PT-2025-20974 · Unknown+1 · Web Threat Defense+1

Vladimir Lagunov

·

Published

2025-05-13

·

Updated

2026-03-16

·

CVE-2025-29971

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Web Threat Defense versions prior to May 2025 update
Description: The issue is an out-of-bounds read in Web Threat Defense (WTD.sys) that allows an unauthorized attacker to deny service over a network. This can be exploited by remote attackers to crash systems, posing a kernel-level denial-of-service threat.
Recommendations: For versions prior to the May 2025 update, apply the patch KB5058411 to resolve the issue. As a temporary workaround, consider restricting network access to minimize the risk of exploitation.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05607
CVE-2025-29971

Affected Products

Web Threat Defense
Windows