Analysis of Microsoft Patch Tuesday updates - May 2025
Executive Summary
On Tuesday, May 13, 2025, Microsoft released its monthly security patch addressing 78 vulnerabilities across its products.
By severity:
- Important - 66;
- Critical - 11;
- Low - 1.
Exploited (Zero-Days) and Publicly Disclosed Vulnerabilities
Special attention should be paid to the following 7 vulnerabilities. Fixing them is the highest priority:
- CVE-2025-26685 (CVSS 6.5; Important) - Microsoft Defender for Identity Spoofing Vulnerability (Spoofing). Inadequate authentication in Microsoft Defender for Identity allows an unauthenticated attacker to impersonate another user or computer in the network.
- CVE-2025-30397 (CVSS 7.5; Important) - Scripting Engine Memory Corruption Vulnerability (Remote Code Execution). A type confusion vulnerability in Microsoft Scripting Engine allows a remote attacker to execute arbitrary code in the system.
- CVE-2025-30400 (CVSS 7.8; Important) - Microsoft DWM Core Library Elevation of Privilege Vulnerability (Elevation of Privilege). A Use-After-Free vulnerability in Desktop Window Manager allows a local authenticated attacker to elevate privileges.
- CVE-2025-32701 (CVSS 7.8; Important) - Windows Common Log File System Driver Elevation of Privilege Vulnerability (Elevation of Privilege). A Use-After-Free vulnerability in Common Log File System Driver allows a local authenticated attacker to elevate privileges.
- CVE-2025-32702 (CVSS 7.8; Important) - Visual Studio Remote Code Execution Vulnerability (Remote Code Execution). An error in Visual Studio ("Code injection") allows an unauthenticated attacker to execute code locally in the system.
- CVE-2025-32706 (CVSS 7.8; Important) - Windows Common Log File System Driver Elevation of Privilege Vulnerability (Elevation of Privilege). Incorrect input validation in the driver allows a local authenticated attacker to elevate privileges.
- CVE-2025-32709 (CVSS 7.8; Important) - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (Elevation of Privilege). CWE-416: Use-After-Free, which allows a local authenticated attacker to elevate privileges.
General Overview and trends
Microsoft’s May 2025 Patch Tuesday was particularly substantial, addressing 78 vulnerabilities. The distribution by severity shows that the majority (66) are classified as "Important", 11 vulnerabilities are classified as "Critical", and require immediate attention. Key trends observed this month include:
- Elevation of Privilege vulnerability mitigation: The majority of the fixes (especially among the priority ones) are aimed at mitigating Elevation of Privilege vulnerabilities. This indicates that Microsoft is continuing to strengthen the security of Windows and related components.
- Vulnerabilities in Microsoft Office and related applications: A large number of vulnerabilities (mainly Remote Code Execution) were discovered in Microsoft Office, including Excel and PowerPoint. This underscores the importance of regularly updating these applications, as they are often targeted by attackers.
- Vulnerabilities in cloud services: Fixes for Azure DevOps Server, Azure Automation, Azure Storage, and other cloud services indicate the growing complexity of ensuring security in cloud infrastructures.
- Remote Code Execution vulnerabilities: The significant number of vulnerabilities allowing remote code execution require special attention, as they can be used to compromise systems without requiring physical access.
- Vulnerabilities in Windows components: The discovery of vulnerabilities in key Windows components, such as Windows Media, Remote Desktop Services, and the Windows Kernel, underscores the need for a comprehensive approach to ensuring the security of the operating system. In general, the May 2025 Patch Tuesday demonstrates a wide range of vulnerabilities affecting various Microsoft products and services. It is recommended to prioritize the installation of updates, especially for vulnerabilities with a high severity rating and those that are actively being exploited.
Full List of Vulnerabilities
Below is a table of all vulnerabilities fixed this month.
| CVE | Title | Type | CVSS | Severity | Exploited | Publicly Disclosed |
|---|---|---|---|---|---|---|
| CVE-2025-30400 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | Yes | No |
| CVE-2025-32701 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | Yes | No |
| CVE-2025-32702 | Visual Studio Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | Yes |
| CVE-2025-32706 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | Yes | No |
| CVE-2025-32709 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | Yes | No |
| CVE-2025-30397 | Scripting Engine Memory Corruption Vulnerability | Remote Code Execution | 7.5 | Important | Yes | No |
| CVE-2025-26685 | Microsoft Defender for Identity Spoofing Vulnerability | Spoofing | 6.5 | Important | No | Yes |
| CVE-2025-29813 | Azure DevOps Server Elevation of Privilege Vulnerability | Elevation of Privilege | 10.0 | Critical | No | No |
| CVE-2025-29827 | Azure Automation Elevation of Privilege Vulnerability | Elevation of Privilege | 9.9 | Critical | No | No |
| CVE-2025-29972 | Azure Storage Resource Provider Spoofing Vulnerability | Spoofing | 9.9 | Critical | No | No |
| CVE-2025-30387 | Document Intelligence Studio On-Prem Elevation of Privilege Vulnerability | Elevation of Privilege | 9.8 | Important | No | No |
| CVE-2025-47733 | Microsoft Power Apps Information Disclosure Vulnerability | Information Disclosure | 9.1 | Critical | No | No |
| CVE-2025-29840 | Windows Media Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important | No | No |
| CVE-2025-29962 | Windows Media Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important | No | No |
| CVE-2025-29963 | Windows Media Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important | No | No |
| CVE-2025-29964 | Windows Media Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important | No | No |
| CVE-2025-29966 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical | No | No |
| CVE-2025-29967 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical | No | No |
| CVE-2025-47732 | Microsoft Dataverse Remote Code Execution Vulnerability | Remote Code Execution | 8.7 | Critical | No | No |
| CVE-2025-30377 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical | No | No |
| CVE-2025-30386 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical | No | No |
| CVE-2025-32704 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Important | No | No |
| CVE-2025-33072 | Microsoft msagsfeedback.azurewebsites.net Information Disclosure Vulnerability | Information Disclosure | 8.1 | Critical | No | No |
