ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Microsoft’s Patch Tuesday fixes 175 vulnerabilities, including two actively exploited zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-59287
+2 in the same advisory: …24990 …59230
Deserialization RCE in Microsoft WSUS (Windows Server)

CVE-2025-59287 is a deserialization of untrusted data flaw (CWE-502) in the Microsoft Windows Server Update Service (WSUS) that permits remote code execution. It is triggered when the WSUS service processes attacker-controlled serialized input, allowing an attacker to run arbitrary code on the server hosting the WSUS role. Organizations running WSUS are affected — typically enterprises that use the role for internal Windows update management — and CISA lists the affected scope as Microsoft Windows broadly. The issue is confirmed exploited in the wild: it was added to the CISA KEV catalog on 2025-10-24, and the EPSS model assigns a 100% (100th percentile) probability of exploitation within 30 days, though no public proof-of-concept is known. CVSS scoring is not yet available, so defenders should treat it as a high-priority remote code execution issue until more detail is published.

Do: Apply Microsoft's latest WSUS security updates on every Windows Server with the WSUS role enabled and verify patch status through your update and configuration-management tooling. Where the WSUS role is not required, disable or remove it, and restrict inbound network access to WSUS service ports (typically TCP 8530/8531) from untrusted networks. Federal agencies must apply the required mitigations per CISA BOD 22-01 given the KEV listing.

9.8
group max
100% KEV PoC
  • Microsoft Windows (systems with the WSUS / Windows Server Update Service role enabled)
largetens of thousands of internet-exposed WSUS servers, within a global deployment base plausibly exceeding 100,000
CVE-2025-49708
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.

NVD description · AI analysis pending
9.91%
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • +1 more
CVE-2025-55315
HTTP Request Smuggling in Microsoft ASP.NET Core Enables Security Feature Bypass

CVE-2025-55315 is an HTTP request/response smuggling vulnerability (CWE-444) in Microsoft ASP.NET Core, in which inconsistent interpretation of HTTP requests between the application and other HTTP-processing components can desynchronize request handling. An authorized (low-privileged) network attacker triggers it by sending crafted HTTP requests, and gains the ability to bypass a security feature; the scope-changed CVSS 9.9 score (C:H/I:H/A:L) indicates the bypass can affect resources beyond the vulnerable component with high confidentiality and integrity impact. All applications built on affected ASP.NET Core versions are in scope, Visual Studio 2022 is listed as an affected product, and related news coverage flags QNAP NetBak PC Agent as an impacted downstream product. No public proof-of-concept or CISA KEV listing exists, so exploitation is not confirmed in the wild, but the 65.8% EPSS (99th percentile) signals a high predicted likelihood of exploitation within 30 days. Microsoft addressed the flaw as part of its recent Patch Tuesday release covering 175 vulnerabilities.

Do: Apply Microsoft's latest security updates for ASP.NET Core (runtime/SDK components) and Visual Studio 2022 immediately; exact patched version numbers are listed in Microsoft's advisory. QNAP NetBak PC Agent users should install the updated build referenced in QNAP's advisory. Given the 65.8% EPSS, prioritize internet-facing ASP.NET Core applications—especially those behind reverse proxies or load balancers where smuggling bypasses front-end security controls—and monitor for a public PoC or KEV listing.

9.966%
  • Microsoft ASP.NET Core
  • Microsoft Visual Studio 2022
mass≈ millions of installations (ASP.NET Core's default role in .NET web applications plus Visual Studio 2022's multi-million install base)
CVE-2025-59246
Azure Entra ID Elevation of Privilege Vulnerability

Azure Entra ID Elevation of Privilege Vulnerability

NVD description · AI analysis pending
9.88%
  • microsoft entra id
Full article584 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The tech giant addressed a record-high number of defects for the year in its latest update.

Listen to this article

0:00

Learn more.

Microsoft
(Jeenah Moon/Getty Images)

Microsoft addressed 175 vulnerabilities affecting its core products and underlying systems, including two actively exploited zero-days, the company said in its latest security update. It’s the largest assortment of defects disclosed by the tech giant this year.

The zero-day vulnerabilities — CVE-2025-24990 affecting Agere Windows Modem Driver and CVE-2025-59230 affecting Windows Remote Access Connection Manager — both have a CVSS rating of 7.8. The Cybersecurity and Infrastructure Security Agency added both zero-days to its known exploited vulnerabilities catalog Tuesday.

Microsoft said the third-party Agere Modem drive that ships with supported Windows operating systems has been removed in the October security update. Fax modem hardware that relies on the driver will no longer work on Windows, the company said.

Attackers can achieve administrator privileges by exploiting CVE-2025-24990. “All supported versions of Windows can be affected by a successful exploitation of this vulnerability, even if the modem is not actively being used,” Microsoft said in its summary of the defect.

The improper access control vulnerability affecting Windows Remote Access Connection manager can be exploited by an authorized attacker to elevate privileges locally and gain system privileges, Microsoft said. 

Windows Remote Access Connection Manager, a service used to manage remote network connections through virtual private networks and dial-up networks, is a “frequent flyer on Patch Tuesday, appearing more than 20 times since January 2022,” Satnam Narang, senior staff research engineer at Tenable, said in an email. “This is the first time we’ve seen it exploited in the wild as a zero day.”

The most severe vulnerabilities disclosed this month include CVE-2025-55315 affecting ASP.NET core and CVE-2025-49708 affecting Microsoft Graphics Component. Microsoft said exploitation of the defects is less likely, but both have a CVSS rating of 9.9.

Microsoft flagged 14 defects as more likely to be exploited this month, including a pair of critical vulnerabilities with CVSS ratings of 9.8 — CVE-2025-59246 affecting Azure Entra ID and CVE-2025-59287 affecting Windows Server Update Service.

The vendor disclosed five critical and 121 high-severity vulnerabilities this month. The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-october-2025/