ZeroHour

CVE-2025-29971

mass

Out-of-Bounds Read DoS in Microsoft Windows 11 Web Threat Defense (WTD.sys) Driver

CVSS 3.1
7.5 high
EPSS
64%p99
Published
()
Modified
AI analysis

CVE-2025-29971 is an out-of-bounds read (CWE-125) in WTD.sys, the kernel driver behind Microsoft's Web Threat Defense component in Windows 11. A remote, unauthenticated attacker can trigger the flaw by sending crafted network traffic that the driver inspects, causing it to read beyond a buffer's bounds and crash. The impact is denial of service only: the CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) reflects high availability impact with no confidentiality or integrity loss, and a successful attack could crash or hang the affected Windows host. All Windows 11 22H2, 23H2, and 24H2 systems running the Web Threat Defense driver are affected. As of the May 2025 Patch Tuesday coverage there is no known public proof-of-concept, the flaw is not in CISA's KEV, and no in-the-wild exploitation has been reported, although EPSS assigns a 64.4% probability of exploitation within 30 days (99th percentile).

What to do: Apply the Windows security updates released in the May 2025 Patch Tuesday for Windows 11 22H2, 23H2, and 24H2, which remediate WTD.sys, and confirm the updated driver is present on hosts. No workaround is documented, so until patching completes, consider limiting untrusted inbound/network exposure to systems running the affected driver. Prioritize internet-facing and high-availability Windows 11 hosts given the elevated EPSS (64.4% within 30 days), and monitor vendor advisories for exploitation updates.

Affected
microsoft windows 11 22h2Windows 11 22H2 (all editions shipping the Web Threat Defense driver; addressed by the May 2025 security updates)
microsoft windows 11 23h2Windows 11 23H2 (all editions shipping the Web Threat Defense driver; addressed by the May 2025 security updates)
microsoft windows 11 24h2Windows 11 24H2 (all editions shipping the Web Threat Defense driver; addressed by the May 2025 security updates)
Estimated exposure
mass~hundreds of millions of Windows 11 devices (22H2/23H2/24H2 installed base) — WTD.sys ships with Windows 11 22H2 and later as part of Microsoft's Web Threat Defense/Defender web protection, so the affected population is essentially the installed base of Windows 11 22H2/23H2/24H2, an order of magnitude of hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network.

Vendors
microsoft
Products
windows 11 22h2, windows 11 23h2, windows 11 24h2
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news