Junglewise Threat Intelligence

CVE-2025-30400: Microsoft Windows DWM Core Library Use-After-Free Vulnerability

CVE-2025-30400 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2025-05-13

Technologies: Microsoft Windows 10 22h2, Microsoft Windows 11 22h2, Microsoft Windows 10 1809, Microsoft Windows 11 24h2, Microsoft Windows, Microsoft Windows 10 21h2, Microsoft Windows Server 2019, Microsoft Windows Server 2022 23h2, Microsoft Windows Server 2022, Microsoft Windows 11 23h2, Microsoft Windows Server 2025. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability in the Microsoft Windows Desktop Window Manager (DWM) Core Library allows a locally authenticated attacker to elevate their privileges. The vulnerability has been observed being exploited in the wild.

Affected products

  • Microsoft Windows 10 1809 up to (excluding) 10.0.17763.7314
  • Microsoft Windows 10 21H2 up to (excluding) 10.0.19044.5854
  • Microsoft Windows 10 22H2 up to (excluding) 10.0.19045.5854
  • Microsoft Windows 11 22H2 up to (excluding) 10.0.22621.5335
  • Microsoft Windows 11 23H2 up to (excluding) 10.0.22631.5335
  • Microsoft Windows 11 24H2 up to (excluding) 10.0.26100.4061
  • Microsoft Windows Server 2019 up to (excluding) 10.0.17763.7314
  • Microsoft Windows Server 2022 up to (excluding) 10.0.20348.3692
  • Microsoft Windows Server 2022 23H2 up to (excluding) 10.0.25398.1611
  • Microsoft Windows Server 2025 up to (excluding) 10.0.26100.4061

Timeline

  • 2025-05-13: disclosed
  • 2025-05-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-05-13: advisory: Microsoft published vendor advisory
  • 2025-05-13: exploited: Reported as exploited in the wild at time of publication

Related threats