Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Patches 173 Vulnerabilities, Including Exploited Windows Flaws

Microsoft Patches 173 Vulnerabilities, Including Exploited Windows Flaws

Posted on October 15, 2025October 15, 2025 By CWS

Microsoft on Tuesday introduced the discharge of patches for 173 distinctive CVEs in its merchandise, together with two flaws which have been exploited within the wild. Patches had been additionally launched for 21 non-Microsoft CVEs.

The primary exploited concern, tracked as CVE-2025-24990 (CVSS rating of seven.8), is described as an untrusted pointer dereference bug that may be exploited for privilege escalation.

The safety defect impacts the Agere Modem driver that ships with supported Home windows iterations and will enable attackers to acquire administrative privileges on a weak system.

Microsoft’s October 2025 cumulative replace for Home windows methods removes the weak ltmdm64.sys driver, which can be impacted by CVE-2025-24052, an elevation of privilege weak point for which a proof-of-concept (PoC) exploit exists.

The second exploited vulnerability, CVE-2025-59230 (CVSS rating of seven.8), is described as an improper entry management in Home windows Distant Entry Connection Supervisor that might enable attackers to raise their privileges.

“An attacker who efficiently exploited this vulnerability may acquire SYSTEM privileges,” Microsoft notes, with out sharing particulars on the noticed exploitation.

Of the 173 distinctive Microsoft CVEs within the October 2025 advisory, solely 5 are critical-severity bugs. The corporate warns that roughly a dozen of those flaws are more likely to be exploited in assaults.

Of the 21 non-Microsoft CVEs within the October advisory, no less than one has been exploited within the wild. Tracked as CVE-2025-47827 and impacting IGEL OS, it might result in a Safe Boot bypass.Commercial. Scroll to proceed studying.

The defect resides within the igel-flash-driver module’s improper verification of a cryptographic signature, permitting attackers to mount a crafted root filesystem from an unverified SquashFS picture.

The US cybersecurity company CISA on Tuesday added all three exploited vulnerabilities to its KEV listing, urging federal businesses to handle them inside three weeks, as mandated by the Binding Operational Directive (BOD) 22-01.

One other flaw patched this month and price mentioning is CVE-2025-2884, a medium-severity out-of-bounds learn concern within the Trusted Platform Module (TPM) 2.0 reference library specification maintained by the Trusted Computing Group (TCG).

Microsoft additionally included in its advisory CVE-2025-0033, known as RMPocalypse, a race situation that may be exploited to interrupt the confidential computing ensures of AMD processors, and CVE-2025-59489, a bug within the gaming and utility editor Unity that might result in code execution.

Associated: CISO Conversations: Are Microsoft’s Deputy CISOs a Signpost to the Future?

Associated: All Microsoft Entra Tenants Have been Uncovered to Silent Compromise through Invisible Actor Tokens: Researcher

Associated: Senator Urges FTC Probe of Microsoft Over Safety Failures

Associated: Microsoft Patches 86 Vulnerabilities

Security Week News Tags:Exploited, Flaws, Including, Microsoft, Patches, Vulnerabilities, Windows

Post navigation

Previous Post: Windows Remote Access Connection Manager 0-Day Vulnerability Exploited in Attacks
Next Post: Adobe Patches Critical Vulnerability in Connect Collaboration Suite

Related Posts

Australia’s TPG Telecom Investigating iiNet Hack Australia’s TPG Telecom Investigating iiNet Hack Security Week News
Meta AI’s Uncontrolled Cybersecurity Test Breach Meta AI’s Uncontrolled Cybersecurity Test Breach Security Week News
Grok-4 Falls to a Jailbreak Two days After Its Release Grok-4 Falls to a Jailbreak Two days After Its Release Security Week News
ZeroRISC Raises  Million for Open Source Silicon Security Solutions ZeroRISC Raises $10 Million for Open Source Silicon Security Solutions Security Week News
Sophisticated Koske Linux Malware Developed With AI Aid Sophisticated Koske Linux Malware Developed With AI Aid Security Week News
Horizon3.ai Raises 0 Million in Series D Funding Horizon3.ai Raises $100 Million in Series D Funding Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks
  • WhatsApp Introduces Scam Alert to Enhance Security
  • Enterprise Security Shows Strength at Edge, Weakness Within

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks
  • WhatsApp Introduces Scam Alert to Enhance Security
  • Enterprise Security Shows Strength at Edge, Weakness Within

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark