CVE-2025-64680
vulnerability analysis and mitigation

Overview

CVE-2025-64680 is a heap-based buffer overflow vulnerability in the Windows Desktop Window Manager (DWM) Core Library that allows an authenticated local attacker to elevate privileges on affected systems. Disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday, it affects a wide range of Windows versions including Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (22H2, 23H2, 24H2, 25H2), Windows Server 2016, 2019, 2022, and 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) within the Windows DWM Core Library, a component responsible for rendering the Windows graphical interface. An attacker with low-privileged local access can trigger the overflow to corrupt heap memory, potentially redirecting execution flow to achieve privilege escalation. Exploitation requires no user interaction and has low attack complexity, but does require the attacker to already have authenticated local access to the target system. The vulnerability is also mapped to CAPEC-92 (Forced Integer Overflow), suggesting the overflow may be triggered via malformed input that causes an integer miscalculation leading to an undersized heap allocation (Microsoft MSRC).

Impact

Successful exploitation allows a low-privileged local attacker to escalate to higher privilege levels on the affected Windows system, with high impact to confidentiality, integrity, and availability. An attacker could leverage elevated privileges to execute arbitrary code, access sensitive system resources, modify critical system configurations, or fully compromise the affected host. In environments where attackers have already gained initial foothold (e.g., via phishing or another vulnerability), this flaw could serve as a stepping stone for lateral movement or persistence (Microsoft MSRC).

Mitigation and workarounds

Microsoft released patches for CVE-2025-64680 on December 9, 2025, as part of the December 2025 Patch Tuesday update cycle. Affected versions and their fixed builds include: Windows 10 1507 (10.0.10240.21161), Windows 10 1607 / Server 2016 (10.0.14393.8519), Windows 10 1809 / Server 2019 (10.0.17763.7919), Windows 10 21H2 (10.0.19044.6456), Windows 10 22H2 (10.0.19045.6456), Windows 11 22H2 (10.0.22621.6060), Windows 11 23H2 (10.0.22631.6060), Windows 11 24H2 / Server 2025 (10.0.26100.6899), Windows 11 25H2 (10.0.26200.6899), Windows Server 2022 (10.0.20348.4294), and Windows Server 2022 23H2 (10.0.25398.1913). Organizations should apply the latest Microsoft security updates immediately, enforce least-privilege principles for local user accounts, and monitor for suspicious privilege escalation activity (Microsoft MSRC).

Community reactions

CVE-2025-64680 was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. Bleeping Computer noted the December 2025 update addressed 57 flaws including 3 zero-days, with this vulnerability among the elevation-of-privilege issues patched (Bleeping Computer). The Zero Day Initiative and Sophos also published Patch Tuesday review posts covering the December 2025 release (ZDI Blog, Sophos News). No notable individual researcher commentary or significant social media discussion specific to this CVE was identified.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management