Junglewise Threat Intelligence

CVE-2026-32154: Microsoft Desktop Window Manager use after free privilege escalation

CVE-2026-32154 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Microsoft Windows Desktop Window Manager, the component responsible for rendering the visual interface of the operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software across the entire machine.

Technical details

This vulnerability is classified as a use-after-free (CWE-416) within the Desktop Window Manager (DWM) service in Microsoft Windows. The flaw occurs when the system continues to use a memory pointer after it has been freed, leading to memory corruption. An attacker with low-privileged local access can exploit this condition without any user interaction to execute code with elevated privileges, potentially reaching SYSTEM-level authority. The vulnerability affects multiple versions of Windows 11 and Windows Server, and Microsoft has released security updates to address the issue.

Affected products

  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2022 Base and 23H2
  • Microsoft Windows Server 2025 All versions

Timeline

  • 2026-04-14: disclosed: Initial disclosure by Microsoft
  • 2026-04-14: advisory: MSRC advisory published
  • 2026-06-01: other: NIST completed initial analysis and added CPE configurations

References

Related threats