# Microsoft Patches Five Exploited Zero-Days

Published: 2025-05-13 · Severity: high
Canonical: https://vorant.io/reports/34ea662f-9372-51c9-b721-37a42429b793/microsoft-patches-five-exploited-zero-days

> IPA Japan warns that five Microsoft vulnerabilities patched in the May 2025 update are already being actively exploited in the wild.

Japan's IPA issued an alert following Microsoft's May 2025 Patch Tuesday release, highlighting that five vulnerabilities among the fixed set are confirmed by Microsoft to be under active exploitation: CVE-2025-30397, CVE-2025-30400, CVE-2025-32701, CVE-2025-32706, and CVE-2025-32709. Successful exploitation of these flaws could lead to application crashes or full attacker control of affected Windows systems.

The advisory urges organizations and individual users to apply the security updates immediately via Windows Update or centralized patch management, noting that exploitation activity is expected to expand if systems remain unpatched. No specific threat actor, malware family, or technical exploitation details are provided in the alert itself; it functions as a localization/notification of Microsoft's monthly security release for the Japanese audience, directing readers to Microsoft's own advisories for further technical detail.

## Mentioned in this report

- Vulnerabilities: CVE-2025-30397 (KEV), CVE-2025-30400 (KEV), CVE-2025-32701 (KEV), CVE-2025-32706 (KEV), CVE-2025-32709 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/0514-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/34ea662f-9372-51c9-b721-37a42429b793/microsoft-patches-five-exploited-zero-days.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
