Executive brief
A security vulnerability has been identified in the Windows Desktop Window Manager (DWM) Core Library, which is responsible for rendering visual effects on the Windows desktop. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.
Technical details
A use-after-free vulnerability exists in the Windows DWM Core Library (dwminit.dll or related components). The flaw is triggered when the system improperly handles objects in memory, allowing an attacker to execute code with elevated privileges. To exploit this, an attacker must first have local access to the target system with low-privileged user credentials. Successful exploitation grants the attacker SYSTEM-level privileges, bypassing security boundaries. Microsoft has released security updates to address this issue; users should apply the latest Windows patches.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory