Executive brief
Windows Desktop Window Manager (DWM) Core Library is a core graphics rendering component in Windows. A use-after-free vulnerability allows an authorized attacker to execute code with elevated privileges, potentially compromising system security and giving an attacker full control over the affected machine.
Technical details
A use-after-free vulnerability exists in the Windows DWM Core Library that can be triggered by an authorized attacker. The vulnerability allows an attacker to gain privilege escalation over the network. The attack requires an authenticated user or prior network access context. Upon successful exploitation, the attacker can execute arbitrary code with elevated privileges. A fix is expected from Microsoft via the Security Update Guide referenced in the advisory.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed