Microsoft releases October 2025 security updates addressing six zero-days and 172 vulnerabilities
On October 14, 2025, Microsoft released its October Patch Tuesday updates, addressing a total of 172 security vulnerabilities, including six zero-day flaws. Among the updates, eight are classified as ‘Critical’, comprising five remote code execution issues and three elevation of privilege vulnerabilities. Windows 10 reached its end-of-support milestone with this update, marking the last free security patch for the OS. Users who want continued protection must enroll in Extended Security Updates (ESU) for up to three years. Significant zero-day vulnerabilities fixed include those in the Windows SMB Server, Microsoft SQL Server, Windows Agere Modem Driver, Remote Access Connection Manager, and IGEL OS Secure Boot. Some flaws were publicly disclosed or actively exploited, affecting systems from AMD processors with SEV-SNP to TPM 2.0 implementations. Microsoft also removed the Agere Modem driver, which may impact related fax hardware. Other software vendors, such as Adobe, Cisco, Oracle, Redis, SAP, and Ivanti, released their own security advisories in October 2025, highlighting the widespread need for timely patching across platforms. These updates aim to mitigate potential risks of privilege escalation, remote code execution, and information disclosure for both enterprise and individual users.
