Executive brief
A security vulnerability exists in the Windows Desktop Window Manager (DWM), the component responsible for rendering visual effects and window management on your computer. An attacker who already has basic access to a system could exploit this flaw to view sensitive information that should normally be protected. While this does not allow an attacker to take over the computer directly, it could be used to gather data for more complex attacks.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Windows DWM Core Library. The flaw is triggered when the component improperly handles memory access, allowing an attacker with local user privileges to read data outside of the intended buffer. This is a local information disclosure vulnerability that does not require user interaction. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server 2016.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 Standard and Server Core
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory