PT-2024-3342 · Microsoft · Windows Dwm Core Library+1

Adam Brunner

+7

·

Published

2024-05-14

·

Updated

2026-01-22

·

CVE-2024-30051

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows DWM Core Library (affected versions not specified)
Description The issue is related to an elevation of privilege vulnerability in the Windows DWM Core Library. This vulnerability allows attackers to affect the system. It has been linked to cyberattacks involving QakBot, a notorious banking trojan. The vulnerability is being actively exploited by QakBot and other malware. Researchers have identified a new zero-day vulnerability in Windows, designated as this issue, and it is being used by multiple attackers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

RCE

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-03613
CVE-2024-30051

Affected Products

Windows
Windows Dwm Core Library