CVE-2025-29971
massOut-of-Bounds Read DoS in Microsoft Windows 11 Web Threat Defense (WTD.sys) Driver
CVE-2025-29971 is an out-of-bounds read (CWE-125) in WTD.sys, the kernel driver behind Microsoft's Web Threat Defense component in Windows 11. A remote, unauthenticated attacker can trigger the flaw by sending crafted network traffic that the driver inspects, causing it to read beyond a buffer's bounds and crash. The impact is denial of service only: the CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) reflects high availability impact with no confidentiality or integrity loss, and a successful attack could crash or hang the affected Windows host. All Windows 11 22H2, 23H2, and 24H2 systems running the Web Threat Defense driver are affected. As of the May 2025 Patch Tuesday coverage there is no known public proof-of-concept, the flaw is not in CISA's KEV, and no in-the-wild exploitation has been reported, although EPSS assigns a 64.4% probability of exploitation within 30 days (99th percentile).
What to do: Apply the Windows security updates released in the May 2025 Patch Tuesday for Windows 11 22H2, 23H2, and 24H2, which remediate WTD.sys, and confirm the updated driver is present on hosts. No workaround is documented, so until patching completes, consider limiting untrusted inbound/network exposure to systems running the affected driver. Prioritize internet-facing and high-availability Windows 11 hosts given the elevated EPSS (64.4% within 30 days), and monitor vendor advisories for exploitation updates.
| microsoft windows 11 22h2 | Windows 11 22H2 (all editions shipping the Web Threat Defense driver; addressed by the May 2025 security updates) |
| microsoft windows 11 23h2 | Windows 11 23H2 (all editions shipping the Web Threat Defense driver; addressed by the May 2025 security updates) |
| microsoft windows 11 24h2 | Windows 11 24H2 (all editions shipping the Web Threat Defense driver; addressed by the May 2025 security updates) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network.
- Vendors
- microsoft
- Products
- windows 11 22h2, windows 11 23h2, windows 11 24h2
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H