Back www.tenable.com Microsofts October 2025 Patch Tuesday Addresses 167 Cves Cve 2025 24990 Cve 2025 59230
Microsoft addresses 167 CVEs in its largest Patch Tuesday to date, including three zero-day vulnerabilities, two of which were exploited in the wild.
Update October 24: The blog has been updated to add additional details for CVE-2025-59287 which has reportedly now been exploited in the wild and has public exploit code available. In addition, an out-of-band update has been released by Microsoft for a more comprehensive fix.
Microsoft patched 167 CVEs in its October 2025 Patch Tuesday release, its largest Patch Tuesday release to date, with seven rated critical, 158 rated important, and two rated moderate. Our counts omitted 27 vulnerabilities, including 14 Chromium CVEs, three MITRE CVEs, one GitHub CVE, one CERT/CC CVE, and eight cloud CVEs that Microsoft published advisories for on October 9.
This month’s update includes patches for:
.NET,.NET Framework, Visual Studio
Active Directory Federation Services
Agere Windows Modem Driver
Azure Connected Machine Agent
Confidential Azure Container Instances
Connected Devices Platform Service (Cdpsvc)
Data Sharing Service Client
JDBC Driver for SQL Server
Microsoft Brokering File System
Microsoft Configuration Manager
Microsoft Failover Cluster Virtual Driver
Microsoft Graphics Component
Microsoft Office Excel
Microsoft Office PowerPoint
Microsoft Office SharePoint
Microsoft Office Visio
Microsoft Office Word
Microsoft Windows Component
Microsoft Windows Speech
Network Connection Status Indicator (NCSI)
NtQueryInformation Token function (ntifs.h)
Software Protection Platform (SPP)
Windows Ancillary Function Driver for WinSock
Windows Authentication Methods
Windows Bluetooth Service
Windows Cloud Files Mini Filter Driver
Windows Connected Devices Platform Service
Windows Cryptographic Services
Windows Device Association Broker service
Windows Digital Media
Windows DWM Core Library
Windows Error Reporting
Windows Failover Cluster
Windows File Explorer
Windows Health and Optimized Experiences Service
Windows High Availability Services
Windows Local Session Manager (LSM)
Windows Management Services
Windows PrintWorkflowUserSvc
Windows Push Notification Core
Windows Remote Access Connection Manager
Windows Remote Desktop Protocol
Windows Remote Desktop Services
Windows Remote Procedure Call
Windows Resilient File System (ReFS)
Windows Resilient File System (ReFS) Deduplication Service
Windows Routing and Remote Access Service (RRAS)
Windows Server Update Service
Windows StateRepository API
Windows Storage Management Provider
Windows USB Video Driver
Windows Virtualization-Based Security (VBS) Enclave
Windows WLAN Auto Config Service
Elevation of Privilege (EoP) vulnerabilities accounted for 47.9% of the vulnerabilities patched this month, followed by Remote Code Execution (RCE) vulnerabilities at 17.4%.
CVE-2025-24052 and CVE-2025-24990 | Windows Agere Modem Driver Elevation of Privilege Vulnerabilities
CVE-2025-24052 and CVE-2025-24990 are EoP vulnerabilities in the third party Agere Modem driver. Both CVEs were assigned CVSSv3 scores of 7.8 and rated as important. Microsoft reports that CVE-2025-24990 has been exploited in the wild and CVE-2025-24052 was disclosed prior to a patch being made available. Successful exploitation would allow an attacker to gain administrator privileges on an affected system.
The ltmdm64.sys driver has historically shipped natively with supported Windows operating systems, but will no longer be supported following the October update. Microsoft notes, that ltmdm64.sys-dependent hardware will no longer work on Windows, and recommends users remove existing dependencies.
CVE-2025-59230 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2025-59230 is an EoP vulnerability affecting Windows Remote Access Connection Manager. According to Microsoft, this vulnerability has been exploited in the wild. It was assigned a CVSSv3 score of 7.8 and is rated as important. Exploitation of this vulnerability involves improper access control in Windows Remote Access Connection Manager and could allow a local attacker to gain SYSTEM privileges.
