CVE-2025-30397: Microsoft Windows Scripting Engine Type Confusion Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL.
— CISA
Scripting Engine Memory Corruption Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.5335Patch KB5058405 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.5854Patch KB5058379 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.3692Patch KB5058385 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.5854Patch KB5058379 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.7314Patch KB5058392 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.3692Fixed in 10.0.20348.3630Patch KB5058500 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25475Fixed in 1.003Patch KB5058380 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27729Fixed in 1.003Patch KB5058380 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.23279Fixed in 1.003Patch KB5058380 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22577Fixed in 1.003Patch KB5058380 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8066Patch KB5058383 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.4061Fixed in 10.0.26100.3981Patch KB5058497 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.21014Patch KB5058387 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1611Patch KB5058384 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.5335Patch KB5058405 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB5058500 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB5058497 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB5058380 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30397?
CVE-2025-30397 is considered to have a high severity level due to its potential for remote code execution via type confusion in the Microsoft Scripting Engine.
How do I fix CVE-2025-30397?
To mitigate CVE-2025-30397, you should install the latest security updates and patches provided by Microsoft for affected products.
What products are affected by CVE-2025-30397?
CVE-2025-30397 affects several Microsoft products, including Windows Server 2022, Windows 11, and multiple versions of Windows 10 and Windows Server.
What type of attack is associated with CVE-2025-30397?
CVE-2025-30397 can be exploited by unauthorized attackers to execute arbitrary code remotely through exploitation of type confusion vulnerabilities.
Is there a known exploit for CVE-2025-30397?
As of now, there have been indications that CVE-2025-30397 could be actively exploited in the wild, heightening the urgency for patches.