CVE-2025-29974Out-of-bounds Read in Microsoft Windows 10 Version 1507

Severity
5.7MEDIUMNVD
EPSS
1.1%
top 21.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13

Description

Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.1 | Impact: 3.6

Affected Packages26 packages

NVDmicrosoft/windows< 10.0.14393.8066+5
NVDmicrosoft/windows_10_1507< 10.0.10240.21014
NVDmicrosoft/windows_10_1607< 10.0.14393.8066
NVDmicrosoft/windows_10_1809< 10.0.17763.7314
NVDmicrosoft/windows_10_21h2< 10.0.19044.5854

🔴Vulnerability Details

2
CVEList
Windows Kernel Information Disclosure Vulnerability2025-05-13
GHSA
GHSA-qw9p-xh57-vvwj: Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network2025-05-13

📋Vendor Advisories

1
Microsoft
Windows Kernel Information Disclosure Vulnerability2025-05-13

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws2025-05-13
CVE-2025-29974 — Out-of-bounds Read in Microsoft | cvebase