top of page

Patch Tuesday – May 2025

Updated: May 14

Guess what? It's gonna be [Patch Tuesday for the month of] May! 🍜 Microsoft has published its monthly updates for May 2025, including patches for 76 vulnerabilities with 9 rated as Critical. Read on to review the details of this month’s patches!

Patch Tuesday banner: It's gonna be MAY

Happy Patch Tuesday! On May 13, 2025, Microsoft released security updates for 76 vulnerabilities across 46 products. 9 of the vulnerabilities were rated as Critical and 67 were rated as Important. This month's patch breakdown is provided below.

5/14 UPDATE: CISA has added five of the patched vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation:

  • CVE-2025-30400 Microsoft Windows DWM Core Library Use-After-Free Vulnerability 

  • CVE-2025-32701 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability 

  • CVE-2025-32706 Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability 

  • CVE-2025-30397 Microsoft Windows Scripting Engine Type Confusion Vulnerability 

  • CVE-2025-32709 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability 

System administrators should prioritize addressing these actively-exploited vulnerabilities within their IT environments.


Patch Tuesday May 2025: Security Updates

Critical

# of Vulnerabilities

Azure Automation

1

Azure DevOps

1

Azure Storage Resource Provider

1

Microsoft Office

2

Remote Desktop Gateway Service

1

Windows Remote Desktop

1

Windows Remote Desktop Services

1

Windows Virtual Machine Bus

1

Important

# of Vulnerabilities

.NET, Visual Studio, and Build Tools for Visual Studio

1

Active Directory Certificate Services (AD CS)

1

Azure

1

Azure File Sync

1

Microsoft Brokering File System

1

Microsoft Dataverse

1

Microsoft Defender for Endpoint

1

Microsoft Defender for Identity

1

Microsoft Office

1

Microsoft Office Excel

9

Microsoft Office Outlook

1

Microsoft Office PowerPoint

1

Microsoft Office SharePoint

4

Microsoft PC Manager

1

Microsoft Scripting Engine

1

Remote Desktop Gateway Service

3

Role: Windows Hyper-V

1

Universal Print Management Service

1

UrlMon

1

Visual Studio

2

Visual Studio Code

1

Web Threat Defense (WTD.sys)

1

Windows Ancillary Function Driver for WinSock

1

Windows Common Log File System Driver

3

Windows Deployment Services

1

Windows Drivers

1

Windows DWM

1

Windows File Server

1

Windows Fundamentals

1

Windows Hardware Lab Kit

1

Windows Installer

1

Windows Kernel

2

Windows LDAP - Lightweight Directory Access Protocol

1

Windows Media

4

Windows NTFS

1

Windows Routing and Remote Access Service (RRAS)

8

Windows Secure Kernel Mode

1

Windows SMB

1

Windows Trusted Runtime Interface Driver

1

Windows Win32K - GRFX

1

As always, you can find more information on the specifics via the MSRC Security Update Guide at https://msrc.microsoft.com/update-guide/

_edited.jpg

Sign up for our newsletter to get exclusive updates

By submitting this form, you are providing your consent for Triumvirate Cybersecurity to contact you about its products and services. We will not sell your information to third parties, per our Privacy Policy.

Recent Posts
LinkedIn
CyberAB-RPO-Badge.png
Navigation

Home    About    Services    Pricing    Insights

31 S. Main Street, Suite 390, Dayton, OH 45402

(937) 203-8443    CAGE: 9ZW92

© Triumvirate Cybersecurity 2025

bottom of page