CVE-2025-30400
KEVmassUse-After-Free LPE in Microsoft Windows DWM Core Library (Actively Exploited)
CISA: Microsoft Windows DWM Core Library Use-After-Free Vulnerability
CVE-2025-30400 is a use-after-free memory corruption flaw (CWE-416) in the Windows Desktop Window Manager (DWM) Core Library, the component that renders the Windows graphical interface. A local, authenticated attacker who can already execute code on a target system can trigger the flaw by running a specially crafted process that causes DWM to use memory that has been freed, with no user interaction required. Successful exploitation yields elevation of privilege, letting the attacker break out of their low-privilege context and gain higher (administrative/SYSTEM-level) rights on the host, with high impact to confidentiality, integrity and availability. Any system running the affected Windows 10 or Windows 11 client releases or Windows Server 2019, 2022, 2022 23H2 or 2025 is affected. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-13 as one of the actively exploited zero-days fixed in Microsoft's May 2025 Patch Tuesday; no public PoC is known and ransomware use is unconfirmed.
What to do: Apply Microsoft's May 2025 security updates (released Patch Tuesday, May 13, 2025) to all affected Windows 10/11 clients and Windows Server 2019/2022/2022 23H2/2025 hosts, and verify the installed build number afterward. Prioritize internet-exposed, multi-user, and terminal/RDS servers where unprivileged users run, since a local foothold anywhere on those systems maps directly to full host compromise. Federal agencies must patch or apply vendor mitigations per BOD 22-01 timelines following the KEV listing, and defenders should monitor for suspicious local privilege-escalation activity on unpatched hosts.
| Microsoft Windows 10 | 1809, 21H2, 22H2 (builds prior to the May 2025 security updates) |
| Microsoft Windows 11 | 22H2, 23H2, 24H2 (builds prior to the May 2025 security updates) |
| Microsoft Windows Server | 2019, 2022, 2022 23H2, 2025 (builds prior to the May 2025 security updates) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2019, windows server 2022, windows server 2022 23h2, windows server 2025
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H