CVE-2025-30388
published 2025-05-13CVE-2025-30388: Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
PriorityP348high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
3.57%
88.1th percentile
Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | 365_copilot | < 16.0.18827.20000 | 16.0.18827.20000 |
| microsoft | microsoft_office_for_android | >= 16.0.1 < 16.0.18827.20000 | 16.0.18827.20000 |
| microsoft | microsoft_office_for_universal | >= 16.0.1 < 16.0.14326.22502 | 16.0.14326.22502 |
| microsoft | microsoft_office_ltsc_for_mac_2021 | >= 16.0.1 < 16.97.25042725 | 16.97.25042725 |
| microsoft | microsoft_office_ltsc_for_mac_2024 | >= 16.0.0 < 16.97.25042725 | 16.97.25042725 |
| microsoft | office | < 16.0.14326.22502 | 16.0.14326.22502 |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | windows_10_1507 | < 10.0.10240.21014 | 10.0.10240.21014 |
| microsoft | windows_10_1607 | < 10.0.14393.8066 | 10.0.14393.8066 |
| microsoft | windows_10_1809 | < 10.0.17763.7314 | 10.0.17763.7314 |
| microsoft | windows_10_21h2 | < 10.0.19044.5854 | 10.0.19044.5854 |
| microsoft | windows_10_22h2 | < 10.0.19045.5854 | 10.0.19045.5854 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.21014 | 10.0.10240.21014 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.8066 | 10.0.14393.8066 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.7314 | 10.0.17763.7314 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.5854 | 10.0.19044.5854 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.5854 | 10.0.19045.5854 |
| microsoft | windows_11_22h2 | < 10.0.22621.5335 | 10.0.22621.5335 |
| microsoft | windows_11_23h2 | < 10.0.22631.5335 | 10.0.22631.5335 |
| microsoft | windows_11_24h2 | < 10.0.26100.4061 | 10.0.26100.4061 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.5335 | 10.0.22621.5335 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.5335 | 10.0.22631.5335 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.5335 | 10.0.22631.5335 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.4061 | 10.0.26100.4061 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Windows up to Server 2025 Graphics heap-based overflow (EUVD-2025-14412 / WID-SEC-2025-1050)
vuldb·2026-05-23·CVSS 7.8
CVE-2025-30388 [HIGH] Microsoft Windows up to Server 2025 Graphics heap-based overflow (EUVD-2025-14412 / WID-SEC-2025-1050)
A vulnerability was found in Microsoft Windows. It has been classified as critical. Affected by this issue is some unknown functionality of the component Graphics Component. The manipulation leads to heap-based buffer overflow.
This vulnerability is referenced as CVE-2025-30388. The attack can only be performed from a local environment. No exploit is available.
It is suggested to install a patch to address this issue.
GHSA
GHSA-9j2q-rv22-36xm: Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally
ghsa_unreviewed·2025-05-13
CVE-2025-30388 [HIGH] CWE-122 GHSA-9j2q-rv22-36xm: Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally
Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
Microsoft
Windows Graphics Component Remote Code Execution Vulnerability
vendor_msrc·2025-05-13·CVSS 7.8
CVE-2025-30388 [HIGH] CWE-122 Windows Graphics Component Remote Code Execution Vulnerability
Windows Graphics Component Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.
For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a
No detection rules found.
No public exploits indexed.
Checkpoint
3rd November – Threat Intelligence Report
blogs_checkpoint·2025-11-03·CVSS 9.8
CVE-2025-61882 [CRITICAL] 3rd November – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 3rd November – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 3rd November, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The Everest ransomware group has claimed responsibility for a series of attacks impacting AT&T, Dublin Airport, and Air Arabia. The ransomware gang exfiltrated sensitive data including 576,000 AT&T applicant records, 1.5 million Dublin Airport passenger files, and 18,000 Air Arabia employee records. Sweden’s power grid op
Checkpoint
Drawn to Danger: Windows Graphics Vulnerabilities Lead to Remote Code Execution and Memory Exposure
blogs_checkpoint·2025-11-02·CVSS 7.8
CVE-2025-30388 [HIGH] Drawn to Danger: Windows Graphics Vulnerabilities Lead to Remote Code Execution and Memory Exposure
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Drawn to Danger: Windows Graphics Vulnerabilities Lead to Remote Code Execution and Memory Exposure
## Background
GDI
These are the vulnerabilities:
CVE-2025-30388 , rated important an
Checkpoint
18th August – Threat Intelligence Report
blogs_checkpoint·2025-08-18
CVE-2025-30388 18th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 18th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 18th August, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The Canadian House of Commons has suffered a data breach. The incident resulted in unauthorized access to a database containing employees’ names, office locations, email addresses, and information on House-managed computers and mobile devices, reportedly due to vulnerability in Microsoft software.
