ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-29967
+2 in the same advisory: …24063 …29833
Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.8
group max
1%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2025-29841
Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker

Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.0<1%
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • microsoft windows 11 22h2
  • +1 more
CVE-2025-29966
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.81%
  • microsoft remote desktop
  • microsoft windows app
  • microsoft windows 10 1507
  • +1 more
CVE-2025-29971
Out-of-Bounds Read DoS in Microsoft Windows 11 Web Threat Defense (WTD.sys) Driver

CVE-2025-29971 is an out-of-bounds read (CWE-125) in WTD.sys, the kernel driver behind Microsoft's Web Threat Defense component in Windows 11. A remote, unauthenticated attacker can trigger the flaw by sending crafted network traffic that the driver inspects, causing it to read beyond a buffer's bounds and crash. The impact is denial of service only: the CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) reflects high availability impact with no confidentiality or integrity loss, and a successful attack could crash or hang the affected Windows host. All Windows 11 22H2, 23H2, and 24H2 systems running the Web Threat Defense driver are affected. As of the May 2025 Patch Tuesday coverage there is no known public proof-of-concept, the flaw is not in CISA's KEV, and no in-the-wild exploitation has been reported, although EPSS assigns a 64.4% probability of exploitation within 30 days (99th percentile).

Do: Apply the Windows security updates released in the May 2025 Patch Tuesday for Windows 11 22H2, 23H2, and 24H2, which remediate WTD.sys, and confirm the updated driver is present on hosts. No workaround is documented, so until patching completes, consider limiting untrusted inbound/network exposure to systems running the affected driver. Prioritize internet-facing and high-availability Windows 11 hosts given the elevated EPSS (64.4% within 30 days), and monitor vendor advisories for exploitation updates.

7.564%
  • microsoft windows 11 22h2 Windows 11 22H2 (all editions shipping the Web Threat Defense driver; addressed by the May 2025 security updates)
  • microsoft windows 11 23h2 Windows 11 23H2 (all editions shipping the Web Threat Defense driver; addressed by the May 2025 security updates)
  • microsoft windows 11 24h2 Windows 11 24H2 (all editions shipping the Web Threat Defense driver; addressed by the May 2025 security updates)
mass~hundreds of millions of Windows 11 devices (22H2/23H2/24H2 installed base)
CVE-2025-30382
+1 in the same advisory: …29976
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
7.82%
  • microsoft sharepoint server
CVE-2025-30386
+1 in the same advisory: …30377
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft 365 apps
  • microsoft 365 copilot
  • microsoft office
  • +1 more
CVE-2025-30385
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • +1 more
CVE-2025-30388
Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
7.84%
  • microsoft 365 copilot
  • microsoft office
  • microsoft office long term servicing channel
  • +1 more
CVE-2025-30390
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.

Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.

NVD description · AI analysis pending
8.8<1%
  • microsoft azure machine learning
CVE-2025-32706
+4 in the same advisory: …32709 …30400 …32701 …30397
Heap-Based Buffer Overflow in Windows CLFS Driver Enables Local Privilege Escalation

CVE-2025-32706 is a heap-based buffer overflow stemming from improper input validation (CWE-20) in the Microsoft Windows Common Log File System (CLFS) driver, triggered when a locally authenticated, low-privileged user gets the driver to process crafted log-related input. A successful exploit lets the attacker elevate from a limited local account to full system-level privileges, giving high impact to confidentiality, integrity, and availability on the host. All installations of the listed releases are affected — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (22H2, 23H2, 24H2), and Windows Server 2008, 2012, 2016, and 2019 — because the CLFS driver ships with these products by default. The vulnerability is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-13, and it was one of the five actively exploited zero-days fixed in Microsoft's May 2025 Patch Tuesday. Ransomware use is currently unknown, and public detection and mitigation scripts are available for defenders.

Do: Apply the May 2025 Windows security updates to all affected Windows 10, Windows 11, and Windows Server systems, prioritizing internet-facing and shared servers given confirmed in-the-wild exploitation; federal agencies must follow BOD 22-01 required actions or discontinue use if mitigations are unavailable. Until patched, restrict local logon and code execution rights to trusted users and watch for local privilege-escalation activity, using the publicly available detection and mitigation scripts as a starting point.

