Executive brief
A security vulnerability has been identified in the Windows Desktop Window Manager (DWM) Core Library, which is responsible for rendering the visual effects on the Windows desktop. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.
Technical details
A use-after-free vulnerability (CWE-416) exists within the Windows DWM Core Library (d3d10warp.dll or similar DWM components). The flaw is triggered when the system continues to use a memory pointer after it has been freed, leading to memory corruption. An attacker with local access and low-level privileges can exploit this condition to execute arbitrary code with SYSTEM privileges. The attack requires no user interaction but does require the attacker to have prior authenticated access to the target machine. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: advisory: Initial disclosure by Microsoft and NVD.
- 2026-06-09: patched: Security updates made available via Microsoft Update Guide.