Executive brief
A type confusion vulnerability in the Microsoft Windows Scripting Engine allows an unauthorized attacker to execute arbitrary code over a network. Exploitation typically requires a user to visit a specially crafted URL, leading to the access of resources using incompatible types.
Affected products
- Microsoft Windows Scripting Engine
- Microsoft Windows 10 up to (excluding) 10.0.14393.8066, 10.0.17763.7314, 10.0.19044.5854, 10.0.19045.5854, 10.0.10240.21014
- Microsoft Windows 11 up to (excluding) 10.0.22621.5335, 10.0.22631.5335, 10.0.26100.4061
- Microsoft Windows Server 2008 / 2012 / 2016 / 2019 / 2022 / 2025
Timeline
- 2025-05-13: disclosed
- 2025-05-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-05-13: exploited: Reported as exploited in the wild at time of publication.