Executive brief
A use-after-free vulnerability in the Microsoft Windows Desktop Window Manager (DWM) Core Library allows a locally authenticated attacker to elevate their privileges. The vulnerability has been observed being exploited in the wild.
Affected products
- Microsoft Windows 10 1809 up to (excluding) 10.0.17763.7314
- Microsoft Windows 10 21H2 up to (excluding) 10.0.19044.5854
- Microsoft Windows 10 22H2 up to (excluding) 10.0.19045.5854
- Microsoft Windows 11 22H2 up to (excluding) 10.0.22621.5335
- Microsoft Windows 11 23H2 up to (excluding) 10.0.22631.5335
- Microsoft Windows 11 24H2 up to (excluding) 10.0.26100.4061
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.7314
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.3692
- Microsoft Windows Server 2022 23H2 up to (excluding) 10.0.25398.1611
- Microsoft Windows Server 2025 up to (excluding) 10.0.26100.4061
Timeline
- 2025-05-13: disclosed
- 2025-05-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-05-13: advisory: Microsoft published vendor advisory
- 2025-05-13: exploited: Reported as exploited in the wild at time of publication