Executive brief
A security vulnerability exists in the Windows Desktop Window Manager (DWM) Core Library, which is responsible for rendering the visual effects on the Windows desktop. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new user accounts with full rights.
Technical details
A use-after-free (UAF) vulnerability exists within the Windows DWM Core Library (d3d10warp.dll or similar DWM components). The flaw is triggered when the system improperly handles objects in memory, allowing an attacker to execute code in the context of a more privileged process. To exploit this, an attacker must first log on to the system with low-privileged credentials and run a specially crafted application. Successful exploitation grants the attacker SYSTEM privileges, leading to a complete compromise of the local machine. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory