Описание
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-30397
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30397
- https://www.vicarius.io/vsociety/posts/cve-2025-30397-type-confusion-vulnerability-in-microsoft-scripting-engine-detection-script
- https://www.vicarius.io/vsociety/posts/cve-2025-30397-type-confusion-vulnerability-in-microsoft-scripting-engine-mitigation-script
Связанные уязвимости
CVSS3: 7.5
nvd
2 месяца назад
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
CVSS3: 7.5
fstec
2 месяца назад
Уязвимость компонента обработки сценариев Scripting Engine браузера Edge и Internet Explorer операционных систем Windows, позволяющая нарушителю выполнить произвольный код