Skip to content
Microsofts October 2025 Patch Tuesday Addresses 167 Cves Cve 2025 24990 Cve 2025 59230

Microsofts October 2025 Patch Tuesday Addresses 167 Cves Cve 2025 24990 Cve 2025 59230

www.tenable.com September 23, 2026

Microsoft addresses 167 CVEs in its largest Patch Tuesday to date, including three zero-day vulnerabilities, two of which were exploited in the wild.

Update October 24: The blog has been updated to add additional details for CVE-2025-59287 which has reportedly now been exploited in the wild and has public exploit code available. In addition, an out-of-band update has been released by Microsoft for a more comprehensive fix.

Microsoft patched 167 CVEs in its October 2025 Patch Tuesday release, its largest Patch Tuesday release to date, with seven rated critical, 158 rated important, and two rated moderate. Our counts omitted 27 vulnerabilities, including 14 Chromium CVEs, three MITRE CVEs, one GitHub CVE, one CERT/CC CVE, and eight cloud CVEs that Microsoft published advisories for on October 9.

This month’s update includes patches for:

.NET,.NET Framework, Visual Studio

Active Directory Federation Services

Agere Windows Modem Driver

Azure Connected Machine Agent

Confidential Azure Container Instances

Connected Devices Platform Service (Cdpsvc)

Data Sharing Service Client

JDBC Driver for SQL Server

Microsoft Brokering File System

Microsoft Configuration Manager

Microsoft Defender for Linux

Microsoft Exchange Server

Microsoft Failover Cluster Virtual Driver

Microsoft Graphics Component

Microsoft Office Excel

Microsoft Office PowerPoint

Microsoft Office SharePoint

Microsoft Office Visio

Microsoft Office Word

Microsoft Windows Component

Microsoft Windows Speech

Network Connection Status Indicator (NCSI)

NtQueryInformation Token function (ntifs.h)

Remote Desktop Client

Software Protection Platform (SPP)

Windows Ancillary Function Driver for WinSock

Windows Authentication Methods

Windows Bluetooth Service

Windows Cloud Files Mini Filter Driver

Windows Connected Devices Platform Service

Windows Cryptographic Services

Windows Device Association Broker service

Windows Digital Media

Windows DWM Core Library

Windows Error Reporting

Windows Failover Cluster

Windows File Explorer

Windows Health and Optimized Experiences Service

Windows High Availability Services

Windows Local Session Manager (LSM)

Windows Management Services

Windows PrintWorkflowUserSvc

Windows Push Notification Core

Windows Remote Access Connection Manager

Windows Remote Desktop

Windows Remote Desktop Protocol

Windows Remote Desktop Services

Windows Remote Procedure Call

Windows Resilient File System (ReFS)

Windows Resilient File System (ReFS) Deduplication Service

Windows Routing and Remote Access Service (RRAS)

Windows Server Update Service

Windows StateRepository API

Windows Storage Management Provider

Windows USB Video Driver

Windows Virtualization-Based Security (VBS) Enclave

Windows WLAN Auto Config Service

Elevation of Privilege (EoP) vulnerabilities accounted for 47.9% of the vulnerabilities patched this month, followed by Remote Code Execution (RCE) vulnerabilities at 17.4%.

CVE-2025-24052 and CVE-2025-24990 | Windows Agere Modem Driver Elevation of Privilege Vulnerabilities

CVE-2025-24052 and CVE-2025-24990 are EoP vulnerabilities in the third party Agere Modem driver. Both CVEs were assigned CVSSv3 scores of 7.8 and rated as important. Microsoft reports that CVE-2025-24990 has been exploited in the wild and CVE-2025-24052 was disclosed prior to a patch being made available. Successful exploitation would allow an attacker to gain administrator privileges on an affected system.

The ltmdm64.sys driver has historically shipped natively with supported Windows operating systems, but will no longer be supported following the October update. Microsoft notes, that ltmdm64.sys-dependent hardware will no longer work on Windows, and recommends users remove existing dependencies.

