Last Windows 10 Patch Tuesday Fixes Six Zero Days

Microsoft Fixes Six Zero-Day Vulnerabilities in Latest Patch Tuesday

Microsoft has released security updates to fix 172 vulnerabilities, including six zero-day vulnerabilities, in the October Patch Tuesday.

Three of the zero-day vulnerabilities are being actively exploited, according to the company. One of the vulnerabilities, CVE-2025-59230, is a local elevation of privilege (EoP) bug in the Windows Remote Access Connection Manager.

“With no user interaction required, this will go straight into an attacker’s standard toolkit,” warned Rapid7 lead software engineer, Adam Barnett. “There’s very little information in the advisory itself, but someone out there knows exactly how to exploit this vulnerability.”

Another EoP vulnerability, CVE-2025-24990, affects the third-party Agere Modem driver (ltmdm64.sys) that ships with Windows.

Author's summary: Microsoft fixes six zero-day vulnerabilities.

more

Infosecurity Magazine Infosecurity Magazine — 2025-10-15

More News