CyberICT

CVE-2025-30397

Microsoft · Published May 13, 2025

CVSS v3.1

HIGH
Patch availableGet patch

Description

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

Affected Products

  • Windows 10 1507 < 10.0.10240.21014
  • Windows 10 1607 < 10.0.14393.8066
  • Windows 10 1809 < 10.0.17763.7314
  • Windows 10 21h2 < 10.0.19044.5854

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H