CyberzSOC

Publication detail
← Back to advisories & guidance

Microsoft Releases May 2025 Security Updates ↗ source

May 14, 2025 JPCERT/CC Alert

Summary

Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. According to Microsoft, among the vulnerabilities, the following vulnerability have been confirmed to be exploited in the wild. Please consider applying the security update programs by referring to the information provided by Microsoft. Scripting Engine Memory Corruption Vulnerability Microsoft DWM Core Library Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Please apply the security update programs through Microsoft Update, Windows Update, etc. If you have any information regarding this alert, please contact JPCERT/CC.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-30400 7.8 High Microsoft Windows Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2025-32701 7.8 High Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileg…
CVE-2025-32706 7.8 High Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elev…
CVE-2025-32709 7.8 High Microsoft Windows Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privil…
CVE-2025-30397 7.5 High Microsoft Windows Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.