CVE-2025-21304

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 416

Summary

CVE-2025-21304 is an elevation of privilege vulnerability affecting Microsoft's Desktop Window Manager (DWM) Core Library. An attacker who successfully exploits this vulnerability can escalate their privileges and gain administrative access to the affected system. This issue poses a serious risk to Windows users, especially those with unpatched installations, as it can allow an attacker to install malware, modify settings, or access sensitive data. Microsoft has released a security update to address this vulnerability, which users are strongly encouraged to install as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10

Affected Vendors

  • Microsoft