ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Microsoft patches three zero-days actively exploited by attackers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24052
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems.

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific driver will no longer work on Windows. Microsoft recommends removing any existing dependencies on this hardware.

NVD description · AI analysis pending
7.82%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2025-59287
+2 in the same advisory: …24990 …59230
Deserialization RCE in Microsoft WSUS (Windows Server)

CVE-2025-59287 is a deserialization of untrusted data flaw (CWE-502) in the Microsoft Windows Server Update Service (WSUS) that permits remote code execution. It is triggered when the WSUS service processes attacker-controlled serialized input, allowing an attacker to run arbitrary code on the server hosting the WSUS role. Organizations running WSUS are affected — typically enterprises that use the role for internal Windows update management — and CISA lists the affected scope as Microsoft Windows broadly. The issue is confirmed exploited in the wild: it was added to the CISA KEV catalog on 2025-10-24, and the EPSS model assigns a 100% (100th percentile) probability of exploitation within 30 days, though no public proof-of-concept is known. CVSS scoring is not yet available, so defenders should treat it as a high-priority remote code execution issue until more detail is published.

Do: Apply Microsoft's latest WSUS security updates on every Windows Server with the WSUS role enabled and verify patch status through your update and configuration-management tooling. Where the WSUS role is not required, disable or remove it, and restrict inbound network access to WSUS service ports (typically TCP 8530/8531) from untrusted networks. Federal agencies must apply the required mitigations per CISA BOD 22-01 given the KEV listing.

9.8
group max
100% KEV PoC
  • Microsoft Windows (systems with the WSUS / Windows Server Update Service role enabled)
largetens of thousands of internet-exposed WSUS servers, within a global deployment base plausibly exceeding 100,000
CVE-2025-47827
Secure Boot Bypass via Expired Key in IGEL OS Before 11 (CVE-2025-47827)

CVE-2025-47827 is a Secure Boot bypass in IGEL OS before version 11, caused by improper verification of a cryptographic signature (CWE-347) in the igel-flash-driver module, which improperly validates a signature using a key past its expiration date. An attacker with physical access (CVSS vector AV:P) can boot a crafted root filesystem from an unverified SquashFS image, defeating the platform's Secure Boot guarantee and loading attacker-controlled code at boot time; the CVSS scoring assigns high availability impact. Deployments running IGEL OS 10 or earlier are affected; CISA's affected-product list names IGEL OS only, while the CPE data additionally tags Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (22H2-25H2) and Windows Server 2012/2016 releases, reflecting the shared Microsoft Secure Boot key ecosystem rather than a CISA-listed Microsoft impact. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-10-14, indicating confirmed in-the-wild exploitation, with ransomware use unknown and EPSS estimating a 4.9% (92nd percentile) probability of exploitation within 30 days. A public proof-of-concept is available (github.com/Zedeldi/CVE-2025-47827), and vendors/CISA have required mitigation per BOD 22-01 guidance.

Do: Inventory all IGEL endpoints and upgrade any running OS 10 or earlier to IGEL OS 11 (current 11.x) per vendor instructions, which is the required KEV/BOD 22-01 remediation path. Because the attack requires physical access (AV:P), restrict physical and console access to thin clients in exposed locations such as lobbies, clinical areas and production floors, and inspect any device that may have been accessed for signs of root-filesystem tampering or unexpected boot behavior. The public PoC (Zedeldi/CVE-2025-47827) can be used to verify whether devices still boot an unverified SquashFS image.

4.65% KEV PoC
  • IGEL OS all versions before 11 (i.e., OS 10 and earlier) - listed as affected by CISA
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2 (tagged in CPE; CISA's affected list names only IGEL OS)
  • microsoft Windows 11 22H2, 23H2, 24H2, 25H2 (tagged in CPE; CISA's affected list names only IGEL OS)
  • +1 more
largeon the order of 100,000-1,000,000 IGEL endpoints (residual pre-v11 share of IGEL's multi-million-device installed base) - estimate
CVE-2025-55315
HTTP Request Smuggling in Microsoft ASP.NET Core Enables Security Feature Bypass

CVE-2025-55315 is an HTTP request/response smuggling vulnerability (CWE-444) in Microsoft ASP.NET Core, in which inconsistent interpretation of HTTP requests between the application and other HTTP-processing components can desynchronize request handling. An authorized (low-privileged) network attacker triggers it by sending crafted HTTP requests, and gains the ability to bypass a security feature; the scope-changed CVSS 9.9 score (C:H/I:H/A:L) indicates the bypass can affect resources beyond the vulnerable component with high confidentiality and integrity impact. All applications built on affected ASP.NET Core versions are in scope, Visual Studio 2022 is listed as an affected product, and related news coverage flags QNAP NetBak PC Agent as an impacted downstream product. No public proof-of-concept or CISA KEV listing exists, so exploitation is not confirmed in the wild, but the 65.8% EPSS (99th percentile) signals a high predicted likelihood of exploitation within 30 days. Microsoft addressed the flaw as part of its recent Patch Tuesday release covering 175 vulnerabilities.

Do: Apply Microsoft's latest security updates for ASP.NET Core (runtime/SDK components) and Visual Studio 2022 immediately; exact patched version numbers are listed in Microsoft's advisory. QNAP NetBak PC Agent users should install the updated build referenced in QNAP's advisory. Given the 65.8% EPSS, prioritize internet-facing ASP.NET Core applications—especially those behind reverse proxies or load balancers where smuggling bypasses front-end security controls—and monitor for a public PoC or KEV listing.

9.966%
  • Microsoft ASP.NET Core
  • Microsoft Visual Studio 2022
mass≈ millions of installations (ASP.NET Core's default role in .NET web applications plus Visual Studio 2022's multi-million install base)
CVE-2025-59234
+1 in the same advisory: …59227
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft 365 apps
  • microsoft 365 copilot
  • microsoft office
  • +1 more
Full article935 words · extracted from helpnetsecurity.com · click to collapse

On October 2025 Patch Tuesday, Microsoft released fixes for 175+ vulnerabilities, including three zero-days under active attack: CVE-2025-24990, CVE-2025-59230, and CVE-2025-47827.

Microsoft Patch Tuesday zero-days

The actively exploited vulnerabilities are an unusual mix

CVE-2025-24990 is in the third-party driver (ltmdm64.sys) for the software-based Agere Modem, which is used for dial-up internet access and sending/receiving faxes.

The vulnerable driver was, until now, shipped natively with Windows and the vulnerability, which allows attackers to gain administrator privileges, has been exploited by attackers in the wild.

How widespread these attacks are is unknown, but Fabian Mosch, one of the researchers credited with flagging the flaw, posited that it might have been exploited for EDR evasion.

“Considering the vulnerable files are on all Windows systems, you should treat this as a broad attack and update quickly,” Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, advised.

Microsoft has removed the driver in the October cumulative update and advised all users to update, since the vulnerability can be exploited even if the modem is not in use. But, the company warned, the fax modem hardware dependent on the specific driver will no longer work on updated systems.

(CVE-2025-24052, another elevation of privilege vulnerability in this same driver has also been “fixed” by the driver’s removal. This one is not exploited in the wild, but was previously publicly disclosed.)

CVE-2025-59230 is an elevation of privilege vulnerability that affects the Windows Remote Access Connection Manager (aka RasMan), a service that manages dial-up and VPN connections.

“While RasMan is a frequent flyer on Patch Tuesday, appearing more than 20 times since January 2022, this is the first time we’ve seen it exploited in the wild as a zero day,” noted Satnam Narang, senior staff research engineer at Tenable.

The vulnerability affects all supported versions of Windows and Windows Server, and allows attackers to elevate their privileges to SYSTEM (i.e., to completely “own” the machine).

The flaw was reported by Microsoft’s threat intelligence analysts and its security response center, but no details have been shared about the breadth of the attacks in which it is being used. Still, all actively exploited flaws should be remediated as quickly as possible.

CVE-2025-47827 affects the Linux-based IGEL OS (before version 11) and allows attackers to bypass the Secure Boot process.

IGEL OS is most commonly used to repurpose Windows PCs as secure, centrally managed thin clients for virtual desktops, kiosks, and other single-purpose devices. Such devices are often used in healthcare, education, retail, and industrial settings.

“The impacts of a Secure Boot bypass can be significant, as threat actors can deploy a kernel-level rootkit, gaining access to the IGEL OS itself and, by extension then tamper with the Virtual Desktops, including capturing credentials,” Kev Breen, senior director of threat research at Immersive, pointed out.

“It should be noted that this is not a remote attack, and physical access is typically required to exploit this type of vulnerability, meaning that ‘evil-maid’ style attacks are the most likely vector affecting employees who travel frequently.”

Other vulnerabilities requiring quick action

For those how use Windows Server Update Service (WSUS), Childs advises patching CVE-2025-59287, which allows remote, unauthenticated attackers to exploit code with elevated privileges without user interaction.

“That means this is wormable between affected WSUS servers. Since WSUS remains a critical piece of anyone’s infrastructure, it’s an attractive target for those looking to do harm,” he explained.

Breen also noted that with WSUS being a trusted Windows service, attackers could potentially bypass some EDR detections that ignore or exclude it.

Narang says that Microsoft Office users should also take note of CVE-2025-59227 and CVE-2025-59234, a pair of remote code execution bugs that take advantage of “Preview Pane”, as the target doesn’t even need to open the malicious file for exploitation to occur.

Finally, CVE-2025-55315 is a critical Security Feature Bypass vulnerability in ASP.NET Core that despite being only exploitable by authenticated attackers, may allow them to view sensitive information (e.g., user’s credentials), make changes to file contents on the target server, or force a crash within the server.

While Microsoft deems the vulnerability less likely to be exploited, Ben McCarthy, lead cyber security engineer at Immersive, notes that security bypasses don’t typically get a 9.9 CVSS score.

“While it might be a security bypass, attackers can exploit this vulnerability with such ease and the fact that it is probably in a lot of external-facing applications using ASP.NET, justify its rating,” he noted.

“It is recommended that organizations try to patch this by upgrading their ASP.NET version when they can, first test their code base works in the newer version of ASP.NET then ensure they upgrade.”

Windows 10 reaches end-of-support

As a reminder: this month, Microsoft is ending support for Windows 10, but also for Office 2016 and 2019, and Exchange Server 2016 and 2019.

Office users can switch to Office 2024, Microsoft 365 (cloud-based software-as-a-service for which you need a subscription), or a non-Microsoft alternative (e.g. LibreOffice, WPS Office, etc.)

Exchange users can migrate to Microsoft’s cloud-based Exchange or, if they want to retain control over their data, upgrade to Exchange Server Subscription Edition. Or they can move off Exchange entirely, to an alternative mail platform.

Windows 10 users and enterprises can can sign up for the Extended Security Updates (ESU) program (European users have more favorable conditions), upgrade to Windows 11, or remain on Windows 10 and opt for micropatching. And, of course, switching to another OS is also an option.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/10/15/microsoft-patch-tuesday-zero-days-cve-2025-24990-cve-2025-59230-cve-2025-47827/