Including CVE-2025-59230, there have been 22 reported and patched vulnerabilities for the Windows Remote Access Connection Manager service (RasMan) since January 2022. CVE-2025-59230 is the first reported RasMan CVE to be exploited as a zero-day.
CVE-2025-59287 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
CVE-2025-59287 is a RCE in the Windows Server Update Service (WSUS). It was assigned a CVSSv3 score of 9.8 and rated critical. It has been assessed as “Exploitation More Likely” according to Microsoft’s Exploitability Index . An attacker could exploit this vulnerability to gain RCE by sending a crafted event that leads to a deserialization of untrusted data.
This is just the third WSUS vulnerability patched as part of Microsoft Patch Tuesday since 2023, when Microsoft patched two WSUS EoP vulnerabilities (CVE-2023-32056, CVE-2023-35317) in the July 2023 Patch Tuesday , but the first RCE and to be assessed as more likely to be exploited.
On October 23, Microsoft update the security advisory for CVE-2025-59287 with an out-of-band update to "comprehensively address CVE-2025-59287." This update came after a public proof-of-concept was released for the vulnerability which could increase the likelihood of exploitation. While Microsoft's advisory was not updated to acknowledge active exploitation, the National Cyber Security Centre (NCSC) has reported that a trusted partner observed active exploitation on October 24.
Microsoft's advisory does provide some workarounds that can be implemented if immediate patching is not able to be performed. Despite the workarounds available, Microsoft notes that you should "install the updates for this vulnerability as soon as possible even if you plan to leave either of these workarounds in place."
CVE-2025-59227, CVE-2025-59234 | Microsoft Office Remote Code Execution Vulnerability
CVE-2025-59227 and CVE-2025-59234 are RCE vulnerabilities in Microsoft Office. Both vulnerabilities were assigned a CVSSv3 score of 7.8, rated critical and assessed as “Exploitation Less Likely.” An attacker could exploit these flaws through social engineering by sending the malicious Microsoft Office document file to an intended target. Successful exploitation would grant code execution privileges to the attacker.
Despite being flagged as “Less Likely” to be exploited, Microsoft notes that the Preview Pane is an attack vector for both CVEs, which means exploitation does not require the target to open the file.
CVE-2025-55680 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-55680 is an EoP vulnerability in the Windows Cloud Files Mini Filter Driver. It was assigned a CVSSv3 score of 7.8, rated important and assessed as “Exploitation More Likely.” A local, authenticated attacker would need to win a race condition in order to exploit this vulnerability. Successful exploitation would allow the attacker to elevate to SYSTEM privileges.
This is the 17th vulnerability in the Windows Cloud Files Mini Filter Driver since 2022. Microsoft patched two in 2022, six in 2023, six in 2024, and three in 2025. As part of its November 2023 Patch Tuesday release , Microsoft patched CVE-2023-36036, another EoP flaw, that was exploited in the wild as a zero-day.
Windows 10 End of Support
As of October 14, Windows 10 has reached its end of support. This means that no new security updates will be released for Windows 10 without being enrolled in the Extended Security Updates (ESU) program. To identify unsupported versions of Windows 10, customers can use plugin ID 192814 .
Additionally, Long-Term Servicing Branch (LTSB) support for Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise LTSB 2015 also ended as of October 14. Plugins to identify these versions are as follows:
Additional Microsoft Products End of Support
As of October 14, several Microsoft Products have reached end of support or extended support. Since these products will no longer receive security updates, we recommend upgrading to supported versions as soon as possible.
Skype for Business Server 2015
Skype for Business 2016
Skype for Business Server 2019
Windows 11 Enterprise and Education Version 22H2
Windows 11 IoT Enterprise Version 22H2
A list of all the plugins released for Microsoft’s October 2025 Patch Tuesday update can be found here . As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.
For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable .
Update October 24: The blog has been updated to add additional details for CVE-2025-59287 which has reportedly now been exploited in the wild and has public exploit code available. In addition, an out-of-band update has been released by Microsoft for a more comprehensive fix.
