VORANT. Threat Intelligence Sign in Get the full feed

Microsoft patches five actively exploited zero-days

critical vulnerability

Microsoft's May 2025 Patch Tuesday addresses five zero-day vulnerabilities currently being exploited in the wild, requiring immediate patching to prevent system compromise.

Japan's Information-technology Promotion Agency (IPA) has issued an urgent security alert following Microsoft's May 14, 2025 Patch Tuesday release. The update addresses multiple vulnerabilities in Microsoft products, five of which Microsoft has confirmed are being actively exploited in the wild: CVE-2025-30397, CVE-2025-30400, CVE-2025-32701, CVE-2025-32706, and CVE-2025-32709.

Successful exploitation of these vulnerabilities could allow attackers to crash applications, achieve remote code execution, or take full control of affected systems. IPA warns that the confirmed active exploitation significantly increases the risk of widespread attacks and urges immediate patching. Organizations are advised to deploy updates through Windows Update, which typically occurs automatically, though enterprise environments with managed update processes should prioritize rapid deployment. System restarts may be required to complete the installation of security updates.

Mentioned in this report

Vulnerabilities CVE-2025-30397KEVCVE-2025-30400KEVCVE-2025-32701KEVCVE-2025-32706KEVCVE-2025-32709KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/0514-ms.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free