Microsoft October 2025 Patch Tuesday – 4 Zero-days and 172 Vulnerabilities Patched
On Tue, Oct 14, 2025, Microsoft released its October 2025 Patch Tuesday updates, addressing 172 vulnerabilities, including four zero-day flaws, with two actively exploited. This update includes critical remote code execution vulnerabilities in Office…
On Tue, Oct 14, 2025, Microsoft released its October 2025 Patch Tuesday updates, addressing 172 vulnerabilities, including four zero-day flaws, with two actively exploited. This update includes critical remote code execution vulnerabilities in Office applications and elevation of privilege issues in Windows components.
Elevation of Privilege: 80 instances Remote Code Execution: 31 instances Information Disclosure: 28 instances Security Feature Bypass: 11 instances Denial of Service: 11 instances Spoofing: 10 instances Tampering: 1 instance Total: 172 vulnerabilities
These updates encompass a wide range of Microsoft products, including core Windows operating systems, Azure cloud services, and the Microsoft Office suite.
Significant fixes include CVE-2025-59234 and CVE-2025-59236, both critical use-after-free vulnerabilities in Microsoft Office and Excel, allowing remote code execution when opening malicious files. These have CVSS scores of approximately 7.8 and require no authentication, posing risks of data theft or ransomware deployment.
CVE-2025-59291 and CVE-2025-59292: External control of file paths in Azure Container Instances and Compute Gallery, allowing privilege escalation. CVE-2016-9535: LibTIFF heap buffer overflow, potentially triggering remote code execution in image-processing scenarios. CVE-2025-2884: Out-of-bounds read in TCG TPM2.0, leading to information disclosure. CVE-2025-47827: Secure Boot bypass in IGEL OS before version 11. CVE-2025-59230: Exploited flaw in Windows Remote Access Connection Manager for privilege escalation.
This update includes critical remote code execution vulnerabilities in Office applications and elevation of privilege issues in Windows components.
Microsoft has stated that there are no public exploits for most vulnerabilities, but the active exploitation by threat actors necessitates rapid patch deployment.
Other Important Vulnerabilities Patched
Additional vulnerabilities cover over 150 important issues, including elevation of privilege, information disclosure, and denial-of-service flaws. Notable vulnerabilities include:
CVE-2025-55684: Use-after-free bugs in Windows PrintWorkflowUserSvc. CVE-2025-55693 and CVE-2025-59187: Windows Kernel vulnerabilities involving improper input validation. CVE-2025-59239: Spoofing risks in File Explorer. CVE-2025-55682: BitLocker security feature bypass via physical attacks.
Microsoft urges users to enable automatic updates via Windows Update or WSUS, with a priority on critical vulnerabilities. Enterprises are encouraged to use vulnerability management tools for scanning affected versions such as Office 2016-2021 or Windows 10/11 builds.
For further details, visit the Microsoft Security Update Guide .
Based on reporting by Cyber Security News.
