Junglewise Threat Intelligence

CVE-2026-20871: Microsoft Desktop Window Manager use after free privilege escalation

CVE-2026-20871 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Microsoft Windows 11 24h2, Microsoft Windows Server 2022 23h2, Microsoft Windows 10 22h2, Microsoft Windows 11 23h2, Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows 10 21h2, Microsoft Windows 11 25h2, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Desktop Window Manager, a core component of Microsoft Windows responsible for rendering the visual interface. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A use-after-free (UAF) vulnerability exists in the Microsoft Desktop Window Manager (DWM) component (dwin.exe). The flaw is triggered when the system improperly handles objects in memory, allowing an attacker to reuse a memory pointer after it has been freed. To exploit this, an attacker must first have local access to the target system with low-privileged user credentials. Successful exploitation enables the attacker to execute arbitrary code with elevated system privileges. Microsoft has released security updates to address this issue across affected Windows 10, 11, and Server versions.

Affected products

  • Microsoft Windows 10 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2022 Standard, 23H2 Edition
  • Microsoft Windows Server 2025 Standard, Server Core

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: patched

References

Related threats