CVE-2025-30397 is a type confusion vulnerability in Microsoft's scripting engine affecting Windows client and server operating systems. Despite being in CISA KEV, this requires user interaction (UI:R in CVSS) and primarily targets client-side script execution rather than internet-facing server services.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2025-05-13
Added to CISA KEV: 2025-05-13 0 DAY BETWEEN CVE AND KEV
CVE-2025-30397 is a critical security vulnerability involving a type confusion flaw within the Microsoft Scripting Engine [2]. It was disclosed in May 2025 as part of Microsoft's Patch Tuesday updates [4].
This repository contains a proof-of-concept (PoC) exploit for a Use-After-Free vulnerability in the JScript engine ( jscript.dll ) affecting Windows Server ...
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
CVE-2025-30397 is a type confusion vulnerability that allows an unauthorized attacker to execute code over a network. It affects various Windows versions and has a CVSS score of 7.5 (HIGH). See vendor advisory, CISA guidance, and affected software configurations. ... NVD MENU Information Technology…
CVE-2025-30397: This type confusion vulnerability in the Microsoft Scripting Engine could let an unauthorized remote attacker execute ...
In early 2025, security researchers discovered a critical vulnerability tracked as CVE-2025-30397—a type confusion bug in the Microsoft Scripting Engine. This vulnerability makes it possible for an unauthorized attacker to execute arbitrary code simply by sending malicious data over a network, targe…
CVE-2025-30397 exposes a critical type confusion flaw in Microsoft's Scripting Engine, enabling remote attackers to execute arbitrary code via Edge's IE Mode.
Microsoft Windows: CVE-2025-30397: Scripting Engine Memory Corruption Vulnerability. Try Surface Command. Severity 8 CVSS.