PatchSiren

Microsoft CVE debriefs · Page 62

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2025-05-13

CVE-2025-30388

CVE-2025-30388 is a high-severity Windows vulnerability affecting Win32K GRFX. Microsoft describes it as a heap-based buffer overflow that could allow an unauthorized attacker to execute code locally. The CVSS vector indicates local access and user interaction are required, but the impact is high because confidentiality, integrity, and availability are all rated high in the supplied record.

HIGH Microsoft CVE published 2025-05-13

CVE-2025-30386

CVE-2025-30386 is a Microsoft Office use-after-free vulnerability that can allow an unauthorized attacker to execute code locally. NVD rates it HIGH (CVSS 8.4), and the affected scope includes multiple Office product lines, including Microsoft 365 Apps, Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Office for Android as listed in NVD.

Known exploited Microsoft CVE published 2025-05-13

CVE-2025-32709

CVE-2025-32709 is a Microsoft Windows vulnerability in the Ancillary Function Driver for WinSock described as a use-after-free issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-13, which makes it a high-priority issue for defenders. The provided source set does not include a CVSS score, so operational urgency should be driven by the known-exploitation status and Microsoft/CISA [truncated]

Known exploited Microsoft CVE published 2025-05-13

CVE-2025-32706

CVE-2025-32706 is a Microsoft Windows Common Log File System (CLFS) driver heap-based buffer overflow. CISA listed it in the Known Exploited Vulnerabilities catalog on 2025-05-13, which makes it a high-priority issue for defenders even though the supplied corpus does not provide a CVSS score or exploitation details.

Known exploited Microsoft CVE published 2025-05-13

CVE-2025-32701

CVE-2025-32701 is a Microsoft Windows Common Log File System (CLFS) driver use-after-free vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-05-13. Because it is a known exploited issue, organizations should treat remediation as urgent and follow Microsoft’s guidance and CISA’s mitigation instructions.

Known exploited Microsoft CVE published 2025-05-13

CVE-2025-30400

CVE-2025-30400 is a Microsoft Windows vulnerability in the DWM Core Library that CISA added to its Known Exploited Vulnerabilities (KEV) catalog on 2025-05-13. Because it is KEV-listed, defenders should treat it as a high-priority remediation item and work toward closure by the CISA due date of 2025-06-03, using Microsoft’s guidance and applicable CISA instructions.

Known exploited Microsoft CVE published 2025-05-13

CVE-2025-30397

CVE-2025-30397 is a Microsoft Windows Scripting Engine type confusion vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-05-13. Because CISA lists it as known exploited, defenders should treat it as a high-priority remediation item and follow Microsoft’s vendor guidance without delay. The supplied source corpus does not provide exploit mechanics, affected builds, or a CVSS score.

Known exploited Microsoft CVE published 2025-04-17

CVE-2025-24054

CVE-2025-24054 is a Microsoft Windows vulnerability described as an NTLM hash disclosure spoofing issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-04-17, which means defenders should treat it as actively exploited and prioritize remediation using Microsoft guidance.

HIGH Microsoft CVE published 2025-04-08

CVE-2025-26687

CVE-2025-26687 is a Microsoft-reported use-after-free issue in Windows Win32K - GRFX. Microsoft and NVD classify it as a high-severity flaw that can be abused by an unauthorized attacker to elevate privileges, with user interaction required. The NVD record also maps the issue to multiple Windows versions and some Microsoft Office CPEs, so administrators should verify exposure against Microsoft’s advisory [truncated]

Known exploited Microsoft CVE published 2025-04-08

CVE-2025-29824

CVE-2025-29824 is a Microsoft Windows Common Log File System (CLFS) Driver use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-04-08. CISA marked it as known to be used in ransomware campaigns and set a remediation due date of 2025-04-29. Because it is a KEV-listed issue, defenders should treat it as actively exploited and prioritize vendor-guided remediation.

Known exploited Microsoft CVE published 2025-03-11

CVE-2025-26633

CVE-2025-26633 is a Microsoft Windows Management Console (MMC) improper neutralization vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-03-11. Because it is officially tracked as actively exploited and marked with known ransomware campaign use, it deserves immediate defensive attention even though the supplied source corpus does not include a CVSS score or full exploit details.

Known exploited Microsoft CVE published 2025-03-11

CVE-2025-24993

CVE-2025-24993 is a Microsoft Windows NTFS heap-based buffer overflow vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-03-11. Because it is listed in KEV, organizations should treat it as actively exploited and prioritize mitigation and patching ahead of routine update cycles. CISA set a remediation due date of 2025-04-01.

Known exploited Microsoft CVE published 2025-03-11

CVE-2025-24991

CVE-2025-24991 is a Microsoft Windows NTFS out-of-bounds read vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-03-11. Because it is tracked as known exploited, defenders should treat it as an urgent remediation item and follow Microsoft’s update guidance and CISA’s required actions without delay.

Known exploited Microsoft CVE published 2025-03-11

CVE-2025-24985

CVE-2025-24985 is a Microsoft Windows Fast FAT File System Driver integer overflow vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-03-11. Because it is in KEV, defenders should treat it as an active-risk issue and prioritize vendor guidance and mitigation planning rather than routine patch scheduling.

Known exploited Microsoft CVE published 2025-03-11

CVE-2025-24984

CVE-2025-24984 is a Microsoft Windows NTFS information disclosure vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-03-11. Because it is on the KEV list, defenders should treat it as a confirmed-exploitation issue and prioritize remediation using vendor guidance and available mitigations.

