logo

Microsoft Desktop Windows Manager Out-Of-Bounds Vulnerability Let Attackers Escalate Privileges

ID: 358ecae7-124e-5606-8bee-22623674ccf4

STIX ID: report--358ecae7-124e-5606-8bee-22623674ccf4

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2025-12-17

Date Updated: 2026-04-21

Author: Abinaya

...
...

Microsoft confirmed CVE-2025-55681, a critical out-of-bounds memory access vulnerability in the Desktop Window Manager core (dwmcore.dll, CBrushRenderingGraphBuilder::AddEffectBrush) that allows local attackers with low-privilege authenticated access to escalate to SYSTEM on Windows 10, Windows 11, and multiple Windows Server editions (CVSS 3.1: 7.8). The issue was demonstrated at the TyphoonPWN competition, Microsoft has issued security patches, and administrators are urged to apply updates immediately while restricting local code execution and enforcing least-privilege controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.