Executive brief
The Microsoft Windows Desktop Window Manager (DWM) Core Library contains an elevation of privilege vulnerability. Successful exploitation allows an attacker to gain SYSTEM privileges via an untrusted pointer dereference or improper restriction of operations within memory bounds.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 21H2, 22H2, 23H2
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.5122
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.2113
- Microsoft Windows Server 2016 all versions
Timeline
- 2023-11-14: disclosed
- 2023-11-14: patched
- 2023-11-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-11-14: exploited