kevmap

Coverage › CVE-2025-30400

CVE-2025-30400 Mapped Sigma

Microsoft Windows DWM Core Library Use-After-Free Vulnerability

Vendor / product
Microsoft — Windows
Description (CISA)
Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Added to KEV
2025-05-13
Due date
2025-06-03
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Known ransomware use
Unknown
CWE
CWE-416
CISA notes
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-30400
https://nvd.nist.gov/vuln/detail/CVE-2025-30400
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28

2 mapping objects across 2 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.

TechniqueMapping typeCTID commentStatus in v19.2
T1068 Exploitation for Privilege Escalation exploitation technique This vulnerability has been exploited to escalate an attacker's privileges to SYSTEM-level via Microsoft Windows Desktop Window Manager (DWM) Core Library, allowing the attacker to take significant actions such as registry modification.
ref 1
live
T1112 Modify Registry primary impact This vulnerability has been exploited to escalate an attacker's privileges to SYSTEM-level via Microsoft Windows Desktop Window Manager (DWM) Core Library, allowing the attacker to take significant actions such as registry modification.
ref 1
live

Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources

T1068 Exploitation for Privilege Escalation exploitation technique

Sigma rules tagged attack.t1068 (31)

Author: Florian Roth (Nextron Systems) · 2019-11-20 (modified 2024-12-01) · logsource: product=windows category=process_creation · 02e0b2ea-a597-428e-b04a-af6a1a403e5c
Detects an exploitation attempt in which the UAC consent dialogue is used to invoke an Internet Explorer process running as LOCAL_SYSTEM
Techniques: T1068
CVE tags: CVE-2019-1388
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-08-18 (modified 2023-12-02) · logsource: product=windows category=driver_load · 05296024-fe8a-4baf-8f3d-9a5f5624ceb2
Detects loading of known malicious drivers via their hash.
Techniques: T1543.003T1068
Author: Florian Roth (Nextron Systems) · 2021-10-09 (modified 2022-12-25) · logsource: product=linux service=auditd · 071d5e5a-9cef-47ec-bc4e-a42e34d8d0ed
Detects command line parameter very often used with coin miners
Techniques: T1068
Author: Nisarg Suthar · 2025-08-01 · logsource: product=windows category=process_creation · 0fdc7c7f-c690-4217-9ae3-31f5156eed72
Detects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.
CVE tags: CVE-2025-54309
Author: Swachchhanda Shrawn Poudel (Nextron Systems) · 2025-10-02 (modified 2026-03-31) · logsource: product=linux category=file_event · 10ac0730-c24e-4f4c-81f8-b13a1ac95a1d
Detects the creation of nsswitch.conf files in non-standard directories, which may indicate exploitation of CVE-2025-32463. This vulnerability requires an attacker to create a nsswitch.conf in a directory that will be used during sudo chroot operations. When sudo executes, it loads malicious shared libraries from user-controlled locations within the chroot environment, potentially leading to arbitrary code execution and privilege escalation.
Techniques: T1068
CVE tags: CVE-2025-32463
Author: @eyezuhk Isaac Fernandes · 2025-02-19 · logsource: product=windows category=image_load · 17ce9373-2163-4a2c-90ba-f91e9ef7a8c1
Detects potentially suspicious loading of "ksproxy.ax", which may indicate an attempt to exploit CVE-2024-35250.
Techniques: T1068
CVE tags: CVE-2024-35250
Author: Florian Roth (Nextron Systems) · 2017-03-01 (modified 2025-03-17) · logsource: product=linux · 18b042f0-2ecd-4b6e-9f8d-aa7a7e7de781
Detects buffer overflow attempts in Unix system log files
Techniques: T1068
Author: Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro · 2019-11-15 (modified 2021-11-27) · logsource: product=windows category=process_creation · 1c373b6d-76ce-4553-997d-8c1da9a6b5f5
Detects exploitation attempt of privilege escalation vulnerability via SetupComplete.cmd and PartnerSetupComplete.cmd described in CVE-2019-1378
CVE tags: CVE-2019-1378
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC · 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 21541900-27a9-4454-9c4c-3f0a4240344a
Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Techniques: T1068T1190T1203
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-06-06 · logsource: product=windows category=process_creation · 38a1ac5f-9c74-47d2-a345-dd6f5eb4e7c8
Detects the execution of SharpSuccessor, a tool used to exploit the BadSuccessor attack for privilege escalation in WinServer 2025 Active Directory environments. Successful usage of this tool can let the attackers gain the domain admin privileges by exploiting the BadSuccessor vulnerability.
Techniques: T1068
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-10-03 (modified 2023-12-02) · logsource: product=windows category=driver_load · 39b64854-5497-4b57-a448-40977b8c9679
Detects loading of known malicious drivers via the file name of the drivers.
Techniques: T1543.003T1068
Author: Florian Roth (Nextron Systems) · 2021-11-22 (modified 2022-12-25) · logsource: product=windows category=file_event · 3be82d5d-09fe-4d6a-a275-0d40d234d324
Detects signs of the exploitation of LPE CVE-2021-41379 that include an msiexec process that creates an elevation_service.exe file
Techniques: T1068
Author: Gene Kazimiarovich · 2026-04-30 · logsource: product=linux service=auditd · 474b415a-8b3d-4e6a-9f12-0d5c8a7b6e94
Detects creation of AF_ALG (Address Family 38) sockets via the socket() syscall. AF_ALG is the Linux kernel crypto API interface. It is exploited in CVE-2026-31431 to achieve local privilege escalation via a buffer overflow in the AF_ALG AEAD splice path that corrupts the page cache of SUID binaries. Legitimate AF_ALG usage is rare and confined to specific crypto utilities and VPN daemons using non-default kernel offload configurations.
Techniques: T1068
CVE tags: CVE-2026-31431
Author: Gene Kazimiarovich · 2026-05-09 · logsource: product=linux category=process_creation · 474b415a-d917-4f3b-8c62-9e1a0d5f7b48
Detects kernel auto-loading of the authencesn crypto module via modprobe This occurs when user-space code creates an AF_ALG socket and binds the authencesn AEAD cipher (e.g., authencesn(hmac(sha256),cbc(aes))). The kernel invokes modprobe to load the crypto module. This is a key indicator of CVE-2026-31431 (Copy Fail) exploitation, where the authencesn cipher is used to trigger a buffer overflow in the AF_ALG AEAD splice path, corrupting the page cache of SUID binaries for local privilege escalation. On Linux systems, modprobe is typically a symlink to kmod, so the process image will be /usr/bin/kmod (or /bin/kmod) with 'modprobe' appearing in the command line.
Techniques: T1068T1547.006
CVE tags: CVE-2026-31431
Audit CVE Event criticaltest
Author: Florian Roth (Nextron Systems), Zach Mathis · 2020-01-15 (modified 2022-10-22) · logsource: product=windows service=application · 48d91a3a-2363-43ba-a456-ca71ac3da5c2
Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.

