HIGH

CVE-2025-30397

Microsoft Windows 10 1507 2025-05-13 CVSS v3.1
CVSS
7.5
KEV

Description

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

Summary dbcve.org

A type confusion vulnerability in the Microsoft Scripting Engine allows an attacker to corrupt memory by accessing a resource with an incompatible type, leading to arbitrary code execution over a network.

Mitigation

Deploy Microsoft security updates for the Scripting Engine component to address the type confusion vulnerability.

Proof of Concept

Weakness (CWE)

CWE-843 Type Confusion

EPSS Score

26.84%
Probability of exploitation in next 30 days
97.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE