← back
CVE-2025-30397

Scripting Engine Memory Corruption Vulnerability

CVSS 7.5 HIGHEPSS 21.6%● KEVCWE-843
In short

A flaw in Microsoft's Scripting Engine allows attackers to confuse data types in memory, leading to unauthorized code execution on a computer. This can happen remotely over the internet without special permissions.

Technical detail

Type confusion vulnerability in Microsoft Scripting Engine enables memory corruption via incompatible resource access. Remote attacker can exploit this over the network to achieve arbitrary code execution; no user interaction or elevated privileges required.

Summary generated and translated by AI from the official description.
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →