Trinetri logo
Updated monthly

Microsoft Patch Tuesday
October 2025

Microsoft's October 2025 Patch Tuesday fixes 186 vulnerabilities across Windows, Microsoft Office and Azure - 21 rated Critical, 3 publicly disclosed before the patch shipped, 3 already exploited in the wild. Patch CVE-2025-24990 first.

Released October 14, 2025, 10:00 PT3 actively exploited3 publicly disclosed66 KB articles to deploy

October 2025 Patch Tuesday at a glance

186
Microsoft CVEs
excl. Edge & Azure Linux
21
Critical
11% of the release
3
Actively exploited
CVE-2025-24990
3
Publicly disclosed
known before the patch
10.0
Highest CVSS
CVE-2025-59503
66
KB articles
what you actually deploy

Why this number differs from other roundups. Microsoft's October 2025 release document lists 429 entries. 207 are Azure Linux (Mariner) OS package updates and 36 are republished Chromium fixes for Edge - neither is a Microsoft product vulnerability. The 186 above is the real Patch Tuesday set. See the breakdown →

The numbers

What’s in this release

Where the 429 entries actually come from

Most roundups quote a single number. These are three unrelated release streams.

186 Microsoft products207 Azure Linux (Mariner)36 Edge (Chromium)

Severity

Microsoft channel only · 186 CVEs

October 2025 severity breakdown
Critical21
Important163
Moderate2
Low0

Impact type

What an attacker gains if it works

October 2025 impact breakdown
Elevation of Privilege88
Remote Code Execution33
Information Disclosure27
Spoofing15
Denial of Service11
Security Feature Bypass11
Tampering1

Most-affected components

Where this month’s fixes concentrate - filter by any of them in the table below

Windows Kernel10Inbox COM Objects9Microsoft Office Excel9Windows PrintWorkflowUserSvc8Windows BitLocker6Microsoft Graphics Component5Connected Devices Platform Service (Cdpsvc)3Copilot3Microsoft Configuration Manager3Microsoft Exchange Server3Microsoft Office3Microsoft Windows Search Component3
Every patch

Browse all 429 entries

Sorted by risk by default: exploited first, then publicly disclosed, then severity, then CVSS. Search by CVE, title, component or KB number.

Showing 186 of 186
186 Microsoft vulnerabilities in the October 2025 Patch Tuesday, sortable by severity, CVSS and exploit status.
TitleStatusKB
ImportantCVE-2025-24990Windows Agere Modem Driver Elevation of Privilege VulnerabilityEoP7.8ExploitedAgere Windows Modem Driver5066586 +13
ImportantCVE-2025-59230Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityEoP7.8ExploitedWindows Remote Access Connection Manager5066586 +13
ImportantCVE-2025-47827MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11Bypass4.6ExploitedWindows Secure Boot5066586 +9
ImportantCVE-2025-24052Windows Agere Modem Driver Elevation of Privilege VulnerabilityEoP7.8DisclosedMore likelyAgere Windows Modem Driver5066586 +13
CriticalCVE-2025-0033AMD CVE-2025-0033: RMP Corruption During SNP InitializationRCE8.2DisclosedAMD Restricted Memory Page
CriticalCVE-2025-2884Cert CC: CVE-2025-2884 Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementationRCE5.3DisclosedTCG TPM2.05066780 +3
CriticalCVE-2025-59246Azure Entra ID Elevation of Privilege VulnerabilityEoP9.8More likelyAzure Entra ID
CriticalCVE-2025-59287Windows Server Update Service (WSUS) Remote Code Execution VulnerabilityRCE9.8More likelyWindows Server Update Service5070879 +8
ImportantCVE-2025-55680Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Cloud Files Mini Filter Driver5066586 +5
ImportantCVE-2025-55692Windows Error Reporting Service Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Error Reporting5066586 +8
ImportantCVE-2025-55694Windows Error Reporting Service Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Error Reporting5066780 +1
ImportantCVE-2025-58722Microsoft DWM Core Library Elevation of Privilege VulnerabilityEoP7.8More likelyWindows DWM5066586 +6
ImportantCVE-2025-59199Software Protection Platform (SPP) Elevation of Privilege VulnerabilityEoP7.8More likelySoftware Protection Platform (SPP)5066586 +5
ImportantCVE-2025-48004Microsoft Brokering File System Elevation of Privilege VulnerabilityEoP7.4More likelyMicrosoft Brokering File System5066780 +2
ImportantCVE-2025-55693Windows Kernel Elevation of Privilege VulnerabilityEoP7.4More likelyWindows Kernel5066835
ImportantCVE-2025-55681Desktop Window Manager Elevation of Privilege VulnerabilityEoP7.0More likelyWindows DWM5066586 +5
ImportantCVE-2025-59194Windows Kernel Elevation of Privilege VulnerabilityEoP7.0More likelyWindows Kernel5066780 +2
ImportantCVE-2025-55676Windows USB Video Class System Driver Information Disclosure VulnerabilityInfo Disc.5.5More likelyWindows USB Video Driver5066835
ModerateCVE-2025-59502Remote Procedure Call Denial of Service VulnerabilityDoS7.5More likelyWindows Remote Procedure Call5065306 +7
CriticalCVE-2025-49708Microsoft Graphics Component Elevation of Privilege VulnerabilityEoP9.9Microsoft Graphics Component5066586 +5
CriticalCVE-2025-59218Azure Entra ID Elevation of Privilege VulnerabilityEoP9.6Azure Entra ID
CriticalCVE-2025-55321Azure Monitor Log Analytics Spoofing VulnerabilitySpoofing9.3Azure Monitor
CriticalCVE-2025-59252M365 Copilot Information Disclosure VulnerabilitySpoofing9.3Copilot
CriticalCVE-2025-59272Copilot Information Disclosure VulnerabilitySpoofing9.3Copilot
CriticalCVE-2025-59286Copilot Information Disclosure VulnerabilitySpoofing9.3Copilot
Your move

