ΑρχικήUpdatesMicrosoft Patch Tuesday Οκτωβρίου 2025: Διορθώθηκαν 172 ευπάθειες

Microsoft Patch Tuesday Οκτωβρίου 2025: Διορθώθηκαν 172 ευπάθειες

Η Microsoft κυκλοφόρησε τις ενημερώσεις Patch Tuesday Οκτωβρίου 2025, αντιμετωπίζοντας 172 ευπάθειες στο οικοσύστημά της, συμπεριλαμβανομένων τεσσάρων zero-day αδυναμιών (δύο από αυτές χρησιμοποιούνται ενεργά από hackers).

Microsoft Patch Tuesday Οκτωβρίου

Αυτό το μηνιαίο δελτίο ασφαλείας υπογραμμίζει τον αδιάκοπο ρυθμό εξέλιξης των απειλών, με κρίσιμα σφάλματα απομακρυσμένης εκτέλεσης κώδικα σε εφαρμογές Office και ζητήματα ανύψωσης προνομίων σε στοιχεία των Windows να κυριαρχούν στις διορθώσεις.

Καθώς οι οργανισμοί αντιμετωπίζουν προθεσμίες λήξης υποστήριξης για παλαιότερα συστήματα όπως τα Windows 10, η έγκαιρη εφαρμογή ενημερώσεων παραμένει απαραίτητη για την μείωση των κινδύνων από κρατικούς φορείς και κυβερνοεγκληματίες.

Δείτε επίσης: Η Oracle διορθώνει νέα ευπάθεια στο E-Business Suite

Οι ενημερώσεις στοχεύουν σε ένα ευρύ φάσμα προϊόντων, από βασικά λειτουργικά συστήματα Windows έως υπηρεσίες cloud Azure και τη σουίτα Microsoft Office.

ImpactCount
Κλιμάκωση προνομίων80
Απομακρυσμένη Εκτέλεση Κώδικα31
Αποκάλυψη πληροφοριών28
Παράκαμψη λειτουργιών ασφαλείας11
Denial of Service11
Spoofing10
Tampering1
Σύνολο172

Μερικές από τις πιο σημαντικές ευπάθειες, που διόρθωσε η Microsoft με το Patch Tuesday Οκτωβρίου, είναι οι CVE-2025-59234 και CVE-2025-59236, δύο αδυναμίες use-after-free στο Microsoft Office και Excel που επιτρέπουν απομακρυσμένη εκτέλεση κώδικα όταν οι χρήστες ανοίγουν κακόβουλα αρχεία. Αυτές οι αδυναμίες, που αξιολογούνται ως πολύ σοβαρές, με CVSS βαθμολογίες γύρω στο 7.8, δεν απαιτούν πιστοποίηση και θα μπορούσαν να επιτρέψουν στους επιτιθέμενους να αποκτήσουν πλήρη έλεγχο του συστήματος, οδηγώντας ενδεχομένως σε κλοπή δεδομένων ή ανάπτυξη ransomware.

Microsoft Patch Tuesday Οκτωβρίου 2025: Διορθώθηκαν 172 ευπάθειες

Παρομοίως, η CVE-2025-49708 στο Microsoft Graphics Component εκθέτει συστήματα σε ανύψωση προνομίων μέσω δικτύων.

Microsoft Patch Tuesday Οκτωβρίου: Διόρθωση κρίσιμων ευπαθειών

Αρκετές κρίσιμες ευπάθειες απαιτούν άμεση προσοχή λόγω του δυναμικού τους για ευρεία εκμετάλλευση. Για παράδειγμα, οι CVE-2025-59291 και CVE-2025-59292 αφορούν εξωτερικό έλεγχο file paths σε Azure Container Instances και Compute Gallery, επιτρέποντας σε εξουσιοδοτημένους επιτιθέμενους να αυξήσουν τα προνόμια τοπικά και ενδεχομένως να θέσουν σε κίνδυνο cloud workloads. Αυτά τα σφάλματα ανύψωσης προνομίων υπογραμμίζουν τους συνεχιζόμενους κινδύνους σε υβριδικά περιβάλλοντα, όπου οι εσφαλμένες ρυθμίσεις ενισχύουν τον αντίκτυπο.

