Home › Microsoft Patch Tuesday › May 2025

Microsoft Patch Tuesday, May 2025

·

Microsoft's May 2025 security release, published May 13, 2025: 34 updates fixing 54 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

34
Updates (KBs)
54
CVEs fixed
4
On the CISA KEV list
0
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2025-32701Windows Common Log File System Driver Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-32706Windows Common Log File System Driver Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-32709Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-30397Scripting Engine Memory Corruption VulnerabilityCVSS 7.5Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2025-29962Windows Media Remote Code Execution VulnerabilityCVSS 8.8

Products fixed this month

Windows Server 2008 for 32-bit Systems Service Pack 2 (3)Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (3)Windows Server 2008 for x64-based Systems Service Pack 2 (3)Microsoft Excel 2016 (32-bit edition) (3)Microsoft Excel 2016 (64-bit edition) (3)Windows Server 2008 R2 for x64-based Systems Service Pack 1 (2)Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (2)Microsoft SharePoint Enterprise Server 2016 (2)Microsoft SharePoint Server 2019 (2)Microsoft Office 2016 (32-bit edition) (2)

Every update in this release

All 18 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5058449 ExploitedHigh8.823Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5061197 ExploitedHigh7.81Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5061196 ExploitedHigh7.81Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5061195 ExploitedHigh7.81Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5058380 ExploitedHigh7.51Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5002711High8.42Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002695High8.41Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5059200High8.01.NET 8.0 installed on Windows, .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OSSupport · Catalog
KB5059201High8.01.NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on WindowsSupport · Catalog
KB5002722High7.84Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002708High7.84Microsoft SharePoint Server 2019Support · Catalog
KB5002709High7.84Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002707High7.87Office Online ServerSupport · Catalog
KB5002717High7.87Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition), Microsoft Office 2016 (32-bit edition)Support · Catalog
KB5002712High7.81Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002706High7.81Microsoft SharePoint Server 2019Support · Catalog
KB5002716High7.81Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5061258High7.51Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
Take this release to your AI

Composed from the May 2025 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.