HIGH
CVE-2024-30051
CVSS
7.8
KEV
Description
Windows DWM Core Library Elevation of Privilege Vulnerability
Summary dbcve.org
This is an Elevation of Privilege vulnerability in the Windows Desktop Window Manager (DWM) Core Library. DWM is a Windows component that handles desktop compositing and visual effects. The vulnerability allows an authenticated attacker to gain elevated privileges on the affected system, potentially executing code with higher permissions than the attacker's current context.
Mitigation
Apply the Microsoft security update for CVE-2024-30051, which is available through Windows Update or as part of the monthly security patch cycle. Prioritize patching workstations and servers that handle sensitive data or are exposed to untrusted inputs.
Weakness (CWE)
CWE-122
Heap-based Buffer Overflow
CWE-787
Out-of-bounds Write
EPSS Score
5.64%
Probability of exploitation in next 30 days
92.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.