What your IT team should do

The same five steps every month, in the order that reduces risk fastest.

Test the known-issue candidates

Check the Windows release health dashboard before promoting past ring 1, and have the rollback path written down before you need it. Kernel, networking and authentication fixes are the ones that historically break things.

12 Patch Management Best Practices for 2026

Verify installed state, then evidence it

Confirm the patch is actually present on each endpoint rather than trusting that "deployment succeeded". Keep the resulting report - it is the artefact auditors ask for, and reconstructing it later is far more work than capturing it now.

Patch Management: The Complete Guide

Trinetri does steps two through five automatically - detecting the 66 KB articles across every endpoint, staging them in rings, verifying installed state and producing the compliance evidence. See patch management →

Patch Tuesday FAQ

Patch Tuesday falls on the second Tuesday of every month, with updates going live at 10:00 a.m. Pacific Time. Microsoft introduced the practice in October 2003, following the Blaster worm, to cut distribution costs and give administrators a predictable cadence instead of patches arriving at random. The 10:00 a.m. timing is deliberate: it leaves a full working week to remediate before the weekend. Internally Microsoft calls it the "B" release; optional "C" and "D" preview releases follow later in the month. The next Patch Tuesday is September 8, 2026.

Microsoft fixed 186 vulnerabilities in October 2025, across Windows, Microsoft Office, Azure and Developer Tools. 21 are rated Critical, 3 were publicly disclosed before the patch shipped, and 3 were already being exploited. Note that Microsoft's release document lists 429 entries in total, but 207 of those are Azure Linux package updates and 36 are republished Chromium fixes for Edge, which is why other sources sometimes quote a much larger number.

Exploit Wednesday is the day after Patch Tuesday. Attackers compare the newly released patches against the previous version to locate the flaw each one fixes, then build working exploits from that difference - often within 24 to 48 hours. It is the reason the deployment window matters as much as the patch itself: every hour a Critical remote code execution fix sits undeployed is an hour of measurable exposure.

A workable target for most organisations: actively exploited vulnerabilities within 24 hours, publicly disclosed ones within 72 hours, remaining Critical fixes within seven days, and everything else within the month. CISA's Known Exploited Vulnerabilities catalogue sets binding deadlines for US federal agencies and is a reasonable benchmark for everyone else. Stage the rollout in rings rather than deploying everywhere at once, so a regression is caught on a pilot group instead of in production.

An out-of-band update is a patch released outside the monthly cycle because the risk will not wait for the next Patch Tuesday. Microsoft issues them for actively exploited flaws with no mitigation - most famously during the WannaCry outbreak in 2017, when it took the unusual step of patching versions of Windows that were already out of support.

Yes. Adobe aligned its releases with Patch Tuesday in November 2012, and both SAP's Security Patch Day and Oracle's quarterly Critical Patch Updates are coordinated to the same week. Part of the reason is defensive: staggered releases let attackers reverse-engineer one vendor's patch to find the same underlying flaw in another's still-unpatched product. For IT teams it means the second Tuesday is rarely just a Microsoft problem.

Edge is built on Chromium, so most of its security fixes originate with the Chromium project and are republished by Microsoft under their own CVE identifiers. They ship on Chromium's cadence rather than the Patch Tuesday cycle, and they are delivered by Edge's own updater rather than Windows Update. Counting the 36 Edge entries alongside Microsoft product fixes would inflate the headline number and imply work for your Windows Update rings that does not exist.

Stop the sprawl. Eliminate the guesswork.

Ready to See Autonomous Endpoint Management in Action?

Experience how Trinetri transforms endpoint chaos into clarity. Try the 30 minute demo session, our experts will walk you through how AI-powered automation, real-time visibility, and unified control can secure your entire hybrid environment, without the overhead.