Executive brief
A security vulnerability exists in the Microsoft Windows Desktop Window Manager, the component responsible for rendering the visual interface of the operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.
Technical details
A use-after-free (CWE-416) vulnerability exists within the Microsoft Desktop Window Manager (DWM.exe). The flaw is triggered when the system attempts to access memory that has already been deallocated, leading to memory corruption. An attacker with low-privileged local access can exploit this condition to execute arbitrary code with elevated system privileges. The attack requires no user interaction and has a low complexity. Microsoft has released security updates to address this issue across affected versions of Windows 11 and Windows Server.
Affected products
- Microsoft Windows 11 23H2 up to (excluding) 10.0.22631.6936
- Microsoft Windows 11 24H2 up to (excluding) 10.0.26100.8246
- Microsoft Windows 11 25H2 up to (excluding) 10.0.26200.8246
- Microsoft Windows 11 26H1 up to (excluding) 10.0.28000.1836
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.5020
- Microsoft Windows Server 2025 up to (excluding) 10.0.26100.32690
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory