Microsoft’s latest Patch Tuesday addresses 78 security vulnerabilities across its software portfolio, with special urgency for five zero-day flaws already being exploited by attackers in the wild.
## Critical Vulnerabilities Overview
Of the 78 patched flaws:
– 11 are rated Critical
– 66 are rated Important
– 1 is rated Low severity
The vulnerabilities include 28 remote code execution flaws, 21 privilege escalation bugs, and 16 information disclosure vulnerabilities. These updates complement eight additional security fixes for Microsoft Edge released since last month.
## Five Zero-Day Vulnerabilities Under Active Exploitation
1. **CVE-2025-30397** (CVSS 7.5): Scripting Engine Memory Corruption Vulnerability
2. **CVE-2025-30400** (CVSS 7.8): Microsoft Desktop Window Manager Core Library Elevation of Privilege
3. **CVE-2025-32701** (CVSS 7.8): Windows Common Log File System Driver Elevation of Privilege
4. **CVE-2025-32706** (CVSS 7.8): Windows Common Log File System Driver Elevation of Privilege
5. **CVE-2025-32709** (CVSS 7.8): Windows Ancillary Function Driver for WinSock Elevation of Privilege
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added all five vulnerabilities to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply patches by June 3, 2025.
## Notable Patterns and Additional Concerns
The DWM Core Library vulnerability (CVE-2025-30400) represents the third privilege escalation flaw in this component exploited in the wild since 2023. Similarly, the CLFS vulnerabilities mark the seventh and eighth privilege escalation flaws discovered in this component since 2022.
Other significant fixes include a privilege escalation bug in Microsoft Defender for Endpoint for Linux (CVE-2025-26684) and a spoofing vulnerability in Microsoft Defender for Identity (CVE-2025-26685).
The highest severity vulnerability is CVE-2025-29813 (CVSS 10.0), a privilege escalation flaw in Azure DevOps Server that allows unauthorized attackers to elevate privileges over a network.
Numerous other technology vendors have also released security updates in recent weeks, including Adobe, Apple, Cisco, Google, Intel, and many others.