Known exploited Microsoft CVE published 2025-03-11

CVE-2025-24983

CVE-2025-24983 is a Microsoft Windows Win32k use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-03-11. The supplied corpus does not include exploit details, affected versions, or a CVSS score, but the KEV listing means it should be treated as an urgent patching priority for Windows environments.

Known exploited Microsoft CVE published 2025-03-03

CVE-2018-8639

CVE-2018-8639 is a Microsoft Windows Win32k improper resource shutdown or release vulnerability. CISA lists it in the Known Exploited Vulnerabilities catalog, marks it as known ransomware campaign use, and sets a remediation due date of 2025-03-24. Treat this as an urgent patching and mitigation item for Windows environments.

Known exploited Microsoft CVE published 2025-02-25

CVE-2024-49035

CVE-2024-49035 is an improper access control vulnerability in Microsoft Partner Center that CISA added to its Known Exploited Vulnerabilities catalog on 2025-02-25. Because it is on the KEV list, defenders should treat it as a priority exposure even though the supplied corpus does not include a CVSS score or deeper technical exploitation detail. CISA’s required action is to apply Microsoft mitigations, fo [truncated]

Known exploited Microsoft CVE published 2025-02-21

CVE-2025-24989

CVE-2025-24989 is a Microsoft Power Pages improper access control vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-02-21. Because it is on the KEV list, defenders should treat it as a high-priority issue even though the supplied corpus does not include a CVSS score or deeper technical impact details. CISA's required action is to apply vendor mitigations, follow BOD 22-0 [truncated]

Known exploited Microsoft CVE published 2025-02-11

CVE-2025-21418

CVE-2025-21418 is a Microsoft Windows vulnerability in the Ancillary Function Driver for WinSock described as a heap-based buffer overflow. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-11, which means defenders should treat it as an actively relevant remediation item rather than a routine advisory. The CISA record directs organizations to apply vendor mitigations or discontinue [truncated]

Known exploited Microsoft CVE published 2025-02-11

CVE-2025-21391

CVE-2025-21391 is a Microsoft Windows Storage link-following vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-02-11. Because it is in KEV, defenders should treat it as an urgent remediation item and follow Microsoft’s guidance as soon as possible.

Known exploited Microsoft CVE published 2025-02-06

CVE-2024-21413

CVE-2024-21413 is a Microsoft Outlook improper input validation vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-02-06. That KEV listing is the key risk signal here: it means the flaw is known to be exploited in real-world environments, so affected Outlook deployments should be treated as urgent remediation candidates.

Known exploited Microsoft CVE published 2025-02-04

CVE-2024-29059

CVE-2024-29059 is a Microsoft .NET Framework information disclosure vulnerability that CISA added to the Known Exploited Vulnerabilities (KEV) catalog on 2025-02-04. Because it is KEV-listed, organizations should treat it as a remediation priority and follow Microsoft’s guidance as referenced by CISA.

HIGH Microsoft CVE published 2025-01-14

CVE-2025-21402

A remote code execution vulnerability in Microsoft Office OneNote for macOS, published by Microsoft on January 14, 2025, and last modified on May 19, 2026. The vulnerability allows an attacker to execute arbitrary code on affected systems through user interaction with a malicious OneNote document. Microsoft has released patches for this vulnerability. The CVSS 3.1 score of 7.8 (HIGH) reflects local attack [truncated]

HIGH Microsoft CVE published 2025-01-14

CVE-2025-21361

CVE-2025-21361 is a high-severity remote code execution vulnerability in Microsoft Outlook affecting macOS platforms. The vulnerability was published on January 14, 2025, and last modified on May 19, 2026. Microsoft has released patches and vendor guidance to address this issue. The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH severity) with a vector of AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicati [truncated]

HIGH Microsoft CVE published 2025-01-14

CVE-2025-21338

A remote code execution vulnerability exists in Microsoft GDI+ (Graphics Device Interface Plus), a Windows component responsible for rendering images and graphics. The vulnerability allows an attacker to execute arbitrary code on affected systems. The CVSS v3.1 score of 7.8 (HIGH) reflects local attack vector with low complexity, requiring local access but no user interaction. The vulnerability was publis [truncated]

Known exploited Microsoft CVE published 2025-01-14

CVE-2025-21335

CVE-2025-21335 is a Microsoft Windows Hyper-V NT Kernel Integration VSP use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities (KEV) catalog on 2025-01-14. Because it is in KEV, defenders should treat it as a high-priority remediation item and follow Microsoft’s vendor guidance and CISA’s required-action timeline.

Known exploited Microsoft CVE published 2025-01-14

CVE-2025-21334

CVE-2025-21334 is a Microsoft Windows Hyper-V NT Kernel Integration VSP use-after-free vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14, which means defenders should treat it as a high-priority issue even though no CVSS score was provided in the supplied record. The safest response is to follow Microsoft’s guidance, apply any available remediation as soon as possib [truncated]

Known exploited Microsoft CVE published 2025-01-14

CVE-2025-21333

CVE-2025-21333 is a Microsoft Windows Hyper-V NT Kernel Integration VSP heap-based buffer overflow. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14, so defenders should treat it as a high-priority issue for Windows systems that use the affected virtualization component. The supplied corpus does not include full vendor advisory text or a CVSS score, so remediation guidance here i [truncated]

Known exploited Microsoft CVE published 2024-12-16

CVE-2024-35250

CVE-2024-35250 is a Microsoft Windows kernel-mode driver untrusted pointer dereference vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-12-16. Because it is in KEV, defenders should treat it as a high-priority remediation item and follow Microsoft’s update guidance as soon as possible.