The Office of the Pennsyl
Qualys
Microsoft and Adobe Patch Tuesday, May 2025 Security Update Review
blogs_qualys·2025-05-13
Microsoft and Adobe Patch Tuesday, May 2025 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for May 2025
Adobe Patches for May 2025
Zero-day Vulnerabilities Patched in May Patch Tuesday Edition
Critical Severity Vulnerabilities Patched in May Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response withPatch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Audit
Qualys Monthly Webinar Series
Microsoft’s May 2025 Patch Tuesday rolls out critical security updates, addressing multiple vulnerabilities across Windows, Office, and other key products. Here’s a quick breakdown of what you need to know.
## Microsoft Patch Tuesday for May 2025
In this month’s Patch Tuesday, Ma
Qualys
Microsoft and Adobe Patch Tuesday, May 2025 Security Update Review | Qualys
blogs_qualys·2025-05-13
Microsoft and Adobe Patch Tuesday, May 2025 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for May 2025
- Adobe Patches for May 2025
- Zero-day Vulnerabilities Patched in May Patch Tuesday Edition
- Critical Severity Vulnerabilities Patched in May Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response withPatch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Audit
- Qualys Monthly Webinar Series
Microsoft’s May 2025 Patch Tuesday rolls out critical security updates, addressing multiple vulnerabilities across Windows, Office, and other key products. Here’s a quick breakdown of what you need to know.
## Microsoft Patch Tuesday for May 2025
In this month’s Patc
Talos
Microsoft Patch Tuesday for May 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-05-13·CVSS 8.8
CVE-2025-30397 [HIGH] Microsoft Patch Tuesday for May 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for May of 2025 which includes 78 vulnerabilities affecting a range of products, including 11 that Microsoft marked as “critical”.
Microsoft noted five vulnerabilities that have been observed to be exploited in the wild. CVE-2025-30397 is a remote code execution vulnerability in the Microsoft Scripting Engine. There were also four elevation of privilege vulnerabilities being actively exploited, CVE-2025-32709, CVE-2025-30400, CVE-2025-32701 and CVE-2025-32706 affecting the Ancillary Function Driver for WinSock, the DWM Core Library and the Windows Common Log File System Driver.
The eleven "critical” entries consist of five remote code execution (RCE) vulnerabilities, four elevation of privilege vulnerabilities, one information disclosure
Talos
Microsoft Patch Tuesday for May 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-05-13·CVSS 8.8
CVE-2025-30397 [HIGH] Microsoft Patch Tuesday for May 2025 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for May 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for May of 2025 which includes 78 vulnerabilities affecting a range of products, including 11 that Microsoft marked as “critical”.
Microsoft noted five vulnerabilities that have been observed to be exploited in the wild. CVE-2025-30397 is a remote code execution vulnerability in the Microsoft Scripting Engine. There were also four elevation of privilege vulnerabilities being actively exploited, CVE-2025-32709 , CVE-2025-30400 , CVE-2025-32701 and CVE-2025-32706 affecting the Ancillary Function Driver for WinSock, the DWM Core Library and the Windows Common Log File System Driver.
The eleven "critical” entries consist of five remote code execution (RCE) v
Bleepingcomputer
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
blogs_bleepingcomputer·2025-05-13·CVSS 7.8
[HIGH] Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
## Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
## Lawrence Abrams
Today is Microsoft's May 2025 Patch Tuesday, which includes security updates for 72 flaws, including five actively exploited and two publicly disclosed zero-day vulnerabilities.
This Patch Tuesday also fixes six "Critical" vulnerabilities, five being remote code execution vulnerabilities and another an information disclosure bug.
The number of bugs in each vulnerability category is listed below:
17 Elevation of Privilege Vulnerabilities
2 Security Feature Bypass Vulnerabilities
28 Remote Code Execution Vulnerabilities
15 Information Disclosure Vulnerabilities
7 Denial of Service Vulnerabilities
2 Spoofing Vulnerabilities
This count does not include Azure, Dataverse, Mariner, and Microsof
Zscaler
Zscaler protects against 4 new vulnerabilities | 05-13-2025
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler protects against 4 new vulnerabilities | 05-13-2025
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2025-05-13
Published