{"id":3279,"date":"2025-10-18T16:52:23","date_gmt":"2025-10-18T16:52:23","guid":{"rendered":"http:\/\/ft365.org\/index.php\/2025\/10\/18\/last-windows-10-patch-tuesday-features-six-zero-days\/"},"modified":"2025-10-18T16:52:23","modified_gmt":"2025-10-18T16:52:23","slug":"last-windows-10-patch-tuesday-features-six-zero-days","status":"publish","type":"post","link":"https:\/\/ft365.org\/index.php\/2025\/10\/18\/last-windows-10-patch-tuesday-features-six-zero-days\/","title":{"rendered":"Last Windows 10 Patch Tuesday Features Six Zero-Days"},"content":{"rendered":"<div>\n<p><img decoding=\"async\" src=\"http:\/\/ft365.org\/wp-content\/uploads\/2025\/06\/localimages\/ea721ff9-8ba4-4d88-b386-57e9e1606077.jpg?width=64&#038;height=64&#038;mode=crop&#038;scale=both&#038;format=webp\" alt=\"Photo of Phil Muncaster\" loading=\"lazy\"><\/p>\n<\/div>\n<div id=\"cphContent_pnlArticleBody\">\n<div id=\"layout-cecd7af3-2e11-4609-92b1-bc601e2c11ca\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>It\u2019s set to be a busy October for system administrators after Microsoft issued security updates to fix 172 vulnerabilities including six classed as zero-days.<\/p>\n<p>Three of the zero-day vulnerabilities in this month\u2019s Patch Tuesday list are being actively exploited.<\/p>\n<p>CVE-2025-59230 is a local elevation of privilege (EoP) bug in the Windows Remote Access Connection Manager.<\/p>\n<p>\u201cWith no user interaction required, this will go straight into an attacker\u2019s standard toolkit,\u201d warned Rapid7 lead software engineer, Adam Barnett.<\/p>\n<p>\u201cThere\u2019s very little information in the advisory itself, but someone out there knows exactly how to exploit this vulnerability.\u201d<\/p>\n<p>CVE-2025-24990 is another EoP vulnerability, this time in the third-party Agere Modem driver (ltmdm64.sys) which ships with Windows. Interestingly, Microsoft has removed the driver rather than patch the flaw.<\/p>\n<p>Ben McCarthy, lead cybersecurity engineer at Immersive, argued that the bug highlights the risks of legacy components.<\/p>\n<p>\u201cThis driver, which supports hardware from the late 1990s and early 2000s, predates current secure development practices and has remained largely unchanged for years. Kernel-mode drivers operate with the highest system privileges, making them a primary target for attackers seeking to escalate their access,\u201d he explained.\u00a0<\/p>\n<p>\u201cMicrosoft\u2019s decision to remove the driver entirely, rather than issue a patch, is a direct response to the risks associated with modifying unsupported, third-party legacy code. Attempts to patch such a component can be unreliable, potentially introducing system instability or failing to address the root cause of the vulnerability completely.\u201d<\/p>\n<p><em>Read more on Patch Tuesday: Two Zero-Days Among Patch Tuesday CVEs This Month<\/em><\/p>\n<p>The third zero-day actively being exploited in the wild is CVE-2025-47827: a secure boot bypass bug that affects IGEL OS, a third-party OS designed to provide virtual desktop infrastructure.<\/p>\n<p>Kev Breen, senior director of threat research at Immersive, claimed a proof of concept has been available for this vulnerability since May, making exploitation trivial.<\/p>\n<p>\u201cThe impacts of a secure boot bypass can be significant, as threat actors can deploy a kernel-level rootkit, gaining access to the IGEL OS itself and, by extension then tamper with the virtual desktops, including capturing credentials,\u201d he added.<\/p>\n<p>\u201cIt should be noted that this is not a remote attack, and physical access is typically required to exploit this type of vulnerability, meaning that \u2018evil-maid\u2019 style attacks are the most likely vector affecting employees who travel frequently.\u201d<\/p>\n<h2>Three Publicly Disclosed Zero-Days<\/h2>\n<p>The three remaining zero-days have been publicly disclosed but so far not exploited. They are:<\/p>\n<ul>\n<li>CVE-2025-0033: a critical vulnerability in AMD EPYC processors using Secure Encrypted Virtualization \u2013 Secure Nested Paging (SEV-SNP), for which there\u2019s not yet a patch<\/li>\n<li>CVE-2025-24052: an EoP bug in Agere Modem driver similar to CVE-2025-24990<\/li>\n<li>CVE-2025-2884: an out-of-bounds read vulnerability in TCG TPM2.0\u00a0that could result in information disclosure or denial of service\u00a0<\/li>\n<\/ul>\n<p>This is the last Patch Tuesday\u00a0in which Windows 10 users will receive free updates. To continue receiving patches, consumers and business customers will need to pay for Microsoft\u2019s\u00a0Extended Security Updates (ESU) scheme.<\/p>\n<\/p><\/div>\n<p>Image\u00a0credit: gguy \/ Shutterstock.com<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s set to be a busy October for system administrators after Microsoft issued security updates to fix 172 vulnerabilities including six classed as zero-days. Three of the zero-day vulnerabilities in this month\u2019s Patch Tuesday list are being actively exploited. CVE-2025-59230 is a local elevation of privilege (EoP) bug in the Windows Remote Access Connection Manager.<\/p>\n","protected":false},"author":2,"featured_media":3280,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3279","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["https:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3279-8a775030-958d-416a-850b-312e5d990560.jpg",300,300,false],"thumbnail":["https:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3279-8a775030-958d-416a-850b-312e5d990560-150x150.jpg",150,150,true],"medium":["https:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3279-8a775030-958d-416a-850b-312e5d990560.jpg",300,300,false],"medium_large":["https:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3279-8a775030-958d-416a-850b-312e5d990560.jpg",300,300,false],"large":["https:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3279-8a775030-958d-416a-850b-312e5d990560.jpg",300,300,false],"1536x1536":["https:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3279-8a775030-958d-416a-850b-312e5d990560.jpg",300,300,false],"2048x2048":["https:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3279-8a775030-958d-416a-850b-312e5d990560.jpg",300,300,false],"morenews-featured":["https:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3279-8a775030-958d-416a-850b-312e5d990560.jpg",300,300,false],"morenews-large":["https:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3279-8a775030-958d-416a-850b-312e5d990560.jpg",300,300,false],"morenews-medium":["https:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3279-8a775030-958d-416a-850b-312e5d990560.jpg",300,300,false],"crawlomatic_preview_image":["https:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3279-8a775030-958d-416a-850b-312e5d990560-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"https:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"https:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/3279","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=3279"}],"version-history":[{"count":0,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/3279\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/3280"}],"wp:attachment":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=3279"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=3279"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=3279"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}