Microsoft Desktop Windows Manager Out-Of-Bounds Vulnerability Let Attackers Escalate Privileges
ID: 358ecae7-124e-5606-8bee-22623674ccf4
STIX ID: report--358ecae7-124e-5606-8bee-22623674ccf4
Feed Name: cybersecurityNews.com
Microsoft confirmed CVE-2025-55681, a critical out-of-bounds memory access vulnerability in the Desktop Window Manager core (dwmcore.dll, CBrushRenderingGraphBuilder::AddEffectBrush) that allows local attackers with low-privilege authenticated access to escalate to SYSTEM on Windows 10, Windows 11, and multiple Windows Server editions (CVSS 3.1: 7.8). The issue was demonstrated at the TyphoonPWN competition, Microsoft has issued security patches, and administrators are urged to apply updates immediately while restricting local code execution and enforcing least-privilege controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
