LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-30051: Microsoft DWM Core Library Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 14, 2024
CVSS 7.8 · High⚠ Actively exploited (CISA KEV)Ransomware-linked
7.8
CVSS score
High
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 4, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-30051 to its Known Exploited Vulnerabilities catalog on May 14, 2024, with a federal patch deadline of Jun 4, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2024-30051 is a privilege escalation vulnerability in the Microsoft DWM Core Library. An attacker who can already run code on a system may abuse it to obtain SYSTEM-level privileges. Because it has been observed in ransomware activity, rapid identification and remediation matter for any environment that runs the affected component.

Public detail is limited to the CISA summary and the CWE classification; exact affected builds, attack vectors, and scoring must be confirmed against the Microsoft advisory before acting.

How it works

The flaw is classified as CWE-122 (heap-based buffer overflow). In this class of weakness, an attacker supplies carefully crafted input that overruns a heap buffer managed by the DWM Core Library. Successful exploitation can corrupt memory structures that control process privileges, allowing the attacker’s code to run with SYSTEM rights instead of the lower privileges of the original process.

Because the library is part of the Windows desktop composition stack, the overflow occurs in a privileged context once the attacker has local code execution. No remote unauthenticated exploit path is described in the available facts; the practical risk is therefore post-compromise elevation that ransomware operators commonly chain after initial access.

Am I affected? How to find it in your systems

The Microsoft DWM Core Library ships with Windows operating systems that provide the Desktop Window Manager. It is present on most interactive Windows workstations and servers that render a graphical desktop.

How to remediate

Apply the security update that Microsoft released for this vulnerability as the primary remediation. Follow the vendor’s installation guidance and reboot requirements exactly; confirm successful installation by verifying the updated file versions or the corresponding knowledge-base article.

If you can't patch immediately

Until the vendor update can be deployed, reduce risk with compensating controls:

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are frequently used by ransomware operators to gain full control of a host and then exfiltrate or encrypt data. If you have evidence of exploitation or cannot rule it out, treat the incident as a potential breach: isolate affected systems, preserve forensic artifacts, and follow your incident-response plan. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · DWM Core Library
WeaknessCWE-122
CVSS base score7.8 (High)
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PublishedMay 14, 2024
Added to CISA KEVMay 14, 2024
Federal patch deadlineJun 4, 2024
Known ransomware useYes
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities