CVE-2024-30051

ENISA EUVD: EUVD-2024-27989 ↗
Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 6 articles

EPSS Score

Source: FIRST.org · 2026-05-24
50.84%
probability
This CVE has a 50.84% probability of being exploited in the next 30 days.
0% Top 97.9th percentile of all CVEs 100%

CVSS v3.1

Source: NVD
7.8
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Temporal
Exploit Code Maturity
Functional
Remediation Level
Official Fix
Report Confidence
Confirmed
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Description

Project Zero
Heap overflow in DWM Core

Affected Products

Attack Intelligence

Google Project Zero

Patched
May 14, 2024
Reported by
Mert Degirmenci and Boris Larin with Kaspersky Quan Jin with DBAPPSecurity WeBin Lab Guoxian Zhong with DBAPPSecurity WeBin Lab Vlad Stolyarov and Benoit Sevens of Google Threat Analysis Group Bryce Abdo and Adam Brunner of Google Mandiant
Root Cause Analysis
???

Signal Intelligence

Confidence
82%
EPSS 50.84%
CVSS v3.1 7.8
Mentions 6
Last Seen Jan 14, 2026

CNA Information

Analyst Note

CVE-2024-30051 is confirmed as a Windows DWM Core Library elevation of privilege vulnerability with HIGH severity (CVSS 7.8) that has been actively exploited in the wild, as evidenced by coverage in TheHackerNews and BleepingComputer regarding Microsoft's January 2026 patch deployment. The vulnerability's inclusion in Google Project Zero research and multiple authoritative security sources provides strong corroboration for the confirmed status, though it is not yet listed in CISA KEV which slightly moderates confidence.

Threat Actors 1

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP

Triage Info

Decided atMar 03, 2026