← Back to browse · API

CVE-2025-30400

Severity
HIGH
CVSS
7.8
EPSS
0.01772
Risk score
56.82
CISA KEV
Yes
PoC
No
Published
2025-05-13
Modified
2025-05-13
First seen
2026-08-07
Aliases
EUVD-2025-14444, GHSA-VVR8-G6JJ-JWRW
Products
Microsoft:Windows, Microsoft:Windows 10 Version 1809 10.0.17763.0 <10.0.17763.7314, Microsoft:Windows 10 Version 21H2 10.0.19044.0 <10.0.19044.5854, Microsoft:Windows 10 Version 22H2 10.0.19045.0 <10.0.19045.5854, Microsoft:Windows 11 Version 23H2 10.0.22631.0 <10.0.22631.5335, Microsoft:Windows 11 Version 24H2 10.0.26100.0 <10.0.26100.4061, Microsoft:Windows 11 version 22H2 10.0.22621.0 <10.0.22621.5335, Microsoft:Windows 11 version 22H3 10.0.22631.0 <10.0.22631.5335, Microsoft:Windows Server 2019 (Server Core installation) 10.0.17763.0 <10.0.17763.7314, Microsoft:Windows Server 2019 10.0.17763.0 <10.0.17763.7314, Microsoft:Windows Server 2022 10.0.20348.0 <10.0.20348.3692, Microsoft:Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.0 <10.0.25398.1611, Microsoft:Windows Server 2025 (Server Core installation) 10.0.26100.0 <10.0.26100.4061, Microsoft:Windows Server 2025 10.0.26100.0 <10.0.26100.4061
Sources
cisa.gov CVE-2025-30400
euvd EUVD-2025-14444

Description

Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

References