NVD disclosure day

Published threat advisories for May 13, 2025

CVE advisoryKnown Exploit

CVE-2025-32709

Windows Local Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A null pointer dereference in the Windows Ancillary Function Driver for WinSock allows an authorized local attacker to elevate privileges. This impacts affected systems by enabling unauthorized access and potential control, posing a business risk to data integrity and confidentiality.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-32706

Windows Driver Vulnerability Allows Local Privilege Escalation.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows Common Log File System Driver could allow an authorized local attacker to elevate privileges. This impacts affected Windows systems, potentially leading to unauthorized access to data and compromise of system integrity, posing a business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-32701

Windows Local Privilege Escalation in CLFS Driver.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows Common Log File System Driver allows an authorized local attacker to elevate privileges. This could affect system integrity and confidentiality, leading to unauthorized control of local system resources and potential data compromise. Organizations should apply vendor updates to mitigate t

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-30397

Microsoft Windows Scripting Engine Vulnerability Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A type confusion vulnerability in the Microsoft Scripting Engine allows unauthorized remote code execution. This impacts organizations using affected Windows systems, posing a business risk through potential system and data compromise. The vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-4427

Ivanti Endpoint Manager Mobile API Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An authentication bypass in Ivanti Endpoint Manager Mobile's API allows unauthorized access to protected resources. This presents a business risk of data exposure and system compromise. Organizations should assess and mitigate this vulnerability.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-32756

Fortinet Products: Code Execution via HTTP Request

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in multiple Fortinet products allows unauthenticated attackers to execute arbitrary code via crafted HTTP requests. This could impact business operations and data integrity by allowing unauthorized command execution. Organizations should assess their exposure and apply vendor updates.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-4632

Samsung MagicINFO Server Path Traversal Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Samsung MagicINFO 9 Server is affected by a vulnerability allowing arbitrary file writes with system authority. This poses a significant business risk, potentially leading to system compromise and data breaches. Affected organizations should address this issue promptly.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-42999

SAP NetWeaver Vulnerability Allows Privileged User Data Compromise.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

SAP NetWeaver Visual Composer Metadata Uploader has a vulnerability where a privileged user can upload malicious content. This can compromise the confidentiality, integrity, and availability of the host system, posing a business risk.

• CISA KEV