Vulnerability record · CVE-2025-29971 · published 13 May 2025
CVE-2025-29971: Microsoft Windows Web Threat Defense driver out-of-bounds read
Microsoft · Windows 11 22h2
Web Threat Defense (WTD.sys) on Windows 11 contains an out-of-bounds read (CWE-125). A remote, unauthenticated attacker can trigger the flaw to cause a denial of service. The record does not specify the exact code path or which packet or input reaches the driver.
Description
Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated denial of service with a high CVSS score and very high EPSS percentile, though no confirmed in-the-wild exploitation is listed.
What it is
Web Threat Defense (WTD.sys) on Windows 11 contains an out-of-bounds read (CWE-125). A remote, unauthenticated attacker can trigger the flaw to cause a denial of service. The record does not specify the exact code path or which packet or input reaches the driver.
Impact
An attacker can crash or destabilize the affected system, denying service to its users. No confidentiality or integrity impact is indicated by the CVSS vector.
Attack surface
The vector is network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so the flaw is reachable remotely without authentication. The description does not state which protocol or interface carries the triggering input.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.64369 (99.2nd percentile), indicating a high predicted likelihood of exploitation activity.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2025-29971.
- Confirm affected Windows 11 22H2, 23H2 and 24H2 systems are patched and rebooted.
- Restrict network exposure of systems running the Web Threat Defense component where operationally feasible.
- Monitor vendor advisories for updated guidance or revised affected product lists.
Detection
- Watch for unexpected WTD.sys crashes or bugcheck events on Windows 11 hosts.
- Correlate system instability or reboot events with inbound network traffic to affected hosts.
- Alert on repeated service outages on unpatched Windows 11 endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29971 | Vendor Advisory |
Track CVE-2025-29971 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-29971), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.