Executive brief
A security vulnerability has been identified in the Microsoft Windows Desktop Window Manager, the component responsible for rendering the visual interface of the operating system. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that should otherwise be protected. While this does not allow for direct control of the system, it could lead to the exposure of private data or credentials, and the vulnerability is reportedly being exploited in the wild.
Technical details
An information disclosure vulnerability (CWE-200) exists in the Microsoft Desktop Window Manager (DWM). The flaw allows an authorized attacker with local access to the system to disclose sensitive information without requiring user interaction. The vulnerability is categorized as medium severity with a CVSS 3.1 score of 5.5, primarily impacting confidentiality. Despite the medium severity, CISA has added this to the Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Microsoft has released security updates for affected versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2012 All versions
Timeline
- 2026-01-13: advisory: Initial disclosure by Microsoft and NVD
- 2026-01-13: kev added: Added to CISA KEV catalog due to active exploitation
- 2026-02-03: patched: CISA deadline for federal agencies to apply patches