HIGH

CVE-2024-30051

Microsoft Windows 10 1507 2024-05-14 CVSS v3.1
CVSS
7.8
KEV

Description

Windows DWM Core Library Elevation of Privilege Vulnerability

Summary dbcve.org

This is an Elevation of Privilege vulnerability in the Windows Desktop Window Manager (DWM) Core Library. DWM is a Windows component that handles desktop compositing and visual effects. The vulnerability allows an authenticated attacker to gain elevated privileges on the affected system, potentially executing code with higher permissions than the attacker's current context.

Mitigation

Apply the Microsoft security update for CVE-2024-30051, which is available through Windows Update or as part of the monthly security patch cycle. Prioritize patching workstations and servers that handle sensitive data or are exposed to untrusted inputs.

Patch Commit

Weakness (CWE)

CWE-122 Heap-based Buffer Overflow
CWE-787 Out-of-bounds Write

EPSS Score

5.64%
Probability of exploitation in next 30 days
92.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE