Microsoft October 2025 Patch Tuesday Addresses Multiple Zero-Days and Over 170 Vulnerabilities
Microsoft released its October 2025 Patch Tuesday security updates, addressing a total of 172 vulnerabilities across its product suite, including six zero-day vulnerabilities. The update marks a significant milestone as it is the final free security update for Windows 10, which has now reached its end of support, requiring users and enterprises to enroll in Extended Security Updates (ESU) for continued protection. Among the vulnerabilities patched, eight were rated as 'Critical,' with five being remote code execution flaws and three classified as elevation of privilege vulnerabilities. The breakdown of vulnerabilities includes 80 elevation of privilege, 11 security feature bypass, 31 remote code execution, 28 information disclosure, 11 denial of service, and 10 spoofing vulnerabilities. Notably, two of the zero-day vulnerabilities were publicly disclosed prior to the patch, affecting Windows SMB Server and Microsoft SQL Server, while three zero-days were actively exploited in the wild. One of the exploited zero-days, CVE-2025-24990, involved the Agere Modem driver, which was being abused to gain administrative privileges, prompting Microsoft to remove the vulnerable driver from supported Windows operating systems. The Patch Tuesday release also included updates for a wide range of Microsoft products and components, such as .NET, Visual Studio, Active Directory Federation Services, Microsoft Office suite, Azure services, Windows authentication methods, and various Windows system components. The update was described as the largest Patch Tuesday release to date, with 167 CVEs directly patched according to some sources, excluding additional vulnerabilities in Chromium, MITRE, GitHub, CERT/CC, and cloud services that were addressed separately. The security updates did not include fixes for vulnerabilities in Microsoft Edge, Azure, or Mariner that were released earlier in the month. Microsoft emphasized the importance of these updates, especially for organizations still running Windows 10, as the cessation of free support increases the risk of exposure to unpatched vulnerabilities. The comprehensive nature of the update reflects the ongoing complexity and breadth of the Microsoft ecosystem, with critical patches spanning from core Windows components to cloud and developer tools. Security professionals are advised to prioritize the deployment of these patches, particularly those addressing actively exploited zero-days and critical remote code execution vulnerabilities. The update also highlights the evolving threat landscape, with attackers increasingly targeting third-party drivers and core system components to escalate privileges. Organizations are encouraged to review the full list of patched vulnerabilities and assess their exposure, especially in light of the end of support for Windows 10. The October 2025 Patch Tuesday underscores the necessity of timely patch management and the challenges posed by legacy systems in maintaining a secure enterprise environment.
Jun 29, 2026