CVE-2025-30400 is a use-after-free vulnerability in Windows Desktop Window Manager (DWM) Core Library that allows local privilege escalation. Despite being on CISA KEV, this is a local-only vulnerability requiring existing system access and cannot be exploited directly over the internet.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: OTHER
CVE Published: 2025-05-13
Added to CISA KEV: 2025-05-13 0 DAY BETWEEN CVE AND KEV
CVE-2025-30400 is a critical elevation of privilege vulnerability residing in the Microsoft Windows Desktop Window Manager (DWM) Core Library?id=CVE-2025-30400?kagi_q=CVE-2025-30400.
This repository features the CVE-2025-30400 Concept, a Python program designed to illustrate the impact of a Use-After-Free (UAF) privilege escalation zero-day ... This repository features the CVE-2025-30400 Concept, a Python program designed to illustrate the impact of a Use-After-Free (UAF) privil…
An actively exploited use-after-free vulnerability in Windows DWM (CVE-2025-30400) enables attackers to escalate privileges to SYSTEM. Immediate patching is ... An actively exploited use-after-free vulnerability in Windows DWM (CVE-2025-30400) enables attackers to escalate privileges to SYSTEM. Imme…
CVE-2025-30400 Detail Description Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
Actively Exploited Zero-Day Vulnerability in Microsoft DWM Core Library. CVE-2025-30400 is an Important elevation of privilege vulnerability ...
Summary: A newly disclosed vulnerability—CVE-2025-30400—in the Windows Desktop Window Manager (DWM) allows a local, authenticated user to escalate privileges via a "use-after-free" flaw. This post gives a clear explanation of how the bug works, sample code, mitigation advice, and more. The details h…