7.8
group max
2% KEV PoC ×2
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019
masson the order of hundreds of millions of installations (CLFS driver present by default on all affected Windows 10, 11, and Server releases)
CVE-2025-30398
Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

NVD description · AI analysis pending
8.1<1%
  • microsoft nuance powerscribe 360
  • microsoft nuance powerscribe one
Full article566 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, May 13, 2025 16:38

Microsoft has released its monthly security update for May of 2025 which includes 78 vulnerabilities affecting a range of products, including 11 that Microsoft marked as “critical”.  

Microsoft noted five vulnerabilities that have been observed to be exploited in the wild. CVE-2025-30397 is a remote code execution vulnerability in the Microsoft Scripting Engine. There were also four elevation of privilege vulnerabilities being actively exploited, CVE-2025-32709, CVE-2025-30400, CVE-2025-32701 and CVE-2025-32706 affecting the Ancillary Function Driver for WinSock, the DWM Core Library and the Windows Common Log File System Driver.  

The eleven "critical” entries consist of five remote code execution (RCE) vulnerabilities, four elevation of privilege vulnerabilities, one information disclosure vulnerability and one spoofing vulnerability. Three of the critical vulnerabilities have been marked as "Exploitation more likely": CVE-2025-30386 --a Microsoft Office RCE vulnerability, CVE-2025-30390 --an Azure ML Compute elevation of privilege vulnerability, and CVE-2025-30398 – a Nuance PowerScribe 360 information disclosure vulnerability.  

The most notable of the “critical” vulnerabilities listed affect Microsoft Office. CVE-2025-30386 is a RCE vulnerability with base CVSS 3.1 score of 8.3. To successfully exploit CVE-2025-30386, an attacker could send a victim an email, and without the victim clicking the link, viewing or interacting with the email, trigger a use-after-free scenario, allowing arbitrary code to be executed. Microsoft has assessed that the attack complexity is “Low”, and exploitation is “More likely”. Another RCE vulnerability affecting Microsoft Office, CVE-2025-30377, has a CVSS 3.1 base score of 8.4, and has been assessed an attack complexity of “Low”, but exploitation is considered “Less Likely”. 

Two RCE vulnerabilities affect the Remote Desktop Client. CVE-2025-29966 and CVE-2025-29967 are both Heap-cased Buffer Overflow vulnerabilities with CVSS 3.1 base scores of 8.8 with “Low” attack complexity and exploitation “Less Likely”. An attacker controlling a Remote Desktop Server could trigger the buffer overflow in a vulnerable when a vulnerable Remote Desktop Client connects to the server. 

CVE-2025-29833 is a RCE affecting the Virtual Machine Bus. This is a Time-of-check Time-of-use (TOCTOU) Race Condition which has been assessed an attack complexity of “High” and exploitation is “Less Likely”. 

Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that exploitation is "More likely": 

  • CVE-2025-24063 - Kernel Streaming Service Driver Elevation of Privilege Vulnerability 
  • CVE-2025-29841 - Universal Print Management Service Elevation of Privilege Vulnerability 
  • CVE-2025-29971 - Web Threat Defense (WTD.sys) Denial of Service Vulnerability 
  • CVE-2025-29976 - Microsoft SharePoint Server Elevation of Privilege Vulnerability 
  • CVE-2025-30382 - Microsoft SharePoint Server Remote Code Execution Vulnerability 
  • CVE-2025-30385 - Windows Common Log File System Driver Elevation of Privilege Vulnerability 
  • CVE-2025-30388 - Windows Graphics Component Remote Code Execution Vulnerability


A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page.  

In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org. 

The rules included in this release that protect against the exploitation of many of these vulnerabilities are 64848-64867. There are also these Snort 3 rules: 64852-64853, 301192-301200, and 301203 

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-may-2025-snort-rules-and-prominent-vulnerabilities/