CVE-2024-30051: Microsoft DWM Core Library Privilege Escalation Vulnerability
Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.
Other sources
Windows DWM Core Library Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6981Patch KB5037763 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20651Patch KB5037788 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.4412Patch KB5037768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.3593Patch KB5037771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.3593Patch KB5037771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.4412Patch KB5037768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2960Patch KB5037770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.5820Patch KB5037765 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2461Fixed in 10.0.20348.2458Patch KB5037848 - Upgrade
Upgrade
Microsoft Desktop Window Manager (DWM) Core Libraryto a version that resolves this vulnerability.Fixed in 10.0.10240.20651Patch KB5037788 - Upgrade
Upgrade
Microsoft Desktop Window Manager (DWM) Core Libraryto a version that resolves this vulnerability.Fixed in 10.0.14393.6981Patch KB5037763 - Upgrade
Upgrade
Microsoft Desktop Window Manager (DWM) Core Libraryto a version that resolves this vulnerability.Fixed in 10.0.17763.5820Patch KB5037765 - Upgrade
Upgrade
Microsoft Desktop Window Manager (DWM) Core Libraryto a version that resolves this vulnerability.Fixed in 10.0.19044.4412Patch KB5037768 - Upgrade
Upgrade
Microsoft Desktop Window Manager (DWM) Core Libraryto a version that resolves this vulnerability.Fixed in 10.0.19045.4412Patch KB5037768 - Upgrade
Upgrade
Microsoft Desktop Window Manager (DWM) Core Libraryto a version that resolves this vulnerability.Fixed in 10.0.20348.2461Patch KB5037848 - Upgrade
Upgrade
Microsoft Desktop Window Manager (DWM) Core Libraryto a version that resolves this vulnerability.Fixed in 10.0.20348.2458Patch KB5037848 - Upgrade
Upgrade
Microsoft Desktop Window Manager (DWM) Core Libraryto a version that resolves this vulnerability.Fixed in 10.0.22000.2960Patch KB5037770 - Upgrade
Upgrade
Microsoft Desktop Window Manager (DWM) Core Libraryto a version that resolves this vulnerability.Fixed in 10.0.22621.3593Patch KB5037771 - Upgrade
Upgrade
Microsoft Desktop Window Manager (DWM) Core Libraryto a version that resolves this vulnerability.Fixed in 10.0.22631.3593Patch KB5037771 - Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30051?
CVE-2024-30051 is a critical elevation of privilege vulnerability in Microsoft DWM Core Library.
How do I fix CVE-2024-30051?
To fix CVE-2024-30051, install the security updates provided by Microsoft for the affected Windows versions.
What versions of Windows are affected by CVE-2024-30051?
CVE-2024-30051 affects multiple versions of Windows, including Windows 10, Windows 11, and Windows Server editions.
What could be the impact of CVE-2024-30051?
Exploitation of CVE-2024-30051 could allow an attacker to gain SYSTEM privileges on susceptible systems.
Is CVE-2024-30051 being actively exploited?
At this time, there are no confirmed reports of active exploitation of CVE-2024-30051 in the wild.