HomeUpdatesMicrosoft Patch Tuesday October 2025: 172 vulnerabilities fixed

Microsoft Patch Tuesday October 2025: 172 vulnerabilities fixed

Microsoft has released its October 2025 Patch Tuesday updates , addressing 172 vulnerabilities in its ecosystem , including four zero-day vulnerabilities (two of which are actively being exploited by hackers).

Microsoft Patch Tuesday October

This monthly security bulletin highlights the relentless pace of threat evolution, with critical remote code execution in Office applications and elevation of privilege issues in Windows components dominating the fixes.

As organizations face end-of-support deadlines for older systems like Windows 10, timely application of updates remains essential to reduce risks from government agencies and cybercriminals.

See also: Oracle patches new vulnerability in E-Business Suite

The updates target a wide range of products, from core Windows operating systems to Azure cloud services and the Microsoft Office suite.

ImpactCount
Privilege escalation80
Remote Code Execution31
Disclosure of information28
Bypassing security features11
Denial of Service11
Spoofing10
Tampering1
Total172

Some of the most significant vulnerabilities, fixed by Microsoft with the October Patch Tuesday, are CVE-2025-59234 and CVE-2025-59236, two use-after-free vulnerabilities in Microsoft Office and Excel that allow remote code execution when users open malicious files. These vulnerabilities, rated as very severe, with CVSS scores around 7.8, do not require authentication and could allow attackers to gain complete control of the system, potentially leading to data theft or ransomware deployment.

Microsoft Patch Tuesday October 2025: 172 vulnerabilities fixed

Similarly, CVE-2025-49708 in Microsoft Graphics Component exposes systems to elevation of privilege over networks.

Microsoft Patch Tuesday October: Fix critical vulnerabilities

Several critical vulnerabilities require immediate attention due to their potential for widespread exploitation. For example, CVE-2025-59291 and CVE-2025-59292 involve external file path control in Azure Container Instances and Compute Gallery, allowing authorized attackers to elevate privileges locally and potentially compromise cloud workloads. These elevation of privilege bugs highlight the ongoing risks in hybrid environments, where misconfigurations amplify the impact.

See also: Vulnerability in Elastic Cloud Enterprise allows execution of malicious commands

Another vulnerability is CVE-2016-9535, a LibTIFF heap buffer overflow that was refactored in this update cycle. It could cause remote code execution in image processing scripts, affecting older applications that are still in use.

Zero-day vulnerabilities fixed

The zero-days add to the urgency of the update: CVE-2025-2884, an out-of-bounds read in the TCG TPM2.0 reference implementation, results from insufficient validation in cryptographic signing functions and could lead to information disclosure. Publicly known via CERT/CC, it affects trusted platform modules that are integral to secure boot processes.

Microsoft Patch Tuesday October 2025: 172 vulnerabilities fixed

Meanwhile, CVE-2025-47827 allows Secure Boot to be bypassed on IGEL OS versions prior to 11, through improper signature verification. It allows unverified images to be placed as a vector for persistent malicious activity. CVE-2025-59230, another zero-day vulnerability in Windows Remote Access Connection Manager, involves improper access checks for local privilege escalation.

Microsoft confirms that there are no public exploits for most vulnerabilities, but active exploitation of some of them requires a quick Patch Tuesday application.

Deserialization issues in Windows Server Update Service (CVE-2025-59287) further raise concerns, allowing unauthenticated remote code execution over networks (a prime target for supply chain attacks).

See also: New PoC Exploit for Sudo Chroot Privilege Escalation Vulnerability

In total, the bulletin includes 11 critical vulnerabilities (remote code execution and elevation of privilege), with many linked to memory safety such as use-after-free and buffer overflows.

Microsoft Patch Tuesday October 2025

In the table below, you can see in detail the vulnerabilities being fixed this month:

CVE IDVulnerability DetailsTypeSeverity
CVE-2016-9535tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka “Predictor heap-buffer-overflow.” ​Remote Code ExecutionCritical ​
CVE-2025-2884CVE-2025-2884 is regarding a vulnerability in CG TPM2.0 Reference implementation's CryptHmacSign helper function that is vulnerable to Out-of-Bounds read due to the lack of validation of the signature scheme with the signature key's algorithm. ​Information DisclosureImportant ​
CVE-2025-47827In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. ​Security Feature BypassImportant ​
CVE-2025-49708Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. ​Elevation of PrivilegeCritical ​
CVE-2025-55680Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-55682Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. ​Security Feature BypassImportant ​
CVE-2025-55683Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. ​Information DisclosureImportant ​
CVE-2025-55684Use-after-free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-55688Use-after-free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-55690Use-after-free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally . ​Elevation of PrivilegeImportant ​
CVE-2025-55691Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-55692Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-55693Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-55694Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-55695Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally. ​Information DisclosureImportant ​
CVE-2025-55696Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-55697Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-55698Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network. ​Denial of ServiceImportant ​
CVE-2025-55699Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. ​Information DisclosureImportant ​
CVE-2025-58714Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-58718Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. ​Remote Code ExecutionImportant ​
CVE-2025-58720Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally. ​Information DisclosureImportant ​
CVE-2025-58724Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-58725Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-58726Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network. ​Elevation of PrivilegeImportant ​
CVE-2025-58727Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-58729Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. ​Denial of ServiceImportant ​
CVE-2025-58730Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-58731Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-58733Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-58734Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-58736Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-58737Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-58738Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-58739Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. ​SpoofingImportant ​
CVE-2025-59184Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally. ​Information DisclosureImportant ​
CVE-2025-59187Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59188Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally. ​Information DisclosureImportant ​
CVE-2025-59189Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59190Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally. ​Denial of ServiceImportant ​
CVE-2025-59191Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59192Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59193Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59194Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59197Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally. ​Information DisclosureImportant ​
CVE-2025-59198Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally. ​Denial of ServiceImportant ​
CVE-2025-59203Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally. ​Information DisclosureImportant ​
CVE-2025-59205Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59208Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network. ​Information DisclosureImportant ​
CVE-2025-59209Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. ​Information DisclosureImportant ​
CVE-2025-59210Elevation of Privilege in Windows Resilient File System (ReFS) Deduplication Service. ​Elevation of PrivilegeImportant ​
CVE-2025-59213Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59214Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. ​SpoofingImportant ​
CVE-2025-59221Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-59222Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-59223Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-59224Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-59225Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-59226Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-59227Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionCritical ​
CVE-2025-59229Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally. ​Denial of ServiceImportant ​
CVE-2025-59230Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59232Out-of-bounds reading in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. ​Information DisclosureImportant ​
CVE-2025-59234Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionCritical ​
CVE-2025-59236Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionCritical ​
CVE-2025-59238Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. ​Remote Code ExecutionImportant ​
CVE-2025-59241Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59244External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network. ​SpoofingImportant ​
CVE-2025-59248Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. ​SpoofingImportant ​
CVE-2025-59253Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally. ​Denial of ServiceImportant ​
CVE-2025-59260Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally. ​Information DisclosureImportant ​
CVE-2025-59261Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59275Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59278Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59285Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59287Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. ​Remote Code ExecutionCritical ​
CVE-2025-59288Improper verification of cryptographic signature in GitHub allows an unauthorized attacker to perform spoofing over an adjacent network. ​SpoofingModerate ​
CVE-2025-59289Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeImportant ​
CVE-2025-59291External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeCritical ​
CVE-2025-59292External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. ​Elevation of PrivilegeCritical ​
CVE-2025-59497Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally. ​Denial of ServiceImportant ​
CVE-2025-59502Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network. ​Denial of ServiceModerate
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS