67
submitted 2 months ago by Delta_V@lemmy.world to c/technology@lemmy.world

..."The vulnerable driver ships with every version of Windows, up to and including Server 2025," Adam Barnett, lead software engineer at Rapid7, said. "Maybe your fax modem uses a different chipset, and so you don't need the Agere driver? Perhaps you've simply discovered email? Tough luck. Your PC is still vulnerable, and a local attacker with a minimally privileged account can elevate to administrator."...

you are viewing a single comment's thread
view the rest of the comments
[-] zleap@techhub.social 1 points 2 months ago

@Delta_V

It will be interesting what happens with this Windows 10 end of support, this just happens to crop up the day after support ends.

[-] SnotFlickerman@lemmy.blahaj.zone 2 points 2 months ago* (last edited 2 months ago)

The exploits are addressed in the patch released yesterday, on the final day of support.

Generally such exploits aren't released to the public until they have been patched, to prevent wider abuse of the exploits in the meantime.

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-24990

As you can see here near the bottom of the page it lists security updates for this epxloit having been released on October 14rh, 2025, the final day of Win10 support. These updates will still be available to Windows 10 systems even after October 14th, they will just be unable to get new patches after that date.

[-] zleap@techhub.social 0 points 2 months ago

@SnotFlickerman

So will MS leave people in the lurch or issue an emergency patch? The former will drive people straight to replacements and the community need to be like a predator ready to move in to injured prey.

If we don't it will be a massive opportunity lost.

[-] Bronzebeard@lemmy.zip 1 points 2 months ago

Why not bother reading the comment you responded to?

load more comments (1 replies)
this post was submitted on 15 Oct 2025
67 points (98.6% liked)

Technology

77791 readers
677 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS