CVE-2025-30388

Published May 13, 2025

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-30388 is a heap-based buffer overflow vulnerability found in the Windows Win32K - GRFX component. It allows an unauthorized attacker with local access to execute code on a vulnerable system. The vulnerability stems from the Win32K GRFX subsystem's inadequate validation of user-supplied input size during graphical rendering, which can lead to memory corruption and arbitrary code execution within the kernel context. The vulnerability affects multiple Microsoft products, including various versions of Windows Server (2008 through 2025), Windows 10, Windows 11, and Microsoft Office installations. Microsoft has released patch KB5058384 to address this vulnerability. However, some users have reported issues with the patch not properly updating DLLs.

Description
Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
365_copilot, office, office_long_term_servicing_channel, windows_10_1507, windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_22h2, windows_11_23h2, windows_11_24h2, windows_server_2008, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-122
nvd@nist.gov
CWE-787

Social media

Hype score
Not currently trending
  1. Windows graphics... #CVE-2025-30388 and CVE-2025-53766 #BufferOverflows enabling #RemoteCodeExecution. CVE-2025-47984 leaks memory over the network due to an incomplete fix. https://t.co/5eGabQcOJG

    @CaponeSoc

    9 Dec 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️Vulnerabilidades en productos Microsoft ❗CVE-2025-53766 ❗CVE-2025-30388 ❗CVE-2025-47984 ➡️Más info: https://t.co/wKQpMAyOv2 https://t.co/P8dK0N5dOx

    @CERTpy

    13 Nov 2025

    108 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🔴 Microsoft GDI Vulnerabilities: Graphics Parser RCE & Info Leak Check Point Research uncovered three GDI flaws where crafted EMF+ metafiles trigger out-of-bounds memory ops in GdiPlus.dll. CVE-2025-30388 (important) and CVE-2025-53766 (critical RCE) exploit the rendering

    @the_c_protocol

    3 Nov 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 We uncovered #security #vulnerabilities in #Windows graphics. #CVE-2025-30388 and CVE-2025-53766 are #BufferOverflows enabling #RemoteCodeExecution. CVE-2025-47984 leaks memory over the network due to an incomplete fix. 👇https://t.co/mK5qUol34V

    @_CPResearch_

    3 Nov 2025

    8445 Impressions

    37 Retweets

    75 Likes

    33 Bookmarks

    0 Replies

    2 Quotes

  5. 📢 𝐃𝐫𝐚𝐰𝐧 𝐭𝐨 𝐃𝐚𝐧𝐠𝐞𝐫: 𝐖𝐢𝐧𝐝𝐨𝐰𝐬 𝐆𝐫𝐚𝐩𝐡𝐢𝐜𝐬 𝐕𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐢𝐞𝐬 𝐋𝐞𝐚𝐝 𝐭𝐨 𝐑𝐞𝐦𝐨𝐭𝐞 𝐂𝐨𝐝𝐞 𝐄𝐱𝐞𝐜𝐮𝐭𝐢

    @PurpleOps_io

    2 Nov 2025

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.