All 31 rules on the technique page →

T1112 Modify Registry primary impact

Sigma rules tagged attack.t1112 (96)

Author: Austin Songer · 2021-07-22 (modified 2023-08-17) · logsource: product=windows category=registry_set · 04b45a8a-d11d-49e4-9acc-4a1b524407a5
Detects when a user enables DNS-over-HTTPS. This can be used to hide internet activity or be used to hide the process of exfiltrating data. With this enabled organization will lose visibility into data such as query type, response and originating IP that are used to determine bad actors.
Techniques: T1140T1112
Author: Christian Burkard (Nextron Systems) · 2021-10-19 (modified 2023-02-08) · logsource: product=windows category=registry_delete · 07bdd2f5-9c58-4f38-aec8-e101bb79ef8d
Detects the deletion of registry keys containing the MSTSC connection history
Techniques: T1070T1112
Author: Oddvar Moe, Sander Wiebing, oscd.community · 2020-10-12 (modified 2024-03-13) · logsource: product=windows category=process_creation · 0b80ade5-6997-4b1d-99a1-71701778ea61
Detects the import of a alternate datastream to the registry with regedit.exe.
Techniques: T1112
Author: frack113 · 2022-08-19 (modified 2023-08-17) · logsource: product=windows category=registry_set · 0c93308a-3f1b-40a9-b649-57ea1a1c1d63
Detect set Notification_Suppress to 1 to disable the Windows security center notification
Techniques: T1112
Author: pH-T (Nextron Systems), @Kostastsale, TheDFIRReport · 2022-02-12 (modified 2025-11-22) · logsource: product=windows category=process_creation · 0d5675be-bc88-4172-86d3-1e96a4476536
Detects the execution of "reg.exe" for enabling/disabling the RDP service on the host by tampering with the 'CurrentControlSet\Control\Terminal Server' values
Techniques: T1021.001T1112
Author: Swachchhanda Shrawan Poudel · 2024-07-31 · logsource: product=windows category=registry_set · 16a4c7b3-4681-49d0-8d58-3e9b796dcb43
Detects registry modifications related to the proxy configuration of the system, potentially associated with the Raspberry Robin malware, as seen in campaigns running in Q1 2024. Raspberry Robin may alter proxy settings to circumvent security measures, ensuring unhindered connection with Command and Control servers for maintaining control over compromised systems if there are any proxy settings that are blocking connections.
Techniques: T1112
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) · 2020-07-14 (modified 2025-10-22) · logsource: product=windows service=security · 18beca67-ab3e-4ee3-ba7a-a46ca8d7d0cc
Potential threat actor tampering with Sysmon manifest and eventually disabling it
Techniques: T1112
Author: Avneet Singh @v3t0_, oscd.community, Christopher Peacock @SecurePeacock (updated) · 2020-10-18 (modified 2022-12-13) · logsource: product=windows category=process_creation · 198effb6-6c98-4d0c-9ea3-451fa143c45c
This rule detects the execution of Run Once task as configured in the registry
Techniques: T1112
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) · 2019-08-25 (modified 2021-11-27) · logsource: product=windows category=registry_event · 1a2d6c47-75b0-45bd-b133-2c0be75349fd
Detects potential malicious modification of the property value of IsCredGuardEnabled from HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest to disable Cred Guard on a system. This is usually used with UseLogonCredential to manipulate the caching credentials.
Techniques: T1112
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-04-09 · logsource: product=windows category=process_creation · 1a4bd6af-99ac-4466-b5b2-7b72b4a05462
Detects attempts to disable security event logging by adding the `MiniNt` registry key. This key is used to disable the Windows Event Log service, which collects and stores event logs from the operating system and applications. Adversaries may want to disable this service to prevent logging of security events that could be used to detect their activities.
Techniques: T1685.001T1112
Author: Trent Liffick (@tliffick), Nasreddine Bencherchali (Nextron Systems) · 2020-05-22 (modified 2023-08-17) · logsource: product=windows category=registry_set · 1a5c46e9-f32f-42f7-b2bc-6e9084db7fbf
Detects registry changes to Microsoft Office "AccessVBOM" to a value of "1" which disables trust access for VBA on the victim machine and lets attackers execute malicious macros without any Microsoft Office warnings.
Techniques: T1112
Author: frack113 · 2022-03-18 (modified 2023-08-17) · logsource: product=windows category=registry_set · 1c3121ed-041b-4d97-a075-07f54f20fb4a
Detects registry modifications that disable internal tools or functions in explorer (malware like Agent Tesla uses this technique)
Techniques: T1112
Author: Hieu Tran · 2023-03-13 · logsource: product=windows category=registry_event · 1c8e96cd-2bed-487d-9de0-b46c90cade56
Detects a registry key used by IceID in a campaign that distributes malicious OneNote files
Techniques: T1112
Author: Christopher Peacock · 2021-10-07 (modified 2025-11-03) · logsource: product=windows category=registry_add · 1d218616-71b0-4c40-855b-9dbe75510f7f
Detects registry keys related to NetWire RAT
Techniques: T1112
Author: megan201296 · 2019-02-13 (modified 2025-10-22) · logsource: product=windows category=registry_add · 21f17060-b282-4249-ade0-589ea3591558
Detects registry keys related to Ursnif malware.
Techniques: T1112

All 96 rules on the technique page →