Microsoft released fixes for 61 vulnerabilities in its May security updates, including three zero-days and one critical flaw, with CVE-2024-30040 and CVE-2024-30051 confirmed as actively exploited in the wild. The patched issues affect core Microsoft products including Windows, Office, SharePoint, .NET, Visual Studio, and Windows Server, and include a Windows MSHTML Platform security feature bypass and a Windows DWM Core Library elevation-of-privilege flaw that can allow attackers to gain SYSTEM privileges.
Researchers who reported CVE-2024-30051 said they validated the Windows Desktop Window Manager flaw after finding a suspicious document uploaded to VirusTotal, then later observed an exploit in mid-April being used with QakBot and other malware. Kaspersky assessed that multiple threat actors likely had access to the exploit before the patch was released, underscoring the urgency for organizations to deploy Microsoft's updates immediately across affected Windows and server environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2024-05-16, CSIRT.SK published guidance noting that Microsoft's May 2024 updates fixed 61 vulnerabilities, including actively exploited zero-days CVE-2024-30040 and CVE-2024-30051, and urged immediate deployment of the patches.
In mid-April 2024, researchers found an in-the-wild exploit for CVE-2024-30051 being used alongside QakBot and other malware. They assessed that multiple threat actors likely had access to the exploit.
In early April 2024, researchers examining a suspicious VirusTotal-uploaded document identified and validated a real Windows Desktop Window Manager privilege-escalation zero-day that could grant SYSTEM privileges. They reported the issue to Microsoft, which later assigned it CVE-2024-30051.
On 2024-05-14, Microsoft released a security update for the Windows DWM Core Library Elevation of Privilege vulnerability CVE-2024-30051 as part of its May 2024 Patch Tuesday. The flaw was reported as actively exploited in the wild.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcesecurelist.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.