CVE-2025-30386 Microsoft Office Remote Code Execution Vulnerability
Published May 13, 2025
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Published May 13, 2025
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Published May 13, 2025
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Published May 13, 2025
Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.
Published May 13, 2025
Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
Published May 13, 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
Published May 13, 2025
Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.
Published May 13, 2025
Corrected CVE title. This is an informational change only.
Published May 13, 2025
Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
Published May 13, 2025
Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.
Published May 13, 2025
Access of resource using incompatible type (‘type confusion’) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.