詳細検索

[November 2025 Edition] Summary of Vulnerabilities to Address Now|Adobe, Windows, Oracle

Avatar
by 似里
3 min read

[November 2025 Edition] Summary of Vulnerabilities to Address Now|Adobe, Windows, Oracle
Translated from 日本語 • View original
似里
似里

Hello! I'm a Colorkrew infrastructure and security engineer. I am about to take the information processing security support specialist exam next spring. In the fall exam of Reiwa 7, questions related to AI were also asked, so I feel the need to grasp trends.

For those involved in SOC/security operations, we have provided explanations + countermeasures based on the "Known Exploited Vulnerbilities Catalog", which publishes public information by the Cybersecurity and Infrastructure Security Agency (CISA) about the most recent vulnerabilities of interest. Please take advantage of this to reduce the operational burden while visualizing and prioritizing risks.

What is Known Exploited Vulnerabilities Catalog?

The Known Exploited Vulnerabilities (KEV) Catalog is a list of "Vulnerabilities Confirmed to Have Actually Exploited" published by CISA. Therefore, it can be used as a criterion for quickly responding to vulnerabilities that are actually used in cyberattacks.

Overview of each vulnerability and how to address it


CVE-2025-54253

Product/Scope of Influence Adobe Experience Manager (AEM) Forms


Target version: 6.5.23 and earlier

Overview/Key Points

This is a serious vulnerability due to "Invalid Authorization (CWE-863)" in Adobe Experience Manager.
Incorrect access control settings can bypass authentication and allow arbitrary code execution. An attacker can take over the system and execute arbitrary code without user interaction.
The CVSS 3.1 score is the highest at 10.0 (Critical), indicating a broad range of impact.

Points to Deal with

Apply the update to the latest patch published by Adobe (6.5.0-0108 or later) as soon as possible. For details on what to do before the update and how to update, please refer to this official documentation.


CVE-2025-59230

Product/Scope of Influence for Microsoft Windows


All Windows servers/clients, including the Remote Access Connection Manager (RasMan) service, may be affected.

Overview/Key Points

This vulnerability allows an attacker to escalate privileges in a local environment due to "improper access control (CWE-284)".
Authenticated users can take over system privileges, which can be exploited to spread internal compromises.
The CVSS 3.1 score is 7.8 (High).

Points to Deal with

Use this official guidance to apply the latest security patches as soon as possible.


CVE-2025-24990

Product/Scope of Influence Agere Modem
Driver (ltmdm64.sys) that comes standard with Windows OS


Affects both Windows Server and client.

Overview/Key Points

An "untrusted pointer reference (CWE-822)" vulnerability that allows privilege escalation.
Microsoft has identified issues caused by third-party Agere Modem drivers and removed them in the October 2025 cumulative update. As a result, the fax modem hardware will no longer be available, so you need to be careful about the operating effects on the dependent system.
The CVSS 3.1 score is 7.8 (High).

Points to Deal with

Use this official guidance to apply the latest security patches as soon as possible.


CVE-2025-61884

Product/Scope of Influence Oracle E-Business Suite


Target Component: Oracle Configurator (Runtime UI)
Target versions: 12.2.3 to 12.2.14

Overview/Key Points

Oracle Configurator の Runtime UI
An information disclosure vulnerability in a component due to an authentication-free access control failure.
An attacker could gain unauthenticated access to the system via HTTP and obtain sensitive data (configuration and configuration information) within the Configurator. The CVSS 3.1 score is 7.5 (High).

Points to Deal with

Apply the October 2025 Critical Patch Update (CPU) patch provided by Oracle.


What Colorkrew can help Colorkrew can help ColorkrewSecurity provides SOC services that support attack detection and CSIRT response to vulnerabilities such as the above.

If you have any requests such as "I want to reduce the operational burden" or "I want to quickly detect cyber attacks", please feel free to contact us. Let's strengthen your company's security operations together.

Related Articles