diff --git a/Misc/NEWS.d/next/Windows/2022-04-01-14-57-40.bpo-47194.IB0XL4.rst b/Misc/NEWS.d/next/Windows/2022-04-01-14-57-40.bpo-47194.IB0XL4.rst
new file mode 100644
index 000000000000000..7e76add45fa953b
--- /dev/null
+++ b/Misc/NEWS.d/next/Windows/2022-04-01-14-57-40.bpo-47194.IB0XL4.rst
@@ -0,0 +1 @@
+Update ``zlib`` to v1.2.12 to resolve CVE-2018-25032.
diff --git a/PCbuild/get_externals.bat b/PCbuild/get_externals.bat
index e0183bf250ae8ef..9e2d70cd5d86382 100644
--- a/PCbuild/get_externals.bat
+++ b/PCbuild/get_externals.bat
@@ -59,7 +59,7 @@ if NOT "%IncludeTkinterSrc%"=="false" set libraries=%libraries% tcl-core-8.6.9.0
if NOT "%IncludeTkinterSrc%"=="false" set libraries=%libraries% tk-8.6.9.0
if NOT "%IncludeTkinterSrc%"=="false" set libraries=%libraries% tix-8.4.3.6
set libraries=%libraries% xz-5.2.2
-set libraries=%libraries% zlib-1.2.11
+set libraries=%libraries% zlib-1.2.12
for %%e in (%libraries%) do (
if exist "%EXTERNALS_DIR%\%%e" (
diff --git a/PCbuild/python.props b/PCbuild/python.props
index ec33f3d60e9722a..a2d541bd76ae9f2 100644
--- a/PCbuild/python.props
+++ b/PCbuild/python.props
@@ -66,7 +66,7 @@
$(ExternalsDir)openssl-bin-1.1.1n\$(ArchName)\
$(opensslOutDir)include
$(ExternalsDir)\nasm-2.11.06\
- $(ExternalsDir)\zlib-1.2.11\
+ $(ExternalsDir)\zlib-1.2.12\
_d