HIGH
CVE-2025-30397
CVSS
7.5
KEV
Description
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
Summary dbcve.org
A type confusion vulnerability in the Microsoft Scripting Engine allows an attacker to corrupt memory by accessing a resource with an incompatible type, leading to arbitrary code execution over a network.
Mitigation
Deploy Microsoft security updates for the Scripting Engine component to address the type confusion vulnerability.
Weakness (CWE)
CWE-843
Type Confusion
EPSS Score
26.84%
Probability of exploitation in next 30 days
97.9th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30397
Vendor Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-30397-type-confusion-vulnerability-in-microsoft-scripting-engine-detection-script
Exploit, Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-30397-type-confusion-vulnerability-in-microsoft-scripting-engine-mitigation-script
Mitigation, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-30397
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.