WEEKLY BRIEFING · 12 MAY – 18 MAY 2025 · UTC
Public sources only
13 public updates in week 20
Microsoft published 4 Windows KB releases (4 security). MSRC published May 2025 Security Updates. 3 roadmap changes, led by Teams (2) and Microsoft 365 Admin Center (1). CISA added 5 Microsoft CVEs to its Known Exploited Vulnerabilities catalog. 2 Windows and security articles from Microsoft blogs.
4Windows KB releases
1MSRC release note
3Roadmap changes across 2 products
2Windows and security articles
5Microsoft CVEs added to CISA KEV
Security to act on5
- CVE-2025-32709 — Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityKEV 13 May
- CVE-2025-32706 — Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow VulnerabilityKEV 13 May
- CVE-2025-32701 — Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free VulnerabilityKEV 13 May
- CVE-2025-30400 — Microsoft Windows DWM Core Library Use-After-Free VulnerabilityKEV 13 May
- CVE-2025-30397 — Microsoft Windows Scripting Engine Type Confusion VulnerabilityKEV 13 May
Windows releases4
MSRC security releases1
Windows and security news2
Microsoft product news3
Microsoft Purview Blog · 1
Microsoft Entra Identity Platform Blog · 1
Microsoft Graph PowerShell SDK release notes · 1
Microsoft 365 roadmap3
Teams · 2
- Microsoft Teams: Ability to Stop Copilot while it is generating a response16 May
- Microsoft Teams: Presenter Chat while screensharing16 May
Microsoft 365 Admin Center · 1
Every line opens its detail page or the original Microsoft source. This briefing uses public sources only and says nothing about your tenant or devices.