Security Boulevard
Follow
Microsoft’s October 2025 Patch Tuesday Addresses 167 CVEs (CVE-2025-24990, CVE-2025-59230)
Microsoft's October 2025 Patch Tuesday is the largest update to date, addressing 167 CVEs. This includes three zero-day vulnerabilities, with two actively exploited in the wild. The update targets an array of Microsoft products, including Windows, Office, and Exchange Server. Elevation of Privilege vulnerabilities are the most prevalent, followed by Remote Code Execution flaws. Key vulnerabilities include EoP exploits in the Agere Modem driver and the Windows Remote Access Connection Manager. A critical RCE vulnerability exists in Windows Server Update Service, with a high exploitability rating. Microsoft Office also sees RCE vulnerabilities, though assessed as less likely to be exploited. The Windows Cloud Files Mini Filter Driver has an important EoP vulnerability. October 14 marked the end of support for Windows 10 and several other Microsoft products. Users should patch systems promptly and regularly scan for vulnerabilities.