Netskope Threat Labs

FILE-EXECUTABLE Microsoft Windows Desktop Window Manager use-after-free attempt

IPS-SWG

1 SID: 63430

Detects content exploiting CVE-2024-30035, a use-after-free in the Windows Desktop Window Manager that can allow privilege escalation. The rule matches the window manager object sequences that public exploits use to free and reuse kernel objects.