Microsoft Patch Tuesday for May 2025 — Snort rules and prominent vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-29967 | Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 group max | 1% |
| — | ||
| CVE-2025-29841 | Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally. NVD description · AI analysis pending | 7.0 | <1% |
| — | ||
| CVE-2025-29966 | Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2025-29971 | Out-of-Bounds Read DoS in Microsoft Windows 11 Web Threat Defense (WTD.sys) Driver CVE-2025-29971 is an out-of-bounds read (CWE-125) in WTD.sys, the kernel driver behind Microsoft's Web Threat Defense component in Windows 11. A remote, unauthenticated attacker can trigger the flaw by sending crafted network traffic that the driver inspects, causing it to read beyond a buffer's bounds and crash. The impact is denial of service only: the CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) reflects high availability impact with no confidentiality or integrity loss, and a successful attack could crash or hang the affected Windows host. All Windows 11 22H2, 23H2, and 24H2 systems running the Web Threat Defense driver are affected. As of the May 2025 Patch Tuesday coverage there is no known public proof-of-concept, the flaw is not in CISA's KEV, and no in-the-wild exploitation has been reported, although EPSS assigns a 64.4% probability of exploitation within 30 days (99th percentile). Do: Apply the Windows security updates released in the May 2025 Patch Tuesday for Windows 11 22H2, 23H2, and 24H2, which remediate WTD.sys, and confirm the updated driver is present on hosts. No workaround is documented, so until patching completes, consider limiting untrusted inbound/network exposure to systems running the affected driver. Prioritize internet-facing and high-availability Windows 11 hosts given the elevated EPSS (64.4% within 30 days), and monitor vendor advisories for exploitation updates. | 7.5 | 64% |
| mass~hundreds of millions of Windows 11 devices (22H2/23H2/24H2 installed base) | ||
| CVE-2025-30382 +1 in the same advisory: …29976 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 7.8 | 2% |
| — | ||
| CVE-2025-30386 +1 in the same advisory: …30377 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-30385 | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-30388 | Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 7.8 | 4% |
| — | ||
| CVE-2025-30390 | Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2025-32706 | Heap-Based Buffer Overflow in Windows CLFS Driver Enables Local Privilege Escalation CVE-2025-32706 is a heap-based buffer overflow stemming from improper input validation (CWE-20) in the Microsoft Windows Common Log File System (CLFS) driver, triggered when a locally authenticated, low-privileged user gets the driver to process crafted log-related input. A successful exploit lets the attacker elevate from a limited local account to full system-level privileges, giving high impact to confidentiality, integrity, and availability on the host. All installations of the listed releases are affected — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (22H2, 23H2, 24H2), and Windows Server 2008, 2012, 2016, and 2019 — because the CLFS driver ships with these products by default. The vulnerability is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-13, and it was one of the five actively exploited zero-days fixed in Microsoft's May 2025 Patch Tuesday. Ransomware use is currently unknown, and public detection and mitigation scripts are available for defenders. Do: Apply the May 2025 Windows security updates to all affected Windows 10, Windows 11, and Windows Server systems, prioritizing internet-facing and shared servers given confirmed in-the-wild exploitation; federal agencies must follow BOD 22-01 required actions or discontinue use if mitigations are unavailable. Until patched, restrict local logon and code execution rights to trusted users and watch for local privilege-escalation activity, using the publicly available detection and mitigation scripts as a starting point. | 7.8 group max | 2% | KEV PoC ×2 |
| masson the order of hundreds of millions of installations (CLFS driver present by default on all affected Windows 10, 11, and Server releases) | |
| CVE-2025-30398 | Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. NVD description · AI analysis pending | 8.1 | <1% |
| — |
Full article566 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, May 13, 2025 16:38
Microsoft has released its monthly security update for May of 2025 which includes 78 vulnerabilities affecting a range of products, including 11 that Microsoft marked as “critical”.
Microsoft noted five vulnerabilities that have been observed to be exploited in the wild. CVE-2025-30397 is a remote code execution vulnerability in the Microsoft Scripting Engine. There were also four elevation of privilege vulnerabilities being actively exploited, CVE-2025-32709, CVE-2025-30400, CVE-2025-32701 and CVE-2025-32706 affecting the Ancillary Function Driver for WinSock, the DWM Core Library and the Windows Common Log File System Driver.
The eleven "critical” entries consist of five remote code execution (RCE) vulnerabilities, four elevation of privilege vulnerabilities, one information disclosure vulnerability and one spoofing vulnerability. Three of the critical vulnerabilities have been marked as "Exploitation more likely": CVE-2025-30386 --a Microsoft Office RCE vulnerability, CVE-2025-30390 --an Azure ML Compute elevation of privilege vulnerability, and CVE-2025-30398 – a Nuance PowerScribe 360 information disclosure vulnerability.
The most notable of the “critical” vulnerabilities listed affect Microsoft Office. CVE-2025-30386 is a RCE vulnerability with base CVSS 3.1 score of 8.3. To successfully exploit CVE-2025-30386, an attacker could send a victim an email, and without the victim clicking the link, viewing or interacting with the email, trigger a use-after-free scenario, allowing arbitrary code to be executed. Microsoft has assessed that the attack complexity is “Low”, and exploitation is “More likely”. Another RCE vulnerability affecting Microsoft Office, CVE-2025-30377, has a CVSS 3.1 base score of 8.4, and has been assessed an attack complexity of “Low”, but exploitation is considered “Less Likely”.
Two RCE vulnerabilities affect the Remote Desktop Client. CVE-2025-29966 and CVE-2025-29967 are both Heap-cased Buffer Overflow vulnerabilities with CVSS 3.1 base scores of 8.8 with “Low” attack complexity and exploitation “Less Likely”. An attacker controlling a Remote Desktop Server could trigger the buffer overflow in a vulnerable when a vulnerable Remote Desktop Client connects to the server.
CVE-2025-29833 is a RCE affecting the Virtual Machine Bus. This is a Time-of-check Time-of-use (TOCTOU) Race Condition which has been assessed an attack complexity of “High” and exploitation is “Less Likely”.
Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that exploitation is "More likely":
- CVE-2025-24063 - Kernel Streaming Service Driver Elevation of Privilege Vulnerability
- CVE-2025-29841 - Universal Print Management Service Elevation of Privilege Vulnerability
- CVE-2025-29971 - Web Threat Defense (WTD.sys) Denial of Service Vulnerability
- CVE-2025-29976 - Microsoft SharePoint Server Elevation of Privilege Vulnerability
- CVE-2025-30382 - Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2025-30385 - Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2025-30388 - Windows Graphics Component Remote Code Execution Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page.
In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.
The rules included in this release that protect against the exploitation of many of these vulnerabilities are 64848-64867. There are also these Snort 3 rules: 64852-64853, 301192-301200, and 301203
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-may-2025-snort-rules-and-prominent-vulnerabilities/