BlackTreeCVE IntelligenceMicrosoft · KB5058430
Linked CVE review
Deploy Microsoft ESU security update KB5058430
- Linked CVEs
- 27
- Confirmed exploited
- 3
- PoC or lab evidence
- 2
- Maximum CVSS
- 8.8
Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.
| CVE and description | Severity | Exploit reality | Forecast and access | Remediation |
|---|---|---|---|---|
CVE-2025-30397 Immediate evidence Microsoft Windows Scripting Engine Type Confusion VulnerabilityMicrosoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL. | 7.5 · CVSS 3.1 · HighSource: CNA | Confirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-05-13.Public exploit referencedA structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised. | EPSS: 26.8% · 98.0th percentileForecast date: 2026-10-07NETWORK · HIGH complexity · NONE privileges · REQUIRED user interaction | Patch nowCISA confirms exploitation in the wild and lists 2025-06-03 as the remediation due date.Mitigation available. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-32706 Immediate evidence Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow VulnerabilityMicrosoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally. | 7.8 · CVSS 3.1 · HighSource: CNA | Confirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-05-13.Public exploit referencedA structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised. | EPSS: 2.31% · 82.9th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Patch nowCISA confirms exploitation in the wild and lists 2025-06-03 as the remediation due date.Mitigation available. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-32701 Immediate evidence Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free VulnerabilityMicrosoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | 7.8 · CVSS 3.1 · HighSource: CNA | Confirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-05-13.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.40% · 71.7th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Patch nowCISA confirms exploitation in the wild and lists 2025-06-03 as the remediation due date.Mitigation available. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29962 Elevated EPSS forecast Windows Media Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 14.3% · 96.5th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-30388 Scheduled assessment Windows Graphics Component Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 4.18% · 90.7th percentileForecast date: 2026-10-07LOCAL · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29966 Scheduled assessment Remote Desktop Client Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.36% · 70.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29967 Scheduled assessment Remote Desktop Client Remote Code Execution VulnerabilityHeap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.28% · 69.2th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29969 Scheduled assessment MS-EVEN RPC Remote Code Execution VulnerabilityTime-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network. | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.15% · 66.0th percentileForecast date: 2026-10-07NETWORK · HIGH complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29831 Scheduled assessment Windows Remote Desktop Services Remote Code Execution VulnerabilityUse after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.97% · 60.7th percentileForecast date: 2026-10-07NETWORK · HIGH complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-24063 Scheduled assessment Kernel Streaming Service Driver Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.69% · 51.3th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-32707 Scheduled assessment NTFS Elevation of Privilege VulnerabilityOut-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.53% · 43.1th percentileForecast date: 2026-10-07LOCAL · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-30385 Scheduled assessment Windows Common Log File System Driver Elevation of Privilege VulnerabilityUse after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.51% · 41.2th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29968 Scheduled assessment Active Directory Certificate Services (AD CS) Denial of Service VulnerabilityImproper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network. | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.86% · 78.6th percentileForecast date: 2026-10-07NETWORK · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29959 Scheduled assessment Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityUse of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.41% · 71.8th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29960 Scheduled assessment Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityOut-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.41% · 71.8th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29954 Scheduled assessment Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityUncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | 5.9 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.36% · 70.8th percentileForecast date: 2026-10-07NETWORK · HIGH complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29958 Scheduled assessment Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityUse of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.33% · 70.2th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29961 Scheduled assessment Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityOut-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.33% · 70.2th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29836 Scheduled assessment Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityOut-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.29% · 69.4th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29830 Scheduled assessment Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityUse of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.27% · 68.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29832 Scheduled assessment Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityOut-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.27% · 68.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29835 Scheduled assessment Windows Remote Access Connection Manager Information Disclosure VulnerabilityOut-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.27% · 68.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29956 Scheduled assessment Windows SMB Information Disclosure VulnerabilityBuffer over-read in Windows SMB allows an authorized attacker to disclose information over a network. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.03% · 62.6th percentileForecast date: 2026-10-07NETWORK · HIGH complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29974 Scheduled assessment Windows Kernel Information Disclosure VulnerabilityInteger underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network. | 5.7 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.69% · 51.1th percentileForecast date: 2026-10-07ADJACENT · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29837 Scheduled assessment Windows Installer Information Disclosure VulnerabilityImproper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally. | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.66% · 49.8th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29957 Scheduled assessment Windows Deployment Services Denial of Service VulnerabilityUncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally. | 6.2 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.58% · 46.2th percentileForecast date: 2026-10-07LOCAL · LOW complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2025-29839 Scheduled assessment Windows Multiple UNC Provider Driver Information Disclosure VulnerabilityOut-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally. | 4.0 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.49% · 39.9th percentileForecast date: 2026-10-07LOCAL · LOW complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |