CVE-2025-29829Use of Uninitialized Resource in Microsoft Windows 10 Version 1507

Severity
5.5MEDIUMNVD
EPSS
1.0%
top 23.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13

Description

Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages22 packages

NVDmicrosoft/windows< 10.0.14393.8066+4
NVDmicrosoft/windows_10_1507< 10.0.10240.21014
NVDmicrosoft/windows_10_1607< 10.0.14393.8066
NVDmicrosoft/windows_10_1809< 10.0.17763.7314
NVDmicrosoft/windows_10_21h2< 10.0.19044.5854

🔴Vulnerability Details

2
GHSA
GHSA-4pm3-q78x-r7p2: Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally2025-05-13
CVEList
Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability2025-05-13

📋Vendor Advisories

1
Microsoft
Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability2025-05-13

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws2025-05-13
CVE-2025-29829 — Use of Uninitialized Resource | cvebase