Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Are open-ear headphones viable in 2025? Listen for the first time, this pair gave a bold statement

    November 10, 2025

    I saw the future of TV in Samsung’s South Korea lab — and I’m excited for these 3 things

    November 9, 2025

    Very few people are talking about this budget laptop from Lenovo that over-delivers

    November 9, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»October 2025 Patch Tuesday: Holes in the Windows Server Update Service and an ancient modem driver
    Security

    October 2025 Patch Tuesday: Holes in the Windows Server Update Service and an ancient modem driver

    PineapplesUpdateBy PineapplesUpdateOctober 15, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    October 2025 Patch Tuesday: Holes in the Windows Server Update Service and an ancient modem driver
    Share
    Facebook Twitter LinkedIn Pinterest Email


    October 2025 Patch Tuesday: Holes in the Windows Server Update Service and an ancient modem driver

    WSUS RCE

    CVE-2025-59287Which can allow remote code execution (RCE) in Windows Server Update Service (WSUS). It was given a CVSSv3 score of 9.8 and a critical rating, and is accordingly assessed as ‘high potential for exploitation’. Microsoft’s exploit indexAn attacker could exploit this vulnerability to achieve RCE by sending a crafted event that leads to deserialization of untrusted data.

    Tenable points out that this is the third WSUS vulnerability patched as part of Microsoft Patch Tuesday since 2023. But this is the first RCE and has been assessed as having a high probability of being exploited.

    “This vulnerability requires immediate CISO attention as it could compromise your entire patch management infrastructure,” said mike waltersPresident of Action1. “This is a critical deserialization flaw (CVSS 9.8) in WSUS that compromises the systems responsible for distributing security patches across an organization.

    In addition to performing immediate patching, teams should review the patch management architecture and network exposure of WSUS servers, he said. A compromised WSUS environment could allow attackers to deploy malicious “updates” to all managed endpoints, posing a potential threat to organizational security;

    Microsoft Office RCE

    CVE-2025-59227 And CVE-2025-59234Two critical remote code execution vulnerabilities in Microsoft Office.

    Tenable says an attacker could exploit these flaws through social engineering by sending a malicious Microsoft Office document file to an intended target. Successful exploitation would grant code execution privileges to the attacker.

    These bugs take advantage of the “preview pane”, meaning the target does not even need to open the file for exploitation to occur. To carry out these flaws, an attacker would social engineer a target to preview an email with a malicious Microsoft Office document.

    Tenable also notes that despite the exploit being marked as ‘low probability’, Microsoft says the preview pane is an attack vector for both CVEs, meaning the exploit does not require the target to open the file.

    Agere Modem Driver Flaws

    Despite these weaknesses being rated as serious, Satnam NarangTenable’s senior staff research engineer believes that the two most notable vulnerabilities this month are in Agere Modem, a third-party modem driver that has been included in the Windows operating system for nearly 20 years.

    Ancient driver holes modem October patch server service Tuesday update Windows
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleImmutable Linux Offers Serious Security – Here Are Your 5 Best Options
    Next Article Apple’s M5 MacBook Pro could be hours away – here’s everything we know
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Why isn’t my new favorite Windows ultraportable laptop made by Lenovo or Dell?

    November 9, 2025
    Startups

    This Windows PC can easily replace my Mac Mini when it comes to local AI performance

    November 6, 2025
    AI/ML

    Which cloud storage service should you buy in 2025? I compared the best options, and here’s my choice

    November 4, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Are open-ear headphones viable in 2025? Listen for the first time, this pair gave a bold statement

    November 10, 2025

    I saw the future of TV in Samsung’s South Korea lab — and I’m excited for these 3 things

    November 9, 2025

    Very few people are talking about this budget laptop from Lenovo that over-delivers

    November 9, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.