| CVE-2025-26646 | .NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability | Spoofing | 8.0 | Important | No | No |
| CVE-2025-24063 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2025-29970 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2025-29975 | Microsoft PC Manager Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2025-29976 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2025-29977 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2025-29978 | Microsoft PowerPoint Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2025-29979 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2025-30375 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2025-30376 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2025-30379 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2025-30381 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2025-30382 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2025-30383 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2025-30385 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2025-30388 | Windows Graphics Component Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2025-30393 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2025-32705 | Microsoft Outlook Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2025-32707 | NTFS Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2025-26677 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | Denial of Service | 7.5 | Important | No | No |
| CVE-2025-29831 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Important | No | No |
| CVE-2025-29842 | UrlMon Security Feature Bypass Vulnerability | Security Feature Bypass | 7.5 | Important | No | No |
| CVE-2025-29969 | MS-EVEN RPC Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Important | No | No |
| CVE-2025-29971 | Web Threat Defense (WTD.sys) Denial of Service Vulnerability | Denial of Service | 7.5 | Important | No | No |
| CVE-2025-29838 | Windows ExecutionContext Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.4 | Important | No | No |
| CVE-2025-30384 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Remote Code Execution | 7.4 | Important | No | No |
| CVE-2025-29826 | Microsoft Dataverse Elevation of Privilege Vulnerability | Elevation of Privilege | 7.3 | Important | No | No |
| CVE-2025-21264 | Visual Studio Code Security Feature Bypass Vulnerability | Security Feature Bypass | 7.1 | Important | No | No |
| CVE-2025-29833 | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability | Remote Code Execution | 7.1 | Critical | No | No |
| CVE-2025-27468 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2025-29841 | Universal Print Management Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2025-29973 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2025-30378 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Remote Code Execution | 7.0 | Important | No | No |
| CVE-2025-26684 | Microsoft Defender Elevation of Privilege Vulnerability | Elevation of Privilege | 6.7 | Important | No | No |
| CVE-2025-27488 | Microsoft Windows Hardware Lab Kit (HLK) Elevation of Privilege Vulnerability | Elevation of Privilege | 6.7 | Important | No | No |
| CVE-2025-29825 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Spoofing | 6.5 | Low | No | No |
| CVE-2025-29830 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Information Disclosure | 6.5 | Important | No | No |
| CVE-2025-29832 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Information Disclosure | 6.5 | Important | No | No |
| CVE-2025-29835 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | Information Disclosure | 6.5 | Important | No | No |
| CVE-2025-29836 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Information Disclosure | 6.5 | Important | No | No |
| CVE-2025-29958 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Information Disclosure | 6.5 | Important | No | No |
| CVE-2025-29959 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Information Disclosure | 6.5 | Important | No | No |
| CVE-2025-29960 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Information Disclosure | 6.5 | Important | No | No |
| CVE-2025-29961 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Information Disclosure | 6.5 | Important | No | No |
| CVE-2025-29968 | Active Directory Certificate Services (AD CS) Denial of Service Vulnerability | Denial of Service | 6.5 | Important | No | No |
| CVE-2025-29955 | Windows Hyper-V Denial of Service Vulnerability | Denial of Service | 6.2 | Important | No | No |
| CVE-2025-29957 | Windows Deployment Services Denial of Service Vulnerability | Denial of Service | 6.2 | Important | No | No |
| CVE-2025-29954 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | Denial of Service | 5.9 | Important | No | No |
| CVE-2025-30394 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | Denial of Service | 5.9 | Important | No | No |
| CVE-2025-29974 | Windows Kernel Information Disclosure Vulnerability | Information Disclosure | 5.7 | Important | No | No |
| CVE-2025-29829 | Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2025-29837 | Windows Installer Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2025-32703 | Visual Studio Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2025-29956 | Windows SMB Information Disclosure Vulnerability | Information Disclosure | 5.4 | Important | No | No |
| CVE-2025-29839 | Windows Multiple UNC Provider Driver Information Disclosure Vulnerability | Information Disclosure | 4.0 | Important | No | No |
Conclusion
May's Patch Tuesday 2025 requires organizations to take a proactive approach to vulnerability management. The focus on fixes for Windows, cloud services, and developer products indicates an expansion of the attack surface and the need for a comprehensive security strategy. In addition to installing updates, it is recommended to analyze the impact of vulnerabilities on a specific infrastructure and consider additional security measures, such as network segmentation and enhanced monitoring. Given the wide range of affected products, automating the update process and regularly scanning for vulnerabilities will become key factors in maintaining a secure environment. It is important to note that the lack of information about active exploitation of vulnerabilities at the moment does not justify a decrease in the priority of their elimination. Information about vulnerabilities becomes publicly available, and attackers can quickly develop exploits, even if they have not yet been detected in the wild. Therefore, timely patching remains critically important for preventing potential attacks and protecting against future threats.