Executive brief
A vulnerability exists in the Microsoft Desktop Window Manager, the component responsible for rendering the visual interface of the Windows operating system. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could allow them to bypass security restrictions, access sensitive data, or install malicious software. This vulnerability is reportedly being actively exploited in the wild.
Technical details
A type confusion vulnerability (CWE-843) exists in the Microsoft Desktop Window Manager (DWM). The flaw stems from the DWM improperly handling resources of incompatible types, which can be manipulated by a local attacker with low privileges. By successfully exploiting this vulnerability, an attacker can achieve local privilege escalation (LPE), potentially gaining SYSTEM-level access. The attack requires local authentication but no user interaction. Microsoft has released patches for various versions of Windows 10, 11, and Windows Server to address this issue. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 23H2, 24H2, 25H2
- Microsoft Windows Server 2016, 2019, 2022, 2025, 23H2
Timeline
- 2026-02-10: disclosed: Initial disclosure by Microsoft
- 2026-02-10: advisory: Microsoft released vendor advisory MSRC CVE-2026-21519
- 2026-02-10: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog
- 2026-02-10: exploited: Vulnerability reported as exploited in the wild at time of disclosure