Microsoft's Patch Tuesday closes 72 vulnerabilities, including 5 zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-36033 | Local Privilege Escalation in Microsoft Windows DWM Core Library A flaw in the Windows Desktop Window Manager (DWM) Core Library — classified as an untrusted pointer dereference/memory-bounds issue (CWE-822, CWE-119) — allows a local, low-privileged attacker to elevate privileges on affected Windows systems. Per the CVSS vector, exploitation requires only the ability to execute code on the target (local vector, low privileges) and no user interaction. A successful attacker runs code with elevated privileges, gaining high-impact control of confidentiality, integrity, and availability on the host, typically as a post-compromise escalation step after initial access. All systems running Windows 10 1809/21H2/22H2, Windows 11 21H2/22H2/23H2, Windows Server 2019, or Windows Server 2022 (including the 23H2 edition) are affected. The vulnerability is confirmed to be exploited in the wild: CISA added it to the KEV on 2023-11-14, Microsoft's November 2023 Patch Tuesday fixed it among three actively exploited zero-days, public coverage notes active exploitation including reported QakBot malware campaigns, and it carries an elevated EPSS of roughly 12% within 30 days (96th percentile). Do: Apply the November 2023 (November 14, 2023) cumulative Windows updates to all Windows 10 1809/21H2/22H2, Windows 11 21H2/22H2/23H2, Windows Server 2019, and Windows Server 2022 (including 23H2) systems, prioritizing servers, RDS hosts, and shared-use machines. Because the flaw is used as a post-compromise escalation step in the wild (KEV-listed, with public reporting tied to QakBot campaigns), assume possible compromise on unpatched endpoints and hunt for follow-on malware, credential theft, and persistence activity; verify patch levels across the fleet rather than relying on mitigations, as CISA lists patching per vendor instructions as the required action. | 7.8 | 12% | KEV |
| masshundreds of millions of Windows client and server endpoints (the Windows 10 1809+ through Windows 11 23H2 and Server 2019/2022 population; exact unpatched… | |
| CVE-2024-30051 | Elevation of Privilege in Microsoft Windows DWM Core Library (Actively Exploited) CVE-2024-30051 is a heap-based buffer overflow / out-of-bounds write (CWE-122, CWE-787) in the Windows Desktop Window Manager (DWM) Core Library that allows a local attacker to escalate privileges. It is triggered by locally executing crafted code that corrupts memory in the DWM component, requiring only low privileges and no user interaction (AV:L/AC:L/PR:L/UI:N). A successful exploit yields high-impact gains on the local system — typically elevation to elevated/SYSTEM rights, giving the attacker full control of confidentiality, integrity and availability on that host. Any organization running the affected Windows 10/11 client releases or Windows Server 2016/2019/2022 with the DWM component is exposed, which in practice means nearly every modern Windows endpoint. The flaw was a zero-day exploited in the wild before remediation: it was added to CISA KEV on 2024-05-14 with known ransomware use, and public reporting ties it to QakBot attack chains and Microsoft's May 2024 Patch Tuesday (which also fixed it alongside other exploited zero-days). Do: Apply Microsoft's May 2024 Patch Tuesday cumulative updates for every affected Windows 10/11 and Windows Server 2016/2019/2022 release immediately; per CISA KEV, apply vendor mitigations or discontinue use of affected systems if updates are unavailable. Prioritize endpoints and servers exposed to user-driven malware (email, web browsing) since the flaw is chained after initial access in QakBot and ransomware operations, and verify patched DWM/dwmcore binaries via the updated OS build. Monitor for local privilege-escalation activity and treat this as a high-priority patch alongside the other May 2024 exploited zero-days. | 7.8 | 6% | KEV ransomware |
| mass≈1 billion+ Windows 10/11 endpoints plus large Windows Server 2016/2019/2022 fleets (DWM is a core component present on effectively every affected Windows… | |
| CVE-2025-29792 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. NVD description · AI analysis pending | 7.3 | 1% |
| — | ||
| CVE-2025-29794 +1 in the same advisory: …29793 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 group max | 5% |
| — | ||
