Microsoft Windows DWM Core Library Privilege Escalation Vulnerability
Vulnerability
A heap-based buffer overflow vulnerability has been identified in the Windows DWM Core Library. This vulnerability allows an authorized attacker to locally elevate privileges. The issue arises from improper handling of memory, which could be exploited to gain higher-level access rights.
Impact
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.
Remediation
Users are advised to install the security updates released in October 2025. These updates address the vulnerability, but CVE-2025-64679 was inadvertently omitted from the October 2025 Security Updates. Instructions for downloading the security updates are available on the Microsoft Update Catalog.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
