EUVD-2025-14411
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 13 May 2025. Evidence sources: cisa_kev.
- ENISA score
- 7.5 · CVSS 3.1
- Advisory evidence
- 3 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2025-0159Kwetsbaarheden verholpen in Microsoft Windows
