Executive brief
A security vulnerability has been identified in the Microsoft Desktop Window Manager, the component responsible for rendering the visual interface of the Windows operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt business operations.
Technical details
This vulnerability is a heap-based buffer overflow (CWE-122) within the Microsoft Desktop Window Manager (DWM.exe). The flaw is triggered locally by an authenticated user with low privileges. By sending specially crafted requests to the DWM process, an attacker can overflow a buffer on the heap to execute arbitrary code or manipulate memory. Successful exploitation allows the attacker to escape the user context and gain SYSTEM-level privileges, as indicated by the 'Changed' scope in the CVSS vector. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 Standard and Server Core
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory