Microsoft’s Patch Tuesday fixes 175 vulnerabilities, including two actively exploited zero-days
ID: 1a160ab6-1f53-5ca8-938f-a7b3678ed423
STIX ID: report--1a160ab6-1f53-5ca8-938f-a7b3678ed423
Feed Name: CyberScoop
Microsoft’s October security update addresses 175 vulnerabilities across Windows and core products, including two actively exploited zero-days (CVE-2025-24990 in the Agere Windows Modem Driver and CVE-2025-59230 in Windows Remote Access Connection Manager). Several defects carry very high CVSS scores (up to 9.9 and multiple 9.8s), Microsoft removed the third-party Agere modem driver (impacting fax modem hardware), and CISA added the two zero-days to its known exploited vulnerabilities catalog; administrators should apply updates promptly to mitigate local privilege escalation and system compromise risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
