HIGH

CVE-2025-30400

Microsoft Windows 10 1809 2025-05-13 CVSS v3.1
CVSS
7.8
KEV

Description

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

Summary dbcve.org

A use-after-free vulnerability in the Windows Desktop Window Manager (DWM) enables a locally authenticated attacker to elevate privileges to SYSTEM level by exploiting improper memory handling in the DWM process.

Mitigation

Apply the Microsoft security update for CVE-2025-30400 once released; until then, limit local user privileges and monitor for suspicious DWM process behavior.

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

1.9%
Probability of exploitation in next 30 days
78.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE