CVE-2025-24074
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 20
Summary
CVE-2025-24074 is a newly disclosed vulnerability affecting the Windows DWM (Desktop Window Manager) Core Library. An attacker who has already gained authorized access to a system can exploit this issue by introducing improperly validated input. Successful exploitation allows the attacker to escalate their privileges locally, gaining higher levels of access within the system. This vulnerability poses a significant risk to Windows systems and requires immediate attention from administrators for patching and mitigation efforts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2022
Affected Vendors
- Microsoft