Patch Tuesday, October 2025 ‘End of 10’ Edition – Krebs on Security

Patch Tuesday, October 2025 ‘End of 10’ Edition – Krebs on Security

Microsoft immediately launched software program updates to plug a whopping 172 safety holes in its Home windows working methods, together with a minimum of two vulnerabilities which might be already being actively exploited. October’s Patch Tuesday additionally marks the ultimate month that Microsoft will ship safety updates for Home windows 10 methods. If you happen to’re working a Home windows 10 PC and also you’re unable or unwilling emigrate to Home windows 11, learn on for different choices.

The primary zero-day bug addressed this month (CVE-2025-24990) includes a third-party modem driver known as Agere Modem that’s been bundled with Home windows for the previous 20 years. Microsoft responded to energetic assaults on this flaw by fully eradicating the weak driver from Home windows.

The opposite zero-day is CVE-2025-59230, an elevation of privilege vulnerability in Home windows Distant Entry Connection Supervisor (often known as RasMan), a service used to handle distant community connections by way of digital personal networks (VPNs) and dial-up networks.

“Whereas RasMan is a frequent flyer on Patch Tuesday, showing greater than 20 occasions since January 2022, that is the primary time we’ve seen it exploited within the wild as a zero day,” stated Satnam Narang, senior employees analysis engineer at Tenable.

Narang notes that Microsoft Workplace customers must also be aware of CVE-2025-59227 and CVE-2025-59234, a pair of distant code execution bugs that benefit from “Preview Pane,” which means that the goal doesn’t even must open the file for exploitation to happen. To execute these flaws, an attacker would social engineer a goal into previewing an e mail with a malicious Microsoft Workplace doc.

Talking of Workplace, Microsoft quietly announced this week that Microsoft Phrase will now robotically save paperwork to OneDrive, Microsoft’s cloud platform. Customers who’re uncomfortable saving all of their paperwork to Microsoft’s cloud can change this in Phrase’s settings; ZDNet has a useful how-to on disabling this function.

Kev Breen, senior director of menace analysis at Immersive, known as consideration to CVE-2025-59287, a crucial distant code execution bug within the Home windows Server Replace Service  (WSUS) — the exact same Home windows service answerable for downloading safety patches for Home windows Server variations. Microsoft says there aren’t any indicators this weak point is being exploited but. However with a menace rating of 9.8 out of attainable 10 and marked “exploitation extra probably,” CVE-2025-59287 could be exploited with out authentication and is a simple “patch now” candidate.

“Microsoft supplies restricted data, stating that an unauthenticated attacker with community entry can ship untrusted information to the WSUS server, leading to deserialization and code execution,” Breen wrote. “As WSUS is a trusted Home windows service that’s designed to replace privileged information throughout the file system, an attacker would have free rein over the working system and will probably bypass some EDR detections that ignore or exclude the WSUS service.”

For extra on different fixes from Redmond immediately, try the SANS Web Storm Heart monthly roundup, which indexes the entire updates by severity and urgency.

Home windows 10 isn’t the one Microsoft OS that’s reaching end-of-life immediately; Change Server 2016, Change Server 2019, Skype for Enterprise 2016, Home windows 11 IoT Enterprise Model 22H2, and Outlook 2016 are a number of the different merchandise that Microsoft is sunsetting immediately.

If you happen to’re working any Home windows 10 methods, you’ve most likely already decided whether or not your PC meets the technical {hardware} specs beneficial for the Home windows 11 OS. If you happen to’re reluctant or unable emigrate a Home windows 10 system to Home windows 11, there are options to easily persevering with to make use of Home windows 10 with out ongoing safety updates.

One possibility is to pay for an additional 12 months’s value of safety updates by way of Microsoft’s Extended Security Updates (ESU) program. The fee is simply $30 in the event you don’t have a Microsoft account, and apparently free in the event you register the PC to a Microsoft account. This video breakdown from Ask Your Pc Man does a very good job of strolling Home windows 10 customers by way of this course of. Microsoft emphasizes that ESU enrollment doesn’t present different kinds of fixes, function enhancements or product enhancements. It additionally doesn’t include technical help.

In case your Home windows 10 system is related to a Microsoft account and signed in while you go to Home windows Replace, you must see an choice to enroll in prolonged updates. Picture: https://www.youtube.com/watch?v=SZH7MlvOoPM

Home windows 10 customers even have the choice of putting in some taste of Linux as a substitute. Anybody severely contemplating this feature ought to try the web site endof10.org, which features a plethora of ideas and a DIY set up information.

Linux Mint is a good possibility for Linux newbies. Like most trendy Linux variations, Mint will run on something with a 64-bit CPU that has a minimum of 2GB of reminiscence, though 4GB is beneficial. In different phrases, it would run on nearly any pc produced within the final decade.

Linux Mint is also prone to be essentially the most intuitive interface for normal Home windows customers, and it’s largely configurable with none fuss on the text-only command-line immediate. Mint and different flavors of Linux include LibreOffice, which is an open supply suite of instruments that features purposes much like Microsoft Workplace, and it could possibly open, edit and save paperwork as Microsoft Workplace information.

If you happen to’d want to offer Linux a check drive earlier than putting in it on a Home windows PC, you possibly can all the time simply obtain it to a detachable USB drive. From there, reboot the pc (with the detachable drive plugged in) and choose the choice at startup to run the working system from the exterior USB drive. If you happen to don’t see an possibility for that after restarting, attempt restarting once more and hitting the F8 button, which ought to open a listing of bootable drives. Here’s a fairly thorough tutorial that walks by way of precisely easy methods to do all this.

And if that is your first time making an attempt out Linux, loosen up and have enjoyable: The good factor a few “stay” model of Linux (because it’s known as when the working system is run from a detachable drive similar to a CD or a USB stick) is that none of your adjustments persist after a reboot. Even in the event you one way or the other handle to interrupt one thing, a restart will return the system again to its unique state.

As ever, in the event you expertise any difficulties throughout or after making use of this month’s batch of patches, please go away a word about it within the feedback under.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *