Skip to content
COOEY

EXPOSURES › CVE-2024-30051

CVE-2024-30051

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-05-14 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-30051 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatchedprivilege-escalation

A privilege escalation flaw in Microsoft's DWM Core Library lets attackers gain SYSTEM privileges and has been actively exploited in the wild.

An unpatched privilege escalation vulnerability in the Microsoft DWM Core Library allows attackers to escalate to SYSTEM privileges, enabling full system compromise. This failure is critical because it has been actively exploited in the wild and is linked to ransomware campaigns, meaning DIB organizations must verify their Microsoft DWM versions and apply patches immediately to prevent lateral movement and data exfiltration.

Shame score — A known privilege escalation vulnerability was actively exploited in the wild and linked to ransomware, indicating severe negligence and avoidable risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized