{"id":7740,"date":"2025-10-16T09:40:08","date_gmt":"2025-10-16T09:40:08","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=7740"},"modified":"2025-10-16T09:40:08","modified_gmt":"2025-10-16T09:40:08","slug":"patch-tuesday-october-2025-finish-of-10-version-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=7740","title":{"rendered":"Patch Tuesday, October 2025 \u2018Finish of 10\u2019 Version \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><strong>Microsoft<\/strong> right this moment launched software program updates to plug a whopping 172 safety holes in its <strong>Home windows<\/strong> working programs, together with at the very least two vulnerabilities which can be already being actively exploited. October\u2019s Patch Tuesday additionally marks the ultimate month that Microsoft will ship safety updates for <strong>Home windows 10<\/strong> programs. In the event you\u2019re working a Home windows 10 PC and also you\u2019re unable or unwilling emigrate to<strong> Home windows 11<\/strong>, learn on for different choices.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-52647\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2020\/08\/windowsec.png\" alt=\"\" width=\"748\" height=\"549\"\/><\/p>\n<p>The primary zero-day bug addressed this month (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2025-24990\" target=\"_blank\" rel=\"noopener\">CVE-2025-24990<\/a>) includes a third-party modem driver known as Agere Modem that\u2019s been bundled with Home windows for the previous twenty years. Microsoft responded to lively assaults on this flaw by fully eradicating the susceptible driver from Home windows.<\/p>\n<p>The opposite zero-day is <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2025-59230\" target=\"_blank\" rel=\"noopener\">CVE-2025-59230<\/a>, an elevation of privilege vulnerability in <strong>Home windows Distant Entry Connection Supervisor<\/strong> (also referred to as <strong>RasMan<\/strong>), a service used to handle distant community connections via digital personal networks (VPNs) and dial-up networks.<\/p>\n<p>\u201cWhereas RasMan is a frequent flyer on Patch Tuesday, showing greater than 20 occasions since January 2022, that is the primary time we\u2019ve seen it exploited within the wild as a zero day,\u201d mentioned <strong>Satnam Narang<\/strong>, senior employees analysis engineer at <strong>Tenable<\/strong>.<\/p>\n<p>Narang notes that <strong>Microsoft Workplace<\/strong> customers also needs to pay attention to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2025-59227\" target=\"_blank\" rel=\"noopener\">CVE-2025-59227<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"http:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2025-59234\" target=\"_blank\" rel=\"noopener\">CVE-2025-59234<\/a>, a pair of distant code execution bugs that reap the benefits of \u201cPreview Pane,\u201d which means that the goal doesn\u2019t even have to open the file for exploitation to happen. To execute these flaws, an attacker would social engineer a goal into previewing an e-mail with a malicious Microsoft Workplace doc.<\/p>\n<p>Talking of Workplace, Microsoft <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.windowscentral.com\/microsoft\/microsoft-office\/microsoft-is-making-word-automatically-save-new-documents-to-onedrive-by-default\" target=\"_blank\" rel=\"noopener\">quietly introduced this week<\/a> that <strong>Microsoft Phrase<\/strong> will now robotically save paperwork to OneDrive, Microsoft\u2019s cloud platform. Customers who&#8217;re uncomfortable saving all of their paperwork to Microsoft\u2019s cloud can change this in Phrase\u2019s settings; ZDNet has <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.zdnet.com\/article\/microsoft-word-forcing-you-to-save-new-files-to-the-cloud-heres-how-to-stop-it\/\" target=\"_blank\" rel=\"noopener\">a helpful how-to<\/a> on disabling this characteristic.<\/p>\n<p><strong>Kev Breen<\/strong>, senior director of menace analysis at <strong>Immersive<\/strong>, known as consideration to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2025-59287\" target=\"_blank\" rel=\"noopener\">CVE-2025-59287<\/a>, a essential distant code execution bug within the Home windows Server Replace Service\u00a0 (WSUS) \u2014 the exact same Home windows service liable for downloading safety patches for Home windows Server variations. Microsoft says there aren&#8217;t any indicators this weak spot is being exploited but. However with a menace rating of 9.8 out of potential 10 and marked \u201cexploitation extra probably,\u201d CVE-2025-59287 may be exploited with out authentication and is a simple \u201cpatch now\u201d candidate.<\/p>\n<p>\u201cMicrosoft offers restricted data, stating that an unauthenticated attacker with community entry can ship untrusted knowledge to the WSUS server, leading to deserialization and code execution,\u201d Breen wrote. \u201cAs WSUS is a trusted Home windows service that&#8217;s designed to replace privileged recordsdata throughout the file system, an attacker would have free rein over the working system and will probably bypass some EDR detections that ignore or exclude the WSUS service.\u201d<\/p>\n<p>For extra on different fixes from Redmond right this moment, take a look at the <strong>SANS Web Storm Heart<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/isc.sans.edu\/forums\/diary\/Microsoft%20Patch%20Tuesday%20October%202025\/32368\/\" target=\"_blank\" rel=\"noopener\">month-to-month roundup<\/a>, which indexes all the updates by severity and urgency.<\/p>\n<p>Home windows 10 isn\u2019t the one Microsoft OS that&#8217;s reaching end-of-life right this moment;\u00a0<strong>Change Server 2016<\/strong>, <strong>Change Server 2019<\/strong>, <strong>Skype for Enterprise 2016<\/strong>, <strong>Home windows 11 IoT Enterprise Model 22H2<\/strong>, and <strong>Outlook 2016<\/strong> are a few of the different merchandise that Microsoft is sunsetting right this moment.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-72385\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/win10pcrequirements.png\" alt=\"\" width=\"747\" height=\"474\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/win10pcrequirements.png 2050w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/win10pcrequirements-768x487.