| CVE-2025-29813 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2025-29824 | Use-After-Free Privilege Escalation in Microsoft Windows CLFS Driver (Actively Exploited) CVE-2025-29824 is a use-after-free flaw (CWE-416) in the Windows Common Log File System (CLFS) kernel driver, scored 7.8 (High) with a local attack vector, low privileges required, and no user interaction. An authorized local attacker can trigger it by interacting with CLFS-managed log files in a way that references freed kernel memory. Successful exploitation elevates the attacker's local privileges, typically to SYSTEM, providing full control of the host that can be chained into ransomware deployment or lateral movement. Any unpatched system running the listed Windows 10, Windows 11, or Windows Server versions is affected. The flaw was exploited as a zero-day — reportedly by Play ransomware — before Microsoft shipped fixes in the April 2025 Patch Tuesday release; it was added to CISA's KEV catalog on 2025-04-08 with known ransomware use, and EPSS estimates a 13.9% probability of continued exploitation over 30 days (96th percentile). Do: Apply Microsoft's April 2025 Patch Tuesday security updates for your Windows version immediately — the vendor update is the only complete fix, and the flaw is on the KEV list with known ransomware use, so prioritize servers and endpoints used by privileged users. Until patched, limit untrusted local code execution and review hosts for post-exploitation privilege escalation; public detection and mitigation scripts (e.g., Vicarius) are available to help hunt for exploitation. Federal agencies must apply the vendor mitigations per BOD 22-01 deadlines or discontinue use of affected versions. | 7.8 | 14% | KEV ransomware PoC ×2 |
| massHundreds of millions of Windows devices worldwide | |
| CVE-2025-29827 | Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2025-29972 | Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2025-30382 +1 in the same advisory: …29976 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 7.8 | 2% |
| — | ||
| CVE-2025-30387 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network. Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2025-32706 | Heap-Based Buffer Overflow in Windows CLFS Driver Enables Local Privilege Escalation CVE-2025-32706 is a heap-based buffer overflow stemming from improper input validation (CWE-20) in the Microsoft Windows Common Log File System (CLFS) driver, triggered when a locally authenticated, low-privileged user gets the driver to process crafted log-related input. A successful exploit lets the attacker elevate from a limited local account to full system-level privileges, giving high impact to confidentiality, integrity, and availability on the host. All installations of the listed releases are affected — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (22H2, 23H2, 24H2), and Windows Server 2008, 2012, 2016, and 2019 — because the CLFS driver ships with these products by default. The vulnerability is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-13, and it was one of the five actively exploited zero-days fixed in Microsoft's May 2025 Patch Tuesday. Ransomware use is currently unknown, and public detection and mitigation scripts are available for defenders. Do: Apply the May 2025 Windows security updates to all affected Windows 10, Windows 11, and Windows Server systems, prioritizing internet-facing and shared servers given confirmed in-the-wild exploitation; federal agencies must follow BOD 22-01 required actions or discontinue use if mitigations are unavailable. Until patched, restrict local logon and code execution rights to trusted users and watch for local privilege-escalation activity, using the publicly available detection and mitigation scripts as a starting point. | 7.8 group max | 2% | KEV PoC ×2 |
| masson the order of hundreds of millions of installations (CLFS driver present by default on all affected Windows 10, 11, and Server releases) |
Full article914 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The company has addressed zero-day vulnerabilities for eight consecutive months without deeming any of them critical at the time of disclosure.
Listen to this article
0:00
Learn more.
Microsoft addressed 72 vulnerabilities affecting its core products and underlying systems, including five actively exploited zero-days across various Windows components, the company said in its latest security update Tuesday.
“This is now the eighth consecutive Patch Tuesday on which Microsoft has published zero-day vulnerabilities without evaluating any of them as critical severity at time of publication,” Adam Barnett, lead software engineer at Rapid7, said in an email.
