CVE-2025-29830Use of Uninitialized Resource in Microsoft Windows 10 Version 1507

Severity
6.5MEDIUMNVD
EPSS
3.5%
top 12.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13

Description

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages26 packages

CVEListV5microsoft/windows_server_2008_service_pack_26.0.6003.06.0.6003.23279
CVEListV5microsoft/windows_server_2008_r2_service_pack_16.1.7601.06.1.7601.27729
NVDmicrosoft/windows< 10.0.14393.8066+5
NVDmicrosoft/windows_10_1507< 10.0.10240.21014
NVDmicrosoft/windows_10_1607< 10.0.14393.8066

🔴Vulnerability Details

2
CVEList
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability2025-05-13
GHSA
GHSA-5293-3c98-r4fm: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a netwo2025-05-13

📋Vendor Advisories

1
Microsoft
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability2025-05-13

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws2025-05-13
CVE-2025-29830 — Use of Uninitialized Resource | cvebase