Junglewise Threat Intelligence

CVE-2026-44811: Microsoft Windows DWM Core Library use after free privilege escalation

CVE-2026-44811 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Desktop Window Manager (DWM) Core Library, which is responsible for rendering the visual effects on the Windows desktop. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new user accounts with full rights.

Technical details

A use-after-free vulnerability exists in the Microsoft Windows DWM Core Library (dwmcore.dll). The flaw is triggered when the system fails to properly manage memory objects during desktop rendering operations. An attacker with low-privileged local access can exploit this by running a specially crafted application to trigger the memory corruption, leading to arbitrary code execution with SYSTEM privileges. While the advisory mentions CWE-20 (Improper Input Validation) and CWE-122 (Heap-based Buffer Overflow), the primary mechanism described is a use-after-free. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: advisory: Initial advisory published by Microsoft and NVD.
  • 2026-06-09: patched: Security updates made available via Microsoft Update Guide.

References