Δείτε επίσης: Ευπάθεια στο Elastic Cloud Enterprise επιτρέπει εκτέλεση κακόβουλων εντολών

Μια άλλη ευπάθεια είναι η CVE-2016-9535, ένα LibTIFF heap buffer overflow που επαναδιευθετήθηκε σε αυτόν τον κύκλο ενημερώσεων. Θα μπορούσε να προκαλέσει απομακρυσμένη εκτέλεση κώδικα σε σενάρια επεξεργασίας εικόνας, επηρεάζοντας παλαιότερες εφαρμογές που εξακολουθούν να χρησιμοποιούνται.

Zero-day ευπάθειες διορθώθηκαν

Τα zero-days προσθέτουν καθιστούν την εφαρμογή της ενημέρωσης ακόμα πιο επείγουσα: το CVE-2025-2884, ένα σφάλμα out-of-bounds read στο TCG TPM2.0 reference implementation, προκύπτει από ανεπαρκή επικύρωση στα cryptographic signing functions και μπορεί να οδηγήσει σε αποκάλυψη πληροφοριών. Γνωστή δημόσια μέσω CERT/CC, επηρεάζει τα trusted platform modules που είναι αναπόσπαστα στις διαδικασίες ασφαλούς εκκίνησης.

Microsoft Patch Tuesday Οκτωβρίου 2025: Διορθώθηκαν 172 ευπάθειες

Εν τω μεταξύ, η CVE-2025-47827 επιτρέπει την παράκαμψη του Secure Boot σε εκδόσεις IGEL OS πριν από την 11, μέσω ακατάλληλης επαλήθευσης υπογραφής. Επιτρέπει την τοποθέτηση μη επαληθευμένων εικόνων ως φορέα για επίμονη κακόβουλη δραστηριότητα. Η CVE-2025-59230, μια άλλη zero-day ευπάθεια στο Windows Remote Access Connection Manager, περιλαμβάνει ακατάλληλους ελέγχους πρόσβασης για τοπική ανύψωση προνομίων.

Η Microsoft επιβεβαιώνει ότι δεν υπάρχουν δημόσιες εκμεταλλεύσεις για τις περισσότερες ευπάθειες, αλλά η ενεργή κατάχρηση μερικών από αυτές απαιτεί γρήγορη εφαρμογή του Patch Tuesday.

Τα ζητήματα Deserialization στο Windows Server Update Service (CVE-2025-59287) αυξάνουν περαιτέρω τις ανησυχίες, επιτρέποντας μη πιστοποιημένη απομακρυσμένη εκτέλεση κώδικα μέσω δικτύων (ένας κύριος στόχος για επιθέσεις στην αλυσίδα εφοδιασμού).

Δείτε επίσης: Νέο PoC Exploit για την ευπάθεια αύξησης προνομίων στο Sudo Chroot

Συνολικά, το δελτίο περιλαμβάνει 11 κρίσιμες ευπάθειες (απομακρυσμένη εκτέλεση κώδικα και ανύψωση προνομίων), με πολλές να συνδέονται με σφάλματα ασφαλείας μνήμης όπως use-after-free και buffer overflows.