Microsoft's October 2025 Security Updates
Tenable plugins for Microsoft October 2025 Patch Tuesday Security Updates
Join Tenable's Research Special Operations (RSO) Team on Tenable Connect and engage with us in the Threat Roundtable group for further discussions on the latest cyber threats.
The world’s leading AI-powered exposure management platform.
Thank you for your interest in Tenable One. A representative will be in touch soon.
Tenable One Cloud Exposure
Close cloud exposure with the actionable cloud security platform.
Thank you for your interest in Tenable One Cloud Exposure. A representative will be in touch soon.
Tenable Security Center
Identify and prioritize vulnerabilities based on risk to your business. Managed on premises.
Thank you for your interest in Tenable Security Center. A representative will be in touch soon.
Tenable Patch Management
Streamline security and IT collaboration and shorten the mean time to remediate with automation.
Thank you for your interest in Tenable Patch Management. A representative will be in touch soon.
Tenable Enclave Security
Identify, understand and close IT and container vulnerabilities.
Thank you for your interest in Tenable Enclave Security. A representative will be in touch soon.
Tenable One Attack Surface Management
Gain visibility into your internet-connected assets to eliminate blind spots and unknown sources of risk.
Thank you for your interest in Tenable One Attack Surface Management. A representative will be in touch soon.
Tenable One AI Exposure
See, secure, and manage how your teams use AI tools.
Thank you for your interest in Tenable One AI Exposure. A representative will be in touch soon.
Tenable One OT Exposure
Close OT exposure with the unified security solution for converged OT/IT environments.
Thank you for your interest in Tenable One OT Exposure. A representative will be in touch soon.
See Tenable in action
Want to see how Tenable can help your team find and fix critical cyber weaknesses that put your business at risk? Complete this form to get a custom quote or demo.
You should receive a confirmation email shortly and one of our representatives will be in touch.
Learn How Tenable Helps Achieve SLCGP Cybersecurity Plan Requirements
You should receive a confirmation email shortly and one of our Sales Development Representatives will be in touch. Route any questions to [email protected] .
Tenable One Vulnerability Management
Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.
Your Tenable One Vulnerability Management trial also includes Tenable One Web App Scanning.
Tenable One Vulnerability Management
Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.
Please us or a Tenable partner.
Thank you for your interest in Tenable One Vulnerability Management. A representative will be in touch soon.
Try Tenable One Web App Scanning
Your Tenable One Web App Scanning trial also includes Tenable One Vulnerability Management.
Buy Tenable One Web App Scanning
Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.
Please us or a Tenable partner.
Thank you for your interest in Tenable Web App Scanning. A representative will be in touch soon.
Try Tenable Nessus Professional free
Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Fill out the form below to continue with a Nessus Pro trial.
Buy Tenable Nessus Professional
Buy a multi-year license and save. Add Advanced Support for access to phone, community, and chat support 24 hours a day, 365 days a year.
Try Tenable Nessus Expert free
Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.
Already have Tenable Nessus Professional? Upgrade to Nessus Expert free for 7 days.
With Advanced Support for Nessus Pro, your teams will have access to phone, Community, and chat support 24 hours a day, 365 days a year. This advanced level of technical support helps to ensure faster response times and resolution to your questions and issues.
Advanced Support Plan Features
Phone support 24 hours a day, 365 days a year, available for up to ten (10) named support contacts.
Chat support available to named support contacts, accessible via the Tenable Community is available 24 hours a day, 365 days a year.
Tenable Community Support Portal
All named support contacts can open support cases within the Tenable Community. Users can also access the Knowledge Base, documentation, license information, technical support numbers, etc.; utilize live chat, ask questions to the Community, and learn tips and tricks from other Community members.
Initial Response Time
P1-Critical: < 2 hr P2-High: < 4 hr P3-Medium: < 12 hr P4-Informational: < 24 hr
Support contacts must be reasonably proficient in the use of information technology, the software they have purchased from Tenable, and familiar with the customer resources that are monitored by means of the software. Support contacts must speak English and conduct support requests in English. Support contacts must provide information reasonably requested by Tenable for the purpose of reproducing any Error or otherwise resolving a support request.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
