7.8
CVSSv3

CVE-2024-30051

Published: 14/05/2024 Updated: 16/05/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Windows DWM Core Library Elevation of Privilege Vulnerability

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 10 22h2

microsoft windows 11 23h2

microsoft windows 11 22h2

microsoft windows server 2019

microsoft windows 10 1809

microsoft windows server 2022

microsoft windows 11 21h2

microsoft windows 10 21h2

microsoft windows 10 1507

microsoft windows 10 1607

microsoft windows server 2016

Recent Articles

Microsoft fixes Windows zero-day exploited in QakBot malware attacks
BleepingComputer • Sergiu Gatlan • 14 May 2024

Microsoft fixes Windows zero-day exploited in QakBot malware attacks By Sergiu Gatlan May 14, 2024 02:18 PM 0 ​Microsoft has fixed a zero-day vulnerability exploited in attacks to deliver QakBot and other malware payloads on vulnerable Windows systems. Tracked as CVE-2024-30051, this privilege escalation bug is caused by a heap-based buffer overflow in the DWM (Desktop Window Manager) core library. Following successful exploitation, attackers can gain SYSTEM privileges. Desktop Window Manager ...

Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws
BleepingComputer • Lawrence Abrams • 14 May 2024

Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws By Lawrence Abrams May 14, 2024 01:49 PM 0 .crit { font-weight:bold; color:red; } .article_section td { font-size: 14px!important; } Today is Microsoft's May 2024 Patch Tuesday, which includes security updates for 61 flaws and three actively exploited or publicly disclosed zero days. This Patch Tuesday only fixes one critical vulnerability, a Microsoft SharePoint Server Remote Code Execution Vulnerability. The number of bugs in each vu...

Microsoft fixes a bug abused in QakBot attacks plus a second under exploit
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Plus: Google Chrome, Apple bugs also exploited in the wild

Happy May Patch Tuesday. We've got a lot of vendors joining this month's patchapalooza, which includes a handful of bugs that have been exploited — either in the wild or at Pwn2Own — and now fixed by Microsoft, Apple, Google and VMware. Starting with Microsoft: Redmond disclosed and fixed 60 Windows CVEs today including two listed as publicly known and exploited prior to the patch being issued. The first one is an elevation of privilege bug in Windows DWM core library, tracked as CVE-2024-30...