CVE-2025-59230 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2025-59230 is an EoP vulnerability affecting Windows Remote Access Connection Manager. According to Microsoft, this vulnerability has been exploited in the wild. It was assigned a CVSSv3 score of 7.8 and is rated as important. Exploitation of this vulnerability involves improper access control in Windows Remote Access Connection Manager and could allow a local attacker to gain SYSTEM privileges.

Including CVE-2025-59230, there have been 22 reported and patched vulnerabilities for the Windows Remote Access Connection Manager service (RasMan) since January 2022. CVE-2025-59230 is the first reported RasMan CVE to be exploited as a zero-day.

CVE-2025-59287 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVE-2025-59287 is a RCE in the Windows Server Update Service (WSUS). It was assigned a CVSSv3 score of 9.8 and rated critical. It has been assessed as “Exploitation More Likely” according to Microsoft’s Exploitability Index . An attacker could exploit this vulnerability to gain RCE by sending a crafted event that leads to a deserialization of untrusted data.

This is just the third WSUS vulnerability patched as part of Microsoft Patch Tuesday since 2023, when Microsoft patched two WSUS EoP vulnerabilities (CVE-2023-32056, CVE-2023-35317) in the July 2023 Patch Tuesday , but the first RCE and to be assessed as more likely to be exploited.

On October 23, Microsoft update the security advisory for CVE-2025-59287 with an out-of-band update to "comprehensively address CVE-2025-59287." This update came after a public proof-of-concept was released for the vulnerability which could increase the likelihood of exploitation. While Microsoft's advisory was not updated to acknowledge active exploitation, the National Cyber Security Centre (NCSC) has reported that a trusted partner observed active exploitation on October 24.

Microsoft's advisory does provide some workarounds that can be implemented if immediate patching is not able to be performed. Despite the workarounds available, Microsoft notes that you should "install the updates for this vulnerability as soon as possible even if you plan to leave either of these workarounds in place."

CVE-2025-59227, CVE-2025-59234 | Microsoft Office Remote Code Execution Vulnerability

CVE-2025-59227 and CVE-2025-59234 are RCE vulnerabilities in Microsoft Office. Both vulnerabilities were assigned a CVSSv3 score of 7.8, rated critical and assessed as “Exploitation Less Likely.” An attacker could exploit these flaws through social engineering by sending the malicious Microsoft Office document file to an intended target. Successful exploitation would grant code execution privileges to the attacker.

Despite being flagged as “Less Likely” to be exploited, Microsoft notes that the Preview Pane is an attack vector for both CVEs, which means exploitation does not require the target to open the file.

CVE-2025-55680 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2025-55680 is an EoP vulnerability in the Windows Cloud Files Mini Filter Driver. It was assigned a CVSSv3 score of 7.8, rated important and assessed as “Exploitation More Likely.” A local, authenticated attacker would need to win a race condition in order to exploit this vulnerability. Successful exploitation would allow the attacker to elevate to SYSTEM privileges.

This is the 17th vulnerability in the Windows Cloud Files Mini Filter Driver since 2022. Microsoft patched two in 2022, six in 2023, six in 2024, and three in 2025. As part of its November 2023 Patch Tuesday release , Microsoft patched CVE-2023-36036, another EoP flaw, that was exploited in the wild as a zero-day.

Windows 10 End of Support

As of October 14, Windows 10 has reached its end of support. This means that no new security updates will be released for Windows 10 without being enrolled in the Extended Security Updates (ESU) program. To identify unsupported versions of Windows 10, customers can use plugin ID 192814 .

Additionally, Long-Term Servicing Branch (LTSB) support for Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise LTSB 2015 also ended as of October 14. Plugins to identify these versions are as follows:

Additional Microsoft Products End of Support

As of October 14, several Microsoft Products have reached end of support or extended support. Since these products will no longer receive security updates, we recommend upgrading to supported versions as soon as possible.

Skype for Business Server 2015

Skype for Business 2016

Skype for Business Server 2019

Windows 11 Enterprise and Education Version 22H2

Windows 11 IoT Enterprise Version 22H2

A list of all the plugins released for Microsoft’s October 2025 Patch Tuesday update can be found here . As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.

For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable .

Update October 24: The blog has been updated to add additional details for CVE-2025-59287 which has reportedly now been exploited in the wild and has public exploit code available. In addition, an out-of-band update has been released by Microsoft for a more comprehensive fix.

Microsoft's October 2025 Security Updates

Tenable plugins for Microsoft October 2025 Patch Tuesday Security Updates

Join Tenable's Research Special Operations (RSO) Team on Tenable Connect and engage with us in the Threat Roundtable group for further discussions on the latest cyber threats.

The world’s leading AI-powered exposure management platform.

Thank you for your interest in Tenable One. A representative will be in touch soon.

Tenable One Cloud Exposure

Close cloud exposure with the actionable cloud security platform.

Thank you for your interest in Tenable One Cloud Exposure. A representative will be in touch soon.

Tenable Security Center

Identify and prioritize vulnerabilities based on risk to your business. Managed on premises.

Thank you for your interest in Tenable Security Center. A representative will be in touch soon.

Tenable Patch Management

Streamline security and IT collaboration and shorten the mean time to remediate with automation.

Thank you for your interest in Tenable Patch Management. A representative will be in touch soon.

Tenable Enclave Security

Identify, understand and close IT and container vulnerabilities.

Thank you for your interest in Tenable Enclave Security. A representative will be in touch soon.

Tenable One Attack Surface Management

Gain visibility into your internet-connected assets to eliminate blind spots and unknown sources of risk.

Thank you for your interest in Tenable One Attack Surface Management. A representative will be in touch soon.

Tenable One AI Exposure

See, secure, and manage how your teams use AI tools.

Thank you for your interest in Tenable One AI Exposure. A representative will be in touch soon.

Tenable One OT Exposure

Close OT exposure with the unified security solution for converged OT/IT environments.

Thank you for your interest in Tenable One OT Exposure. A representative will be in touch soon.

See Tenable in action

Want to see how Tenable can help your team find and fix critical cyber weaknesses that put your business at risk? Complete this form to get a custom quote or demo.

You should receive a confirmation email shortly and one of our representatives will be in touch.

Learn How Tenable Helps Achieve SLCGP Cybersecurity Plan Requirements

You should receive a confirmation email shortly and one of our Sales Development Representatives will be in touch. Route any questions to [email protected] .

Tenable One Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable One Vulnerability Management trial also includes Tenable One Web App Scanning.

Tenable One Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

Please us or a Tenable partner.

Thank you for your interest in Tenable One Vulnerability Management. A representative will be in touch soon.

Try Tenable One Web App Scanning

Your Tenable One Web App Scanning trial also includes Tenable One Vulnerability Management.

Buy Tenable One Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

Please us or a Tenable partner.

Thank you for your interest in Tenable Web App Scanning. A representative will be in touch soon.

Try Tenable Nessus Professional free

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Fill out the form below to continue with a Nessus Pro trial.

Buy Tenable Nessus Professional

Buy a multi-year license and save. Add Advanced Support for access to phone, community, and chat support 24 hours a day, 365 days a year.

Try Tenable Nessus Expert free

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional? Upgrade to Nessus Expert free for 7 days.

With Advanced Support for Nessus Pro, your teams will have access to phone, Community, and chat support 24 hours a day, 365 days a year. This advanced level of technical support helps to ensure faster response times and resolution to your questions and issues.

Advanced Support Plan Features

Phone support 24 hours a day, 365 days a year, available for up to ten (10) named support contacts.

Chat support available to named support contacts, accessible via the Tenable Community is available 24 hours a day, 365 days a year.

Tenable Community Support Portal

All named support contacts can open support cases within the Tenable Community. Users can also access the Knowledge Base, documentation, license information, technical support numbers, etc.; utilize live chat, ask questions to the Community, and learn tips and tricks from other Community members.

Initial Response Time

P1-Critical: < 2 hr P2-High: < 4 hr P3-Medium: < 12 hr P4-Informational: < 24 hr

Support contacts must be reasonably proficient in the use of information technology, the software they have purchased from Tenable, and familiar with the customer resources that are monitored by means of the software. Support contacts must speak English and conduct support requests in English. Support contacts must provide information reasonably requested by Tenable for the purpose of reproducing any Error or otherwise resolving a support request.