this post was submitted on 15 Oct 2025
418 points (99.3% liked)

Technology

76089 readers
2850 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

..."The vulnerable driver ships with every version of Windows, up to and including Server 2025," Adam Barnett, lead software engineer at Rapid7, said. "Maybe your fax modem uses a different chipset, and so you don't need the Agere driver? Perhaps you've simply discovered email? Tough luck. Your PC is still vulnerable, and a local attacker with a minimally privileged account can elevate to administrator."...

you are viewing a single comment's thread
view the rest of the comments
[–] zleap@techhub.social 50 points 1 day ago (3 children)

@Delta_V

It will be interesting what happens with this Windows 10 end of support, this just happens to crop up the day after support ends.

[–] SnotFlickerman@lemmy.blahaj.zone 35 points 1 day ago* (last edited 1 day ago) (1 children)

The exploits are addressed in the patch released yesterday, on the final day of support.

Generally such exploits aren't released to the public until they have been patched, to prevent wider abuse of the exploits in the meantime.

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-24990

As you can see here near the bottom of the page it lists security updates for this epxloit having been released on October 14rh, 2025, the final day of Win10 support. These updates will still be available to Windows 10 systems even after October 14th, they will just be unable to get new patches after that date.

[–] Delta_V@lemmy.world 24 points 1 day ago

yeah, the timing is 'interesting'

[–] Alphane_Moon@lemmy.world 1 points 21 hours ago (1 children)

They will continue to releases major security updates for Windows 10 as long as it has double digit installed base share.

[–] mic_check_one_two@lemmy.dbzer0.com 1 points 2 hours ago* (last edited 2 hours ago)

Yeah, they did the same for Win7 for a long time. Win7 was so widely used (and people were so hesitant to upgrade after the awful 8/8.1 mess) that like 25-30% of all the computers in the world were still using it several years after support officially ended. It forced MS to continue issuing critical vulnerability patches for Win7, long after support officially ended. Because they didn’t want to be responsible for creating a massive “literally a quarter of all PCs in the world” botnet when they stopped patching things.