

CVE-2025-12727

Chromium: CVE-2025-12727 V8¿¡¼­ ºÎÀûÀýÇÑ ±¸Çö

Microsoft Edge (Chromium-based)

CVE-2025-12726

Chromium: CVE-2025-12726 º¸±â¿¡¼­ ºÎÀûÀýÇÑ ±¸Çö

Microsoft Edge (Chromium-based)

CVE-2025-12725

Chromium: CVE-2025-12725 WebGPU¿¡¼­ ¹üÀ§¸¦ ¹þ¾î³­ ¾²±â

Microsoft Edge (Chromium-based)

CVE-2025-12447

Chromium: CVE-2025-12447 Incorrect security UI in Omnibox

Microsoft Edge (Chromium-based)

CVE-2025-12446

Chromium: CVE-2025-12446 Incorrect security UI in SplitView

Microsoft Edge (Chromium-based)

CVE-2025-12445

Chromium: CVE-2025-12445 Policy bypass in Extensions

Microsoft Edge (Chromium-based)

CVE-2025-12444

Chromium: CVE-2025-12444 Incorrect security UI in Fullscreen UI

Microsoft Edge (Chromium-based)

CVE-2025-12443

Chromium: CVE-2025-12433 Inappropriate implementation in V8

Microsoft Edge (Chromium-based)

CVE-2025-12441

Chromium: CVE-2025-12441 Out of bounds read in V8

Microsoft Edge (Chromium-based)

CVE-2025-12440

Chromium: CVE-2025-12440 Inappropriate implementation in Autofill

Microsoft Edge (Chromium-based)

CVE-2025-12439

Chromium: CVE-2025-12439 Inappropriate implementation in App-Bound Encryption

Microsoft Edge (Chromium-based)

CVE-2025-12438

Chromium: CVE-2025-12438 Use after free in Ozone

Microsoft Edge (Chromium-based)

CVE-2025-12437

Chromium: CVE-2025-12437 Use after free in PageInfo

Microsoft Edge (Chromium-based)

CVE-2025-12436

Chromium: CVE-2025-12436 Policy bypass in Extensions

Microsoft Edge (Chromium-based)

CVE-2025-12435

Chromium: CVE-2025-12435 Incorrect security UI in Omnibox

Microsoft Edge (Chromium-based)

CVE-2025-12434

Chromium: CVE-2025-12434 Race in Storage

Microsoft Edge (Chromium-based)

CVE-2025-12433

Chromium: CVE-2025-12433 Inappropriate implementation in V8

Microsoft Edge (Chromium-based)

CVE-2025-12432

Chromium: CVE-2025-12432 Race in V8

Microsoft Edge (Chromium-based)

CVE-2025-12431

Chromium: CVE-2025-12431 Inappropriate implementation in Extensions

Microsoft Edge (Chromium-based)

CVE-2025-12430

Chromium: CVE-2025-12430 Object lifecycle issue in Media

Microsoft Edge (Chromium-based)

CVE-2025-12429

Chromium: CVE-2025-12429 Inappropriate implementation in V8

Microsoft Edge (Chromium-based)

CVE-2025-12428

Chromium: CVE-2025-12428 Type Confusion in V8

Microsoft Edge (Chromium-based)

CVE-2025-12036

Chromium: CVE-2025-12036 Inappropriate implementation in V8

Microsoft Edge (Chromium-based)

CVE-2025-11756

Chromium: CVE-2025-11756 Use after free in Safe Browsing

Mariner

CVE-2025-10966

missing SFTP host verification with wolfSSH

Mariner

CVE-2024-25621

containerd affected by a local privilege escalation via wide permissions on CRI directory

Microsoft Edge (Chromium-based)

CVE-2023-4863

Chromium: CVE-2023-4863 WebP¿¡¼­ Èü ¹öÆÛ ¿À¹öÇ÷Î

¡à ÀÛ¼º: À§ÇùºÐ¼®´Ü Ãë¾àÁ¡ºÐ¼®ÆÀ
Back 12 3 4 5