Junglewise Threat Intelligence

CVE-2026-34336: Microsoft Windows DWM Core Library privilege escalation

CVE-2026-34336 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Windows 11, Microsoft Windows, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Desktop Window Manager (DWM), the component responsible for rendering the visual interface of the operating system. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level system permissions or access sensitive information. This could allow an unauthorized user to take full control of the affected workstation or server, potentially leading to data theft or further network compromise.

Technical details

A buffer over-read vulnerability (initially identified as CWE-126 and later updated to CWE-122 heap-based buffer overflow) exists within the Windows DWM Core Library (dwmcore.dll). The flaw is triggered when the Desktop Window Manager improperly handles memory during rendering operations. An attacker with local access and low-level privileges can exploit this to read out-of-bounds memory, leading to information disclosure or full local privilege escalation (LPE) to SYSTEM. The vulnerability affects a wide range of Windows 10, Windows 11, and Windows Server versions. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2016 All versions
  • Microsoft Windows Server 2019 All versions

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Microsoft
  • 2026-05-12: advisory: NVD published the CVE record
  • 2026-05-22: other: Vulnerability description updated from information disclosure to privilege escalation

References

Related threats