# Microsoft patches five actively exploited zero-days

Published: 2025-05-13 · Severity: critical
Canonical: https://vorant.io/reports/34ea662f-9372-51c9-b721-37a42429b793/microsoft-patches-five-actively-exploited-zero-days

> Microsoft's May 2025 Patch Tuesday addresses five zero-day vulnerabilities currently being exploited in the wild, requiring immediate patching to prevent system compromise.

Japan's Information-technology Promotion Agency (IPA) has issued an urgent security alert following Microsoft's May 14, 2025 Patch Tuesday release. The update addresses multiple vulnerabilities in Microsoft products, five of which Microsoft has confirmed are being actively exploited in the wild: CVE-2025-30397, CVE-2025-30400, CVE-2025-32701, CVE-2025-32706, and CVE-2025-32709.

Successful exploitation of these vulnerabilities could allow attackers to crash applications, achieve remote code execution, or take full control of affected systems. IPA warns that the confirmed active exploitation significantly increases the risk of widespread attacks and urges immediate patching. Organizations are advised to deploy updates through Windows Update, which typically occurs automatically, though enterprise environments with managed update processes should prioritize rapid deployment. System restarts may be required to complete the installation of security updates.

## Mentioned in this report

- Vulnerabilities: CVE-2025-30397 (KEV), CVE-2025-30400 (KEV), CVE-2025-32701 (KEV), CVE-2025-32706 (KEV), CVE-2025-32709 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/0514-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/34ea662f-9372-51c9-b721-37a42429b793/microsoft-patches-five-actively-exploited-zero-days.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
