Saturday, June 14, 2025
HomeCVE/vulnerabilityCritical Zero-day Vulnerability in Desktop Window Manager (DWM) Let Attackers to Escalate...

Critical Zero-day Vulnerability in Desktop Window Manager (DWM) Let Attackers to Escalate Privilege

Published on

SIEM as a Service

Follow Us on Google News

The security firm, Kaspersky has recently issued a warning about a new critical zero-day vulnerability found by its researchers in the Desktop Window Manager (DWM).

The bug was accidentally found by the security researchers at Kaspersky in February of this year while they were studying another known flaw (CVE-2021-1732); this new problem was then referred to Microsoft and classified by code CVE-2021-28310.

Researchers claimed that this newly-discovered critical zero-day vulnerability, CVE-2021-28310 was abused in the wild by the attackers. This flaw is an Escalation of Privilege (EoP) which is detected in DWM (Desktop Window Manager)

- Advertisement - Google News

According to the report, this exploit was used in the wild by several threat actors. This is an Escalation of Privilege (EoP) that allows attackers to execute arbitrary code on the victim’s device.

Desktop Window Manager (DWM)

Desktop Window Manager (DWM) is an essential component of Windows responsible for rendering the windows that use the operating system.

The Desktop Window Manager composes the application windows screen before drawing it on your screen. This allows Windows to add effects like transparency and live taskbar thumbnails. So, this process is a vital part of Windows that you can’t prevent from running.

In short, the DWM (Desktop Window Manager) clutches all the necessary information from the buffer of each program and formulates the composite view of the overall interface that the user perceives.

Zero-day vulnerability in Desktop Window Manager (DWM)

The “CVE-2021-28310” is a privilege escalation bug, and abusing this flaw an attacker can easily evade the operating system’s user levelling systems and become an administrator to perform abstruser actions on the affected PC. 

So, in this case, the cybersecurity analysts of Kaspersky believe that the hacking groups that are specialized in targeted attacks were already actively abusing this bug along with other known weaknesses to hack into other user’s systems without being detected by security tools.

Mitigations

The security researchers at Kaspersky has recommended quick mitigations, and here they are mentioned below:-

  • Immediately install the patches released on April 13 by Microsoft on all the vulnerable systems to prevent threat actors from exploiting them.
  • Guard all of your devices with a robust endpoint security solution and patch management capabilities.
  • Implement an enterprise-grade security solution that identifies advanced network-layer threats early on.

Microsoft has already released security updates and patches to fix the flaw for several versions of Windows 10. So, here, users need to install them as soon as possible to defend against these types of vulnerabilities.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Kali Linux 2025.2 Released: New Tools, Smartwatch and Car Hacking Added

Kali Linux, the preferred distribution for security professionals, has launched its second major release...

Arsen Launches AI-Powered Vishing Simulation to Help Organizations Combat Voice Phishing at Scale

Arsen, the cybersecurity startup known for defending organizations against social engineering threats, has announced...

NIST Releases New Guide – 19 Strategies for Building Zero Trust Architectures

The National Institute of Standards and Technology (NIST) has released groundbreaking guidance to help...

Spring Framework Flaw Enables Remote File Disclosure via “Content‑Disposition” Header

A medium-severity reflected file download (RFD) vulnerability (CVE-2025-41234) in VMware's Spring Framework has been...

Credential Abuse: 15-Min Attack Simulation

Credential Abuse Unmasked

Credential abuse is #1 attack vector in web and API breaches today (Verizon DBIR 2025). Join our live, 15-min attack simulation with Karthik Krishnamoorthy (CTO - Indusface) and Phani Deepak Akella (VP of Marketing - Indusface) to see hackers move from first probe to full account takeover.

Discussion points


Username & email enumeration – how a stray status-code reveals valid accounts.
Password spraying – low-and-slow guesses that evade basic lockouts.
Credential stuffing – lightning-fast reuse of breach combos at scale.
MFA / session-token bypass – sliding past second factors with stolen cookies.

More like this

Severe WSO2 SOAP Flaw Allows Unauthorized Password Resets for Any Use

A newly disclosed vulnerability, CVE-2024-6914, has shocked the enterprise software community, affecting a wide...

CISA Alerts on Threat Actors Targeting Commvault Azure App to Steal Secrets

On May 22, 2025, Commvault, a leading enterprise data backup provider, issued an urgent...

PoC Code Published for Linux nftables Security Vulnerability

Security researchers have published proof-of-concept (PoC) exploit code for CVE-2024-26809, a high-severity double-free vulnerability in...