Junglewise Threat Intelligence

CVE-2026-44814: Microsoft Windows out-of-bounds read in DWM Core Library

CVE-2026-44814 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Desktop Window Manager (DWM) Core Library, which is responsible for managing the visual effects and window rendering on your computer. An attacker who already has basic access to a system could exploit this flaw to view sensitive information that should normally be protected. This could lead to the exposure of private data or help an attacker plan further, more damaging strikes against the system.

Technical details

An out-of-bounds read vulnerability exists in the Microsoft Windows DWM Core Library (dwminit.dll). The flaw is rooted in improper bounds checking during memory operations, specifically identified as a potential heap-based buffer overflow or out-of-bounds read (CWE-125, CWE-122). An attacker with low-privileged local access can exploit this vulnerability without user interaction to read sensitive data from the system's memory. While it does not directly allow for code execution, the information disclosed can be used to bypass security mitigations like ASLR. Microsoft has released security updates to address this issue via the MSRC update guide.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References