this post was submitted on 15 Oct 2025
448 points (99.1% liked)

Technology

77795 readers
2595 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

..."The vulnerable driver ships with every version of Windows, up to and including Server 2025," Adam Barnett, lead software engineer at Rapid7, said. "Maybe your fax modem uses a different chipset, and so you don't need the Agere driver? Perhaps you've simply discovered email? Tough luck. Your PC is still vulnerable, and a local attacker with a minimally privileged account can elevate to administrator."...

you are viewing a single comment's thread
view the rest of the comments
[–] SnotFlickerman@lemmy.blahaj.zone 190 points 2 months ago (10 children)

To anyone misreading this, these exploits were patched yesterday and thus were included as the final patch for Windows 10 before the extended security updates requirements kick in.

Known exploits are always reported to the company first to give them time to patch it before releasing info on the exploits.

All Windows 10 users will continue to have access to the patches in this final freely available patch Tuesday for Windows 10. They just can't get new updates without joining the ESU program.

I hate Microsoft too and only use Linux, but let's stop the circlejerk of false claims here please and thank you.

[–] sourhill@lemmy.sdf.org 7 points 2 months ago (7 children)

Zero-day means the company had 0 days to fix it before the exploits were made public. Maybe the headline is wrong?

[–] SnotFlickerman@lemmy.blahaj.zone 4 points 2 months ago

Perhaps, either that or they made a very quick fix making updates to address them the day before this patch release.

load more comments (6 replies)
load more comments (8 replies)