Junglewise Threat Intelligence

CVE-2026-20842: Microsoft Windows DWM use after free privilege escalation

CVE-2026-20842 · Severity: high · CVSS 7 · Published 2026-01-13

Technologies: Microsoft Windows 11 24h2, Microsoft Windows Server 2022 23h2, Microsoft Windows 10 22h2, Microsoft Windows 11 23h2, Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows 10 21h2, Microsoft Windows 11 25h2, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Desktop Window Manager (DWM), the component responsible for rendering the visual interface of the Windows operating system. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level administrative permissions. This could allow them to bypass security restrictions, access sensitive data, or install malicious software that would otherwise be blocked.

Technical details

A use-after-free (UAF) vulnerability exists in the Windows Desktop Window Manager (DWM) component (CWE-416). The flaw is triggered when the system improperly handles objects in memory, allowing an attacker to reuse a memory pointer after it has been freed. To exploit this, an attacker must have local access to the target system with low-privileged user credentials. Successful exploitation enables the attacker to execute code with elevated privileges, potentially gaining full SYSTEM access. Microsoft has released security updates to address this issue across affected versions of Windows 10, 11, and Windows Server.

Affected products

  • Microsoft Windows 10 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2022 Base and 23H2 Edition
  • Microsoft Windows Server 2025 Base and Server Core

Timeline

  • 2026-01-13: advisory: Initial disclosure by Microsoft

References

Related threats