The zero-days — CVE-2025-30397, CVE-2025-30400, CVE-2025-32701, CVE-2025-32706 and CVE-2025-32709 — all score in the range of 7.5 to 7.8 on the CVSS scale. Two of the zero-days, CVE-2025-32701 and CVE-2025-32706, are defects in the Windows Common Log File Driver System (CLFS), adding to an “ongoing dynasty where exploitation typically leads to elevation of privilege to SYSTEM,” Barnett said.
The Cybersecurity and Infrastructure Security Agency (CISA) added all five to its Known Exploited Vulnerabilities (KEV) list on Tuesday.
Mike Walters, president and co-founder of Action1, said attackers can exploit a pair of the new zero-days in CLFS to gain “full control to run arbitrary code, install malware, modify data or disable security protections. With low complexity and minimal privileges needed, these flaws pose a serious risk, especially given the confirmed in-the-wild exploitation.”
Barnett credited Microsoft’s Threat Intelligence Center for putting more effort into detecting and rooting out CLFS exploitation. “Of course, since Microsoft is aware of exploitation in the wild, we know that someone else got there first, and there’s no reason to suspect that threat actors will stop looking for ways to abuse CLFS any time soon.”
Zero-day exploits of CVE-2025-32701 and CVE-2025-32706 were likely part of post-compromise activity that was either targeted espionage or financially motivated activities, such as ransomware deployment, according to Satnam Narang, senior staff research engineer at Tenable.
In April, Microsoft said a ransomware group it tracks as Storm-2460 exploited a zero-day in the CLFS, CVE-2025-29824, against organizations in the IT and real estate sectors in the United States, the financial sector in Venezuela, a Spanish software company and the retail sector in Saudi Arabia.
One of the new zero-days, a use-after-free defect affecting Windows Desktop Window Manager (DWM), CVE-2025-30400, marks a slow and steady uptick in zero-day attacks targeting elevation of privilege vulnerabilities in the DWM Core Library for Windows, according to Narang.
“Prior to CVE-2025-30400, only two DWM elevation of privilege bugs were exploited as zero days — CVE-2024-30051 in 2024 and CVE-2023-36033 in 2023,” Narang said in an email.
The remaining zero-days in this month’s security update include: an elevation of privilege flaw in the Windows Ancillary Function Driver for Windows Sockets API (WinSock), CVE-2025-32709; and a scripting memory corruption defect in Microsoft Scripting Engine, CVE-2025-30397.
Although CVE-2025-30397 is a zero-day remote code execution vulnerability, broad exploitation is unlikely because the pre-requisites for exploitation are complicated, researchers said.
“While the attack requires user interaction and carries high complexity, it remains a viable avenue for advanced attackers, including nation-state actors, who are capable of developing reliable exploits,” said Alex Vovk, CEO and co-founder of Action1. “Active exploitation has already been observed in the wild, highlighting the urgency of a response.”
The batch of CVE disclosures and patches in Microsoft’s monthly security update include five critical vulnerabilities and 50 high-severity defects. The four most-critical software defects, according to initial CVSS scores, include CVE-2025-29813, CVE-2025-29827, CVE-2025-29972 and CVE-2025-30387.
Eighteen of the vulnerabilities in this month’s security update affect Microsoft Office and standalone Office products. All of the software defects affecting Microsoft Office are high-severity, and Microsoft designated three of those vulnerabilities — CVE-2025-29792, CVE-2025-29793 and CVE-2025-29794 — as “more likely” to be exploited.
Overall, Microsoft said eight of the vulnerabilities it patched this month are “more likely” to be exploited. This set of more concerning flaws includes a pair of high-severity software defects — CVE-2025-29976 and CVE-2025-30382 — that could allow for privilege escalation and remote code execution, respectively, in Microsoft SharePoint Server.
The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-may-2025/