ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Patch Tuesday: Microsoft fixes 5 actively exploited zero-days

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-26685
Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

NVD description · AI analysis pending
6.5<1%
  • microsoft defender for identity
CVE-2025-32706
+4 in the same advisory: …32709 …30400 …32701 …30397
Heap-Based Buffer Overflow in Windows CLFS Driver Enables Local Privilege Escalation

CVE-2025-32706 is a heap-based buffer overflow stemming from improper input validation (CWE-20) in the Microsoft Windows Common Log File System (CLFS) driver, triggered when a locally authenticated, low-privileged user gets the driver to process crafted log-related input. A successful exploit lets the attacker elevate from a limited local account to full system-level privileges, giving high impact to confidentiality, integrity, and availability on the host. All installations of the listed releases are affected — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (22H2, 23H2, 24H2), and Windows Server 2008, 2012, 2016, and 2019 — because the CLFS driver ships with these products by default. The vulnerability is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-13, and it was one of the five actively exploited zero-days fixed in Microsoft's May 2025 Patch Tuesday. Ransomware use is currently unknown, and public detection and mitigation scripts are available for defenders.

Do: Apply the May 2025 Windows security updates to all affected Windows 10, Windows 11, and Windows Server systems, prioritizing internet-facing and shared servers given confirmed in-the-wild exploitation; federal agencies must follow BOD 22-01 required actions or discontinue use if mitigations are unavailable. Until patched, restrict local logon and code execution rights to trusted users and watch for local privilege-escalation activity, using the publicly available detection and mitigation scripts as a starting point.

7.8
group max
2% KEV PoC ×2
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019
masson the order of hundreds of millions of installations (CLFS driver present by default on all affected Windows 10, 11, and Server releases)
CVE-2025-32702
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft visual studio 2019
  • microsoft visual studio 2022
Full article493 words · extracted from helpnetsecurity.com · click to collapse

On May 2025 Patch Tuesday, Microsoft has released security fixes for 70+ vulnerabilities, among them five actively exploited zero-days and two publicly disclosed (but not exploited) vulnerabilities.

Microsoft Patch Tuesday

The zero-days and the publicly disclosed flaws

Among the zero-days patched is a memory corruption vulnerability in the Windows scripting engine (CVE-2025-30397) that is being exploited to remotely execute malicious code.

“The user would have to click on a specially crafted URL to be compromised by the attacker,” Microsoft explained.

“The potential target needs to be using Microsoft Edge in Internet Explorer mode in order for exploitation to be successful – a tall order considering Edge has 5% market share. In addition, authentication on the client side is required and the potential target would need to click on a specially crafted link from the attacker,” noted Satnam Narang, senior staff research engineer at Tenable.

“Despite clear exploitation in the wild, we’re not likely to see broad exploitation of this bug due to the number of pre-requisites,” he opined.

CVE-2025-32701 and CVE-2025-32706 are two vulnerabilities in the Windows Common Log File System Driver that allow an authorized attacker to elevate privileges to SYSTEM once they’ve achieved initial access by other means.

They have been spotted being exploited by Microsoft, Google and Crowdstrike threat analysts, but the details about the attacks are currently unavailable.

“In the past, these types of bugs were used by ransomware gangs, so it’s likely these are as well,” says Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, and advised admins to test the patches and deploy them quickly.

CVE-2025-32709 in Windows Ancillary Function Driver for WinSock and CVE-2025-30400 in Microsoft DWM Core Library have also been exploited by attackers to escalate their privileges on vulnerable machines and should be remediated quickly.

The two publicly disclosed vulnerabilities are a remote code execution vulnerability in Visual Studio (CVE-2025-32702) and a spoofing vulnerability in Microsoft Defender (CVE-2025-26685), which are “less likely” and “unlikely” to be exploited, according to Microsoft.

Other vulnerabilities of note

Microsoft has fixed four vulnerabilities in Sharepoint, two of which are considered to be “more likely” to be exploited. The reason for this assessment are unknown, but if you’re using Microsoft SharePoint Server, get the updates.

“SharePoint services, especially those used as internal document stores, can be a treasure trove for threat actors looking to steal data, especially data that may be leveraged to force ransom payments using double extortion techniques by threatening to release the stolen data if payment is not made,” said Kev Breen, Senior Director Threat Research at Immersive.

“A secondary concern is that threat actors with access to SharePoint services could deploy weaponised documents or replace legitimate documents with infected versions that would allow them to spread to other hosts or victims moving laterally across the organization.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/05/13/patch-tuesday-microsoft-fixes-5-actively-exploited-zero-days/