Microsoft Windows DWM Zero-Day Poised for Mass Exploit
ID: c5d77c79-b565-5554-aab2-ca9811c63543
STIX ID: report--c5d77c79-b565-5554-aab2-ca9811c63543
Feed Name: Dark Reading
Date Published: 2024-05-14
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Microsoft's May Patch Tuesday fixes 59 CVEs across Windows, Office, .NET, Edge and other products, including three zero-days: CVE-2024-30051 (Windows DWM elevation of privilege) and CVE-2024-30040 (MSHTML bypass) are under active exploitation, and CVE-2024-30046 (ASP.NET Core DoS) is publicly known. Kaspersky and other researchers report multiple actors — notably QakBot operators — integrating exploits, and the bulletin highlights additional high-risk issues (SharePoint XXE allowing info disclosure and NTLM relay, kernel and Windows Search Service elevation flaws) that could be chained to achieve full system takeover, making timely patching critical.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
