About Elevation of Privilege – Microsoft DWM Core Library (CVE-2025-30400) vulnerability

Security Update News

Update Information

Title About Elevation of Privilege – Microsoft DWM Core Library (CVE-2025-30400) vulnerability
Update ID AVLEONOV:6946721120CD18555F773AB676282400
Type avleonov
Published 2025-06-10T08:44:06
Last Updated 2025-06-10T08:44:06

Security Impact

CVSS Score 7.8
Severity HIGH
Attack Vector LOCAL

Affected CVEs

  • CVE-2024-30051
  • CVE-2025-30400

Update Details

![About Elevation of Privilege – Microsoft DWM Core Library \(CVE-2025-30400\) vulnerability](https://avleonov.com/wp-content/uploads/2025/06/photo_830@10-06-2025_11-44-06.jpg)

**About Elevation of Privilege – Microsoft DWM Core Library (CVE-2025-30400) vulnerability. **The vulnerability, patched as part of May Microsoft Patch Tuesday, affects the Desktop Window Manager component. This is a compositing window manager that has been part of Windows since Windows Vista. Successful exploitation could grant an attacker SYSTEM-level privileges. At the time the vulnerability was disclosed, there were signs of in-the-wild exploitation. No details about the attacks are available yet.

According to the Acknowledgements, exploitation was discovered by the Microsoft Threat Intelligence Center, which rarely shares details. ![🤷‍♂️](https://s.w.org/images/core/emoji/15.1.0/72×72/1f937-200d-2642-fe0f.png) We’ll have to wait for reports from other researchers or a public exploit. There is currently one GitHub repository with a PoC, but its functionality is highly questionable. ![🤔](https://s.w.org/images/core/emoji/15.1.0/72×72/1f914.png)

The previous actively exploited EoP vulnerability in the DWM Core Library (CVE-2024-30051) was patched in May last year.

На русском

View Advisory Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.