Microsoft Patch Tuesday – May 2025: 72 Vulnerabilities Fixed, Including 5 Actively Exploited Zero-Day

Microsoft has released its Patch Tuesday updates for May 2025, addressing a total of 78 vulnerabilities across its product ecosystem, with five identified as actively exploited zero-day flaws.

The updates affect products including Windows, Microsoft Office, Azure, Visual Studio, and more. Users and system administrators are strongly urged to apply these patches immediately.

🧩 Vulnerability Breakdown

Out of 72 vulnerabilities, Microsoft addressed:

  • πŸ› οΈ 29 Remote Code Execution
  • ⬆️ 18 Elevation of Privilege
  • πŸ” 14 Information Disclosure
  • 🚫 7 Denial of Service
  • πŸ•΅οΈβ€β™‚οΈ 2 Spoofing
  • 🧱 2 Security Feature Bypass

πŸ”₯ Actively Exploited Zero-Day Vulnerabilities

The five zero-days patched this month are:

1. CVE-2025-30397 (Microsoft Scripting Engine)

  • CVSS Score: 7.5
  • Impact: Remote Code Execution via malicious web content
  • Status: Exploited in the wild

2. CVE-2025-30400 (Windows DWM)

  • CVSS Score: 7.8
  • Impact: Local Privilege Escalation
  • Status: Actively exploited

3. CVE-2025-32701 (Windows Common Log File System Driver)

  • CVSS Score: 7.8
  • Impact: Privilege Escalation
  • Status: Exploited

4. CVE-2025-32706 (Windows Common Log File System Driver)

  • CVSS Score: 7.8
  • Impact: Privilege Escalation
  • Status: Exploited

5. CVE-2025-32709 (Windows Ancillary Function Driver for WinSock)

  • CVSS Score: 7.8
  • Impact: Privilege Escalation
  • Status: Exploited

πŸ—‚οΈ Office and Windows Vulnerabilities

Multiple high-risk vulnerabilities were found in Office and Windows components:

  • CVE-2025-29976 (SharePoint) – Elevation of Privilege
  • CVE-2025-30393 (Excel) – Remote Code Execution
  • CVE-2025-24063 (Windows Kernel) – β€œExploitation More Likely”

πŸ“‹ Sample Vulnerability Table

CVE NumberComponentImpactSeverity
CVE-2025-29966Remote Desktop ClientRemote Code ExecutionCritical
CVE-2025-30377Microsoft OfficeRemote Code ExecutionCritical
CVE-2025-26684Microsoft DefenderElevation of PrivilegeImportant
CVE-2025-29959RRASInformation DisclosureImportant
CVE-2025-29968Active Directory Certificate ServicesDenial of ServiceImportant
CVE-2025-29979Microsoft ExcelRemote Code ExecutionImportant
CVE-2025-26685Defender for IdentitySpoofingImportant
CVE-2025-32703Visual StudioInformation DisclosureImportant
CVE-2025-21264VS CodeSecurity Feature BypassImportant

πŸ”½ The full list includes 78 vulnerabilities. Visit the full article for the complete table:
Microsoft Patch Tuesday – May 2025


βœ… Recommendations

  • Update all Windows and Office installations ASAP
  • Monitor your systems for CVE exploit indicators
  • Use vulnerability scanners to verify patch deployment
  • Stay informed about Microsoft Patch Tuesday updates every month

Leave a Reply

Your email address will not be published. Required fields are marked *