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/win10pcrequirements-1536x974.png 1536w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/win10pcrequirements-2048x1299.png 2048w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/win10pcrequirements-782x496.png 782w\" sizes=\"auto, (max-width: 747px) 100vw, 747px\"\/><\/p>\n<p>In the event you\u2019re working any Home windows 10 programs, you\u2019ve most likely already decided whether or not your PC meets the technical {hardware} specs advisable for the Home windows 11 OS. In the event you\u2019re reluctant or unable emigrate a Home windows 10 system to Home windows 11, there are options to easily persevering with to make use of Home windows 10 with out ongoing safety updates.<span id=\"more-72318\"\/><\/p>\n<p>One possibility is to pay for one more 12 months\u2019s price of safety updates via <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-ie\/windows\/extended-security-updates?r=1\" target=\"_blank\" rel=\"noopener\">Microsoft\u2019s Prolonged Safety Updates<\/a> (ESU) program. The fee is simply $30 should you don\u2019t have a Microsoft account, and apparently free should you register the PC to a Microsoft account. This <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.youtube.com\/watch?v=SZH7MlvOoPM\" target=\"_blank\" rel=\"noopener\">video breakdown<\/a> from <strong>Ask Your Laptop Man<\/strong> does a very good job of strolling Home windows 10 customers via this course of. Microsoft emphasizes that ESU enrollment doesn&#8217;t present different forms of fixes, characteristic enhancements or product enhancements. It additionally doesn&#8217;t include technical help.<\/p>\n<div id=\"attachment_72386\" style=\"width: 756px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-72386\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-72386\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/esu-winupdate.png\" alt=\"\" width=\"746\" height=\"436\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/esu-winupdate.png 2226w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/esu-winupdate-768x449.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/esu-winupdate-1536x897.png 1536w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/esu-winupdate-2048x1196.png 2048w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/esu-winupdate-782x457.png 782w\" sizes=\"auto, (max-width: 746px) 100vw, 746px\"\/><\/p>\n<p id=\"caption-attachment-72386\" class=\"wp-caption-text\">In case your Home windows 10 system is related to a Microsoft account and signed in if you go to Home windows Replace, you need to see an choice to enroll in prolonged updates. Picture: https:\/\/www.youtube.com\/watch?v=SZH7MlvOoPM<\/p>\n<\/div>\n<p>Home windows 10 customers even have the choice of putting in some taste of Linux as a substitute. Anybody significantly contemplating this feature ought to take a look at the web site <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/endof10.org\/\" target=\"_blank\" rel=\"noopener\">endof10.org<\/a>, which features a plethora of suggestions and a DIY set up information.<\/p>\n<p><strong>Linux Mint <\/strong>is a superb possibility for Linux newbies. Like most fashionable Linux variations, Mint will run on something with a 64-bit CPU that has at the very least 2GB of reminiscence, though 4GB is advisable. In different phrases, it would run on nearly any laptop produced within the final decade.<\/p>\n<p>Linux Mint is also prone to be essentially the most intuitive interface for normal Home windows customers, and it&#8217;s largely configurable with none fuss on the text-only command-line immediate. Mint and different flavors of Linux include <strong>LibreOffice<\/strong>, which is an open supply suite of instruments that features purposes much like Microsoft Workplace, and it could open, edit and save paperwork as Microsoft Workplace recordsdata.<\/p>\n<p>In the event you\u2019d choose to provide Linux a check drive earlier than putting in it on a Home windows PC, you&#8217;ll be able to all the time simply obtain it to a detachable USB drive. From there, reboot the pc (with the detachable drive plugged in) and choose the choice at startup to run the working system from the exterior USB drive. In the event you don\u2019t see an possibility for that after restarting, attempt restarting once more and hitting the F8 button, which ought to open an inventory of bootable drives.\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.youtube.com\/watch?v=_qZI6i21jB4\" target=\"_blank\" rel=\"noopener\">Right here\u2019s a reasonably thorough tutorial<\/a>\u00a0that walks via precisely learn how to do all this.<\/p>\n<p>And if that is your first time attempting out Linux, loosen up and have enjoyable: The great factor a couple of \u201creside\u201d model of Linux (because it\u2019s known as when the working system is run from a detachable drive similar to a CD or a USB stick) is that none of your adjustments persist after a reboot. Even should you someway handle to interrupt one thing, a restart will return the system again to its authentic state.<\/p>\n<p>As ever, should you expertise any difficulties throughout or after making use of this month\u2019s batch of patches, please depart a observe about it within the feedback beneath.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Microsoft right this moment launched software program updates to plug a whopping 172 safety holes in its Home windows working programs, together with at the very least two vulnerabilities which can be already being actively exploited. October\u2019s Patch Tuesday additionally marks the ultimate month that Microsoft will ship safety updates for Home windows 10 programs. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":7742,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[406,262,2273,1077,211,1078],"class_list":["post-7740","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-edition","tag-krebs","tag-october","tag-patch","tag-security","tag-tuesday"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/7740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7740"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/7740\/revisions"}],"predecessor-version":[{"id":7741,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/7740\/revisions\/7741"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/7742"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7740"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-05-06 17:32:02 UTC -->