CVE-2025-30397
KEV PoC mass1Type Confusion RCE in Microsoft Windows Scripting Engine
CISA: Microsoft Windows Scripting Engine Type Confusion Vulnerability
CVE-2025-30397 is a type confusion flaw (CWE-843) in the Microsoft Windows Scripting Engine, the Windows component that interprets script-based web content. An unauthenticated attacker can trigger the bug remotely by inducing a user's system to process a specially crafted URL, causing the engine to mishandle object types in memory and execute attacker-controlled code. Successful exploitation yields code execution on the targeted Windows host, typically in the context of the user, which can lead to data access and further compromise. Per the CISA data, Microsoft Windows is the affected product, so effectively all unpatched Windows deployments are in scope. The flaw was added to the CISA KEV catalog on 2025-05-13, indicating known exploitation in the wild; EPSS assigns a 26.8% probability of exploitation within 30 days (98th percentile), while no public proof-of-concept is yet known and ransomware use is unknown.
What to do: Apply Microsoft's security update for this vulnerability to all Windows endpoints and servers as soon as possible, prioritizing internet-exposed systems and workstations used for web browsing, per the vendor instructions cited in the CISA KEV required action. Federal agencies must also comply with BOD 22-01 mitigation timelines or discontinue use of the affected product. Until patched, discourage or restrict processing of untrusted URLs and monitor for exploitation activity.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H