Microsoft Addresses 72 Vulnerabilities in May 2025 Patch Tuesday, Including 5 Exploited Zero-Days

Microsoft Addresses 72 Vulnerabilities in May 2025 Patch Tuesday, Including 5 Exploited Zero-Days

Microsoft has rolled out its Patch Tuesday updates for May 2025, addressing 78 security flaws across its suite of products, with five of them identified as actively exploited zero-day vulnerabilities.

The latest updates span a broad array of Microsoft software, including Windows, Office, Azure, Visual Studio, and others. Users and administrators are strongly advised to apply these patches without delay to safeguard systems against potential threats.

The vulnerabilities tackled this month include 29 related to Remote Code Execution (RCE), 18 involving Elevation of Privileges (EoP), 14 Information Disclosure flaws, 7 Denial of Service issues, 2 Spoofing vulnerabilities, and 2 Security Feature Bypasses.

Zero-Day Vulnerabilities Under Active Exploitation

Microsoft has patched five zero-day vulnerabilities that were found to be under active attack, posing significant risk to both individuals and organizations. These include:

  • CVE-2025-30397 (Microsoft Scripting Engine) – This critical flaw, with a CVSS score of 7.5, allows remote attackers to run arbitrary code through malicious web content. It is already being exploited, and swift patching is recommended.
  • CVE-2025-30400 (Windows DWM) – Scoring 7.8 on the CVSS scale, this vulnerability in the Desktop Window Manager (DWM) allows attackers to escalate privileges. There are confirmed active exploits.
  • CVE-2025-32701 (Windows Common Log File System Driver) – A privilege escalation flaw, rated 7.8, which has been actively exploited and jeopardizes system security.
  • CVE-2025-32706 (Windows Common Log File System Driver) – Another 7.8-rated privilege escalation issue, which is being actively exploited and needs urgent attention.
  • CVE-2025-32709 (Windows Ancillary Function Driver for WinSock) – This vulnerability, with a CVSS score of 7.8, also facilitates privilege escalation and has been confirmed to be exploited in the wild.

Vulnerabilities in Office and Windows

Microsoft Office, particularly Excel and SharePoint, has been affected by numerous vulnerabilities, many with critical severity ratings of 7.8 or higher. Examples include:

  • CVE-2025-29976 (Microsoft Office SharePoint) – A flaw rated 7.8, which could allow attackers to escalate privileges locally.
  • CVE-2025-30393 (Microsoft Office Excel) – A dangerous vulnerability in Excel, rated 7.8, that could lead to remote code execution when users open specially crafted files.

The updates also address significant flaws in Windows components, including the Windows Kernel, Remote Desktop Gateway Service, and Routing and Remote Access Service (RRAS). Of particular note, CVE-2025-24063 (Windows Kernel), rated 7.8, is flagged as “Exploitation More Likely,” underlining the urgency of applying the patch.

This comprehensive security update reinforces the importance of applying patches swiftly to protect systems and data from potential exploitation.

Security Flaws Addressed in Microsoft’s May 2025 Patch Tuesday Update

  • CVE-2025-29966: Remote Desktop Client Remote Code Execution – Critical
  • CVE-2025-29967: Remote Desktop Client Remote Code Execution – Critical
  • CVE-2025-30377: Microsoft Office Remote Code Execution – Critical
  • CVE-2025-30386: Microsoft Office Remote Code Execution – Critical
  • CVE-2025-29833: Microsoft Virtual Machine Bus (VMBus) Remote Code Execution – Critical
  • CVE-2025-26629: Microsoft Office Remote Code Execution – Important
  • CVE-2025-26646: .NET, Visual Studio, and Visual Studio Build Tools Spoofing – Important
  • CVE-2025-26684: Microsoft Defender Elevation of Privilege – Important
  • CVE-2025-29959: Windows Routing and Remote Access Service (RRAS) Information Disclosure – Important
  • CVE-2025-29960: Windows Routing and Remote Access Service (RRAS) Information Disclosure – Important
  • CVE-2025-29964: Windows Media Remote Code Execution – Important
  • CVE-2025-29968: Active Directory Certificate Services (AD CS) Denial of Service – Important
  • CVE-2025-29969: MS-EVEN RPC Remote Code Execution – Important
  • CVE-2025-29970: Microsoft Brokering File System Elevation of Privilege – Important
  • CVE-2025-29973: Microsoft Azure File Sync Elevation of Privilege – Important
  • CVE-2025-29971: Web Threat Defense (WTD.sys) Denial of Service – Important
  • CVE-2025-29975: Microsoft PC Manager Elevation of Privilege – Important
  • CVE-2025-29976: Microsoft SharePoint Server Elevation of Privilege – Important
  • CVE-2025-29977: Microsoft Excel Remote Code Execution – Important
  • CVE-2025-29978: Microsoft PowerPoint Remote Code Execution – Important
  • CVE-2025-29979: Microsoft Excel Remote Code Execution – Important
  • CVE-2025-30375: Microsoft Excel Remote Code Execution – Important
  • CVE-2025-30376: Microsoft Excel Remote Code Execution – Important
  • CVE-2025-30378: Microsoft SharePoint Server Remote Code Execution – Important
  • CVE-2025-30379: Microsoft Excel Remote Code Execution – Important
  • CVE-2025-30381: Microsoft Excel Remote Code Execution – Important
  • CVE-2025-30382: Microsoft SharePoint Server Remote Code Execution – Important
  • CVE-2025-30383: Microsoft Excel Remote Code Execution – Important
  • CVE-2025-30384: Microsoft SharePoint Server Remote Code Execution – Important
  • CVE-2025-30387: Document Intelligence Studio On-Prem Elevation of Privilege – Important
  • CVE-2025-27468: Windows Kernel-Mode Driver Elevation of Privilege – Important
  • CVE-2025-30393: Microsoft Excel Remote Code Execution – Important
  • CVE-2025-29826: Microsoft Dataverse Elevation of Privilege – Important
  • CVE-2025-30394: Windows Remote Desktop Gateway (RD Gateway) Denial of Service – Important
  • CVE-2025-30400: Microsoft DWM Core Library Elevation of Privilege – Important
  • CVE-2025-32701: Windows Common Log File System Driver Elevation of Privilege – Important
  • CVE-2025-32703: Visual Studio Information Disclosure – Important
  • CVE-2025-32706: Windows Common Log File System Driver Elevation of Privilege – Important
  • CVE-2025-21264: Visual Studio Code Security Feature Bypass – Important
  • CVE-2025-32709: Windows Ancillary Function Driver for WinSock Elevation of Privilege – Important
  • CVE-2025-26677: Windows Remote Desktop Gateway (RD Gateway) Denial of Service – Important
  • CVE-2025-27488: Microsoft Windows Hardware Lab Kit (HLK) Elevation of Privilege – Important
  • CVE-2025-26685: Microsoft Defender for Identity Spoofing – Important
  • CVE-2025-29829: Windows Trusted Runtime Interface Driver Information Disclosure – Important
  • CVE-2025-29830: Windows Routing and Remote Access Service (RRAS) Information Disclosure – Important
  • CVE-2025-29831: Windows Remote Desktop Services Remote Code Execution – Important
  • CVE-2025-29832: Windows Routing and Remote Access Service (RRAS) Information Disclosure – Important
  • CVE-2025-29835: Windows Remote Access Connection Manager Information Disclosure – Important
  • CVE-2025-29836: Windows Routing and Remote Access Service (RRAS) Information Disclosure – Important
  • CVE-2025-29837: Windows Installer Information Disclosure – Important
  • CVE-2025-29838: Windows ExecutionContext Driver Elevation of Privilege – Important
  • CVE-2025-29839: Windows Multiple UNC Provider Driver Information Disclosure – Important
  • CVE-2025-29840: Windows Media Remote Code Execution – Important
  • CVE-2025-29841: Universal Print Management Service Elevation of Privilege – Important
  • CVE-2025-29842: UrlMon Security Feature Bypass – Important
  • CVE-2025-29954: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service – Important
  • CVE-2025-29955: Windows Hyper-V Denial of Service – Important
  • CVE-2025-29956: Windows SMB Information Disclosure – Important
  • CVE-2025-29957: Windows Deployment Services Denial of Service – Important
  • CVE-2025-29958: Windows Routing and Remote Access Service (RRAS) Information Disclosure – Important
  • CVE-2025-29961: Windows Routing and Remote Access Service (RRAS) Information Disclosure – Important
  • CVE-2025-29962: Windows Media Remote Code Execution – Important
  • CVE-2025-29963: Windows Media Remote Code Execution – Important
  • CVE-2025-29974: Windows Kernel Information Disclosure – Important
  • CVE-2025-30385: Windows Common Log File System Driver Elevation of Privilege – Important
  • CVE-2025-30388: Windows Graphics Component Remote Code Execution – Important
  • CVE-2025-30397: Scripting Engine Memory Corruption Remote Code Execution – Important
  • CVE-2025-32702: Visual Studio Remote Code Execution – Important
  • CVE-2025-32704: Microsoft Excel Remote Code Execution – Important
  • CVE-2025-32705: Microsoft Outlook Remote Code Execution – Important
  • CVE-2025-32707: NTFS Elevation of Privilege – Important
  • CVE-2025-24063: Kernel Streaming Service Driver Elevation of Privilege – Important

Microsoft urges both users and IT administrators to promptly install the latest updates via Windows Update or enterprise management solutions. With an active zero-day vulnerability in the wild, delaying the application of these patches could expose systems to real-time threats and attacks.

As cyber threats continue to evolve, the May 2025 Patch Tuesday release underscores the importance of maintaining an active security posture. Ensure your systems are patched without delay to protect against these vulnerabilities and strengthen your defenses against potential exploitation.

Additional Key Security Updates:

  • Fortinet has issued patches for several products, including a critical zero-day vulnerability that is actively being exploited.
  • SAP has rolled out updates for various products, addressing a critical remote code execution (RCE) zero-day flaw.
  • Apple has released security fixes for iOS, iPadOS, and macOS, addressing vulnerabilities in its ecosystem.
  • Ivanti has deployed patches for ITSM, Cloud Security, and Neurons to resolve vulnerabilities.
  • Zoom has patched several vulnerabilities in its workplace apps, including privilege escalation flaws.
  • VMware has addressed an XSS vulnerability in Aria and other security flaws in VMware Tools.

Be sure to act quickly on these updates to ensure your systems are secure against evolving cyber threats.

More Articles & Posts