CVE-2025-64680

7.8

Microsoft · Windows DWM Core Library

A heap-based buffer overflow in the Windows DWM Core Library allows an authenticated local attacker to achieve privilege escalation.

Executive summary

A heap-based buffer overflow in the Windows DWM Core Library, rated as a high-severity vulnerability, enables local privilege escalation for authenticated attackers.

Vulnerability

This flaw is a heap-based buffer overflow (CWE-122) within the Desktop Window Manager (DWM) Core Library. Exploitation requires an attacker to already possess local access with low-level privileges, which can then be leveraged to execute code with elevated permissions.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its significant potential for local privilege escalation. Successful exploitation allows an attacker to bypass security boundaries, potentially leading to full system compromise, data theft, or the installation of persistent malicious software. Organizations face a high risk of unauthorized administrative access if this vulnerability is not addressed.

Remediation

Immediate Action: Organizations must apply the relevant Microsoft security updates for the specific Windows versions identified in the affected versions list.

Proactive Monitoring: Security teams should monitor system logs for suspicious process execution patterns or unauthorized attempts to access sensitive DWM-related memory spaces.

Compensating Controls: Ensure that endpoint detection and response (EDR) solutions are configured to alert on anomalous local privilege escalation attempts. Restricting standard user permissions can also limit the initial foothold required to trigger this overflow.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for privilege escalation and the critical nature of the DWM Core Library, this vulnerability should be prioritized within standard patch management cycles. Administrators should verify that all affected Windows systems are updated to the latest available build to mitigate the risk of local exploitation.

More Microsoft CVEs

Sources