CVE-2025-53801

7.8

Microsoft · Windows

An untrusted pointer dereference vulnerability in Windows Desktop Window Manager (DWM) allows an authenticated local attacker to achieve privilege escalation.

Executive summary

A critical privilege escalation vulnerability in the Windows Desktop Window Manager could allow a locally authenticated attacker to gain elevated system permissions.

Vulnerability

This vulnerability involves an untrusted pointer dereference within the Desktop Window Manager (DWM) component. An attacker with low-level local access can leverage this flaw to elevate their privileges to a higher level of system control.

Business impact

Successful exploitation of this vulnerability permits a local user to bypass security boundaries, potentially resulting in full system compromise. Given the CVSS score of 7.8, this is classified as a High severity issue because it enables unauthorized administrative control over affected workstations or servers, leading to data exfiltration or the installation of persistent malicious software.

Remediation

Immediate Action: Apply the relevant monthly security updates provided by Microsoft in the September 2025 patch cycle to address the DWM pointer dereference flaw.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected DWM-related crashes that may indicate an exploitation attempt.

Compensating Controls: Ensure that principle of least privilege is strictly enforced for all local user accounts to minimize the potential impact if a local account is compromised.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability poses a significant risk to the integrity of local Windows environments. System administrators should prioritize the deployment of the September 2025 security updates across all affected Windows 10 and 11 versions to mitigate the risk of local privilege escalation.

More Microsoft CVEs

Sources