Microsoft Patch Tuesday Οκτωβρίου 2025

Στον παρακάτω πίνακα, μπορείτε να δείτε αναλυτικά τις ευπάθειες που διορθώνονται αυτό το μήνα:

CVE IDVulnerability DetailsTypeSeverity
CVE-2016-9535tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka “Predictor heap-buffer-overflow.” Remote Code ExecutionCritical 
CVE-2025-2884CVE-2025-2884 is regarding a vulnerability in CG TPM2.0 Reference implementation’s CryptHmacSign helper function that is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key’s algorithm. Information DisclosureImportant 
CVE-2025-47827In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. Security Feature BypassImportant 
CVE-2025-49708Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. Elevation of PrivilegeCritical 
CVE-2025-55680Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-55682Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. Security Feature BypassImportant 
CVE-2025-55683Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. Information DisclosureImportant 
CVE-2025-55684Use-after-free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-55688Use-after-free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-55690Use-after-free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-55691Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-55692Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-55693Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-55694Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-55695Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally. Information DisclosureImportant 
CVE-2025-55696Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-55697Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-55698Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network. Denial of ServiceImportant 
CVE-2025-55699Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. Information DisclosureImportant 
CVE-2025-58714Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-58718Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Remote Code ExecutionImportant 
CVE-2025-58720Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally. Information DisclosureImportant 
CVE-2025-58724Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-58725Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-58726Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network. Elevation of PrivilegeImportant 
CVE-2025-58727Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-58729Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. Denial of ServiceImportant 
CVE-2025-58730Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-58731Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-58733Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-58734Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-58736Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-58737Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-58738Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-58739Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. SpoofingImportant 
CVE-2025-59184Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally. Information DisclosureImportant 
CVE-2025-59187Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59188Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally. Information DisclosureImportant 
CVE-2025-59189Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59190Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally. Denial of ServiceImportant 
CVE-2025-59191Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59192Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59193Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Management Services allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59194Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59197Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally. Information DisclosureImportant 
CVE-2025-59198Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally. Denial of ServiceImportant 
CVE-2025-59203Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally. Information DisclosureImportant 
CVE-2025-59205Concurrent execution using shared resource with improper synchronization (‘race condition’) in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59208Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network. Information DisclosureImportant 
CVE-2025-59209Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. Information DisclosureImportant 
CVE-2025-59210Elevation of Privilege in Windows Resilient File System (ReFS) Deduplication Service. Elevation of PrivilegeImportant 
CVE-2025-59213Improper neutralization of special elements used in an sql command (‘sql injection’) in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59214Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. SpoofingImportant 
CVE-2025-59221Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-59222Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-59223Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-59224Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-59225Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-59226Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-59227Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Remote Code ExecutionCritical 
CVE-2025-59229Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally. Denial of ServiceImportant 
CVE-2025-59230Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59232Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Information DisclosureImportant 
CVE-2025-59234Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Remote Code ExecutionCritical 
CVE-2025-59236Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Remote Code ExecutionCritical 
CVE-2025-59238Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. Remote Code ExecutionImportant 
CVE-2025-59241Improper link resolution before file access (‘link following’) in Windows Health and Optimized Experiences Service allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59244External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network. SpoofingImportant 
CVE-2025-59248Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. SpoofingImportant 
CVE-2025-59253Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally. Denial of ServiceImportant 
CVE-2025-59260Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally. Information DisclosureImportant 
CVE-2025-59261Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59275Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59278Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59285Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59287Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. Remote Code ExecutionCritical 
CVE-2025-59288Improper verification of cryptographic signature in GitHub allows an unauthorized attacker to perform spoofing over an adjacent network. SpoofingModerate 
CVE-2025-59289Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeImportant 
CVE-2025-59291External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeCritical 
CVE-2025-59292External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. Elevation of PrivilegeCritical 
CVE-2025-59497Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally. Denial of ServiceImportant 
CVE-2025-59502Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network. Denial of ServiceModerate
📧
Εγγραφείτε στο Newsletter του SecNews

Τα σημαντικότερα νέα Ασφάλειας & Τεχνολογίας στο Inbox σας.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

ΑΝΑΖΗΤΗΣΗ

FOLLOW US

📧
Newsletter SecNews
Τα σημαντικότερα νέα Ασφάλειας & Τεχνολογίας στο inbox